Agent Racoon

First seen
2020-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 13:09:50

Targeted industries: education-and-nonprofits government-and-public-sector

Targeted regions: country_code:us country_code:ae country_code:za

Context

Agent Racoon is a .NET-based backdoor malware that leverages DNS for covert C2 communication, employing randomized subdomains and Punycode encoding to evade detection. It features encrypted communication using a unique key per sample, supports remote command execution, and facilitates file transfers. Despite lacking an inherent persistence mechanism, it relies on external methods like scheduled tasks for execution. The malware, active since at least 2020, has targeted organizations in the U.S., Middle East, and Africa, including non-profits and government sectors. It disguises itself as legitimate binaries such as Google Update and MS OneDrive Updater, using obfuscation techniques like Base64 encoding and timestamp modifications to avoid detection​.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Apt_Agent_Racoon_Strings (yara-rule)

Reports & references

  • Palo Alto Unit 42 — Operation Diplomatic Specter (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Agent Racoon (report)
  • Palo Alto Unit 42 — New Toolset Targets Middle East Africa Usa (report)

External references