Raccoon Stealer

MITRE ATT&CK: S1148 View on attack.mitre.org

Aliases: Raccoon Stealer

First seen
2019-01-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
782 (782 malicious)
Last IoC activity
2026-09-02 02:07:15
Profile updated
2026-07-07 15:17:12

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

Raccoon Stealer is an information stealer malware family active since at least 2019 as a malware-as-a-service offering sold in underground forums. Raccoon Stealer has experienced two periods of activity across two variants, from 2019 to March 2022, then resurfacing in a revised version in June 2022.

Recent IoC activity

783 malicious indicators in Maltiverse are attributed to Raccoon Stealer (S1148). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 29b42c1815d533711f11ece6e07db9db.exe 2026-09-02 1
file sample 35E7888189D7515A2161DB1B7502C193.exe 2026-09-02 1
file sample 5707DDADA5B7EA6BEF434CD294FA12E1.exe 2026-09-02 1
file sample 2d59ec6d1d1541388eaa66015b3a5922.exe 2026-09-01 1
file sample 360f2daa601a407296f2a123346526c790bc1a03f974bad4379e0c534056182e.exe 2026-08-30 2
file sample d054432e74a1747393b2d000262c8652.exe 2026-08-30 1
file sample 8e602.Trojan.exe 2026-08-30 2
file sample c49079a991ee6716a9c8fc229d27200d.exe 2026-08-29 1
file sample tuc3.exe 2026-08-28 2
file sample c0190f427c134c069f949b4eb0dac8d8.exe 2026-08-27 1
file sample 558975be0d7c34879eb58a600f30e9c4.exe 2026-08-26 1
file sample 60caf2fbf0ca1f0207c2bad9306648a3743e3a70f148e6acf7dc64d92049cbc9 2026-08-25 2
file sample 880c87ff7f4bef57032202fb5d3255b1.exe 2026-08-25 1
file sample 5021c0258bf60f4ffe914b6955310b6c.exe 2026-08-24 1
file sample Delivery Note.exe 2026-08-24 1
file sample 2e066855f5af48f4402ee0134d5d2d7d.exe 2026-08-24 1
file sample 7a800cc6deb285c9a34b9a911c2720a0.exe 2026-08-24 1
file sample USPS Delivery Note.exe 2026-08-24 1
file sample 553b7d328390ed54db9af59e9e3ea2c9.exe 2026-08-24 1
file sample 8e314bedbae96da919e2a217a8840ffa.exe 2026-08-24 1

Detection coverage

  • 1 YARA rules
  • 292 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Data from Information Repositories (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Dynamic API Resolution (attack-pattern)
  • Supply Chain Compromise (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Automated Collection (attack-pattern)
  • Screen Capture (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • File Deletion (attack-pattern)
  • Query Registry (attack-pattern)
  • Software Discovery (attack-pattern)
  • Local Account (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Information Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

Detection rules

  • RUSSIANPANDA_Raccoonstealer (yara-rule)

Reports & references

  • medium.com — Raccoon Stealer Is Back With A New Version 5F436E04B20D (report)
  • blog.sekoia.io — Raccoon Stealer V2 Part 1 The Return Of The Dead (report)
  • MITRE ATT&CK — S1148 (report)

External references