Summary:
The Raccoon stealer malware is back with a second major version circulating on cybercrime forums, offering hackers elevated password-stealing functionality and upgraded operational capacity. Raccoon stealer 2.0 is now promoted on hacking forums, with the first samples captured by malware analysis earlier this month. The team promised to return with a second version relaunching the MAAS (Malware as service) project on upragaded infracture and with more capabilities.[/subscribe_to_unlock_form]
Summary:
The Raccoon stealer malware is back with a second major version circulating on cybercrime forums, offering hackers elevated password-stealing functionality and upgraded operational capacity. Raccoon stealer 2.0 is now promoted on hacking forums, with the first samples captured by malware analysis earlier this month. The team promised to return with a second version relaunching the MAAS (Malware as service) project on upragaded infracture and with more capabilities.[emaillocker id="1283"]
Description:
The new Raccoon version is built from scratch using C/C++, featuring a new back-end, front-end, and code to steal credentials and other data. Technical analysis now confirms that 56KB sample which was captured is the new Raccoon, able to work on 32 and 64-bit systems without any dependencies, only fetching eight legitimate DLLs from its C2 servers. The C2 also provides the malware with its configuration (apps to target, URL hosting the DLLs, token for data exfiltration), receives machine fingerprint data, and then waits for individual POST requests that contain stolen information.

What stands out is that the new Raccoon sends data each time it collects a new item, which increases the risk of detection but ensures maximum effectiveness until the malware is discovered and uprooted from the host.
Best Practices:
Threat Assessment:
We expect a resurgence of Raccoon Stealer v2, as developers implemented a version tailored to the needs of cybercriminals (efficiency, performance, stealing capabilities, etc.) and scaled their backbone servers to handle large loads. Its operators have chosen not to announce Raccoon’s wide availability yet, possibly because they’re still working on some aspects of the malware.
[/emaillocker]