Raccoon Stealer is a commodity Windows information stealer operated as a malware-as-a-service offering and widely used in financially motivated cybercrime. It is designed to harvest sensitive data from infected systems, especially browser-saved credentials, cookies, autofill data, stored payment-card information, and other host details. The malware also gathers system and user information, can capture screenshots, and can collect files and directories according to operator-supplied configuration. Its theft of browser cookies and session tokens makes infections particularly useful for account takeover and session hijacking, not just password compromise.
Raccoon Stealer commonly communicates with command-and-control infrastructure over HTTP, including HTTP POST requests, and can use dynamically resolved infrastructure to improve resilience. In observed campaigns, operators used Telegram-based dead-drop or gate-resolution mechanisms to rotate command-and-control endpoints when infrastructure was blocked. Stolen data is typically bundled and exfiltrated to attacker-controlled servers.
Distribution has been closely associated with cybercrime delivery ecosystems rather than bespoke intrusion tradecraft. Observed infection vectors include fake cracked-software and warez sites, YouTube-promoted download lures, malicious ads and broader malvertising activity, and delivery by other malware such as GootLoader or batch-script-based download chains. Raccoon Stealer has also appeared alongside additional payloads including clippers, cryptominers, browser-extension abuse, click-fraud components, backdoors, and ransomware, reflecting its role in multi-payload criminal operations.
Raccoon Stealer is frequently referenced alongside other major infostealers such as RedLine, Vidar, Lumma, and StealC, and stolen logs from such malware are routinely monetized in underground markets and used for downstream intrusion activity. Threat actors and access brokers have used Raccoon-derived credentials and session material to support enterprise compromise, fraud, and extortion workflows. The malware has also been associated with actors such as Scattered Spider as part of a broader credential-theft toolkit, though it remains primarily known as a mass-market infostealer rather than malware tied to a single operator or state-backed campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
GOLD HARVEST is known to employ commodity infostealers such as Vidar and Raccoon, which collect browser-saved passwords, cookies, and session tokens.
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
"Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser."
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Payloads disguised as pirated software; SFX headers manipulated to block static unpacking.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
RC4-decrypts the Telegram channel description to recover the C2 gate address.
The .NET loader includes an anti-virtual-machine module.
DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.
The downloaded file was a VHD container which, when mounted, revealed Installer.bat, a batch file containing simple commands intended to raise execution privileges; add scanning exclusions for Windows Defender; and download and execute a remote batch script and an executable.
When successfully deployed and executed, information-stealing malware can harvest credentials (usernames, passwords, and session cookies) from infected environments and export them as logs to the attackers’ server.
Collects browser authentication cookies for session hijacking.
The content repeatedly describes malware and threat actors querying, enumerating, searching, reading, or checking Windows Registry keys and values, e.g., "ADVSTORESHELL can enumerate registry keys," "APT41 queried registry values to determine items such as configured RDP ports and network configurations," and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
T1087.004: Account Discovery: Cloud To establish a foundational understanding of the target environment, a threat actor might first locate the identities operating within it... AzureHound parameters that facilitate the MITRE technique Account Discovery: Cloud Account include the following: list users list devices list device-owners list service-principals list service-principal-owners
APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources.
Confucius has used a file stealer to steal documents and images... Patchwork developed a file stealer to search C:\ and collect files with certain extensions... Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer used to harvest credentials and browser artifacts; in this report it is cited as the source of infected-machine data used to help attribute ByteToBreach.
Mentioned only in external reference citations linking Telegram dead-drop resolvers to Raccoon Stealer botnet infrastructure.
Information-stealing malware sold as a service that harvests browser passwords, cookies, autofill and stored card data, can target cryptocurrency wallets via a bundled clipper update, retrieve or drop additional payloads, and is operated through a Tor-based C2 panel.
Инфостилер, упомянутый как пример malware, использующего кражу учетных данных из браузеров.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.