Summary:
Raccoon Stealer is an information stealer that primarily targets victim credentials and cryptocurrency wallets. The malware has been observed in cybercriminal forums since 2019 and is offered as a 'Malware-as-a-Service' (MaaS) threat. Despite its simplicity, Raccoon Stealer has been successful due to its focus on stealing data and credentials. The malware's distribution method includes malicious document attachments in unsolicited emails and the use of third-party exploit kits or malware families. The Raccoon Stealer has experienced periods of activity and hiatus. In October 2022, one of its main operators, Mark Sokolovsky, was arrested, leading to a temporary halt in the operation. However, the malware recently announced its return.[/subscribe_to_unlock_form]
Summary:
Raccoon Stealer is an information stealer that primarily targets victim credentials and cryptocurrency wallets. The malware has been observed in cybercriminal forums since 2019 and is offered as a 'Malware-as-a-Service' (MaaS) threat. Despite its simplicity, Raccoon Stealer has been successful due to its focus on stealing data and credentials. The malware's distribution method includes malicious document attachments in unsolicited emails and the use of third-party exploit kits or malware families. The Raccoon Stealer has experienced periods of activity and hiatus. In October 2022, one of its main operators, Mark Sokolovsky, was arrested, leading to a temporary halt in the operation. However, the malware recently announced its return.[emaillocker id="1283"]
The technical details of Raccoon Stealer, including its behavior, capabilities, and its control panel hosted on a Tor onion service. The control panel allows subscribers to manage campaign configurations, generate malware payloads, and view stolen data. The post outlines various features and updates introduced in the control panel, including quicker searches for URLs, automatic bot blocking, reporting systems, and log statistics.The malware targets a wide range of applications, including browsers, email clients, and cryptocurrency wallets. After extracting data, Raccoon Stealer gathers it into a "Log.zip" folder and sends it to its command and control (C&C) server.
The Raccoon Stealer following a hiatus is causing concern, particularly within the financial sector, highlighting the potential danger for industries susceptible to data breaches and financial fraud. The emphasizes the importance of a proactive cybersecurity approach, combining advanced endpoint security, network monitoring, threat intelligence sharing, user awareness, and compliance with data protection regulations to counter information stealer malware effectively.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]