EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/criminal-hacking/raccoon-stealer
214/430

File EL-0217HighOngoingCriminal Hacking / Credential Theft / InfoStealer

Raccoon Stealer

Also filed as Raccoon Stealer Malware · Raccoon Stealer Trojan

Raccoon Stealer is a sophisticated info-stealer malware designed to compromise endpoints and exfiltrate sensitive data. It targets credentials, browser data, and other personal information for sale on the dark web. The malware is known for its modular design and ability to evade detection on various operating systems.

  • #infostealer
  • #credential-theft
  • #ransomware
  • #malware
  • #raccoon-stealer
Notoriety7/10
Event
1 Jan 2019
Disclosed
1 Jan 2019
Target
Global End Users
Actor
Raccoon Operators
Scale
Variable (depends on the victim's data stored)
Status
Ongoing

01Summary

Raccoon Stealer operates by compromising user endpoints, typically through phishing campaigns or exploiting unpatched vulnerabilities. Once installed, it systematically searches the compromised machine for valuable data, including saved passwords from browsers (Chrome, Firefox, Edge), cryptocurrency wallet keys, and session tokens. The malware employs anti-analysis techniques to frustrate security researchers and often communicates with Command and Control (C2) infrastructure using encrypted channels. The stolen data is then packaged and sold to criminal groups, making it a key component in the modern cybercrime ecosystem. Its modularity allows threat actors to adapt it quickly to new operating systems and security measures.

02Background

The emergence of Raccoon Stealer reflects the increasing monetization of personal data in the cybercrime economy. It represents a shift from simple disruptive attacks to highly targeted, financially motivated espionage operations. These types of stealers are often sold as Ransomware-as-a-Service (RaaS) components, lowering the barrier to entry for less skilled criminals.

03Key revelations

  1. 01The ability to steal credentials across multiple major browser platforms (Chrome, Firefox, Edge).
  2. 02The modular architecture allows for rapid adaptation to new security environments.
  3. 03The primary goal is the monetization of stolen data on underground marketplaces.

04Technical analysis

Raccoon Stealer typically utilizes a combination of techniques, including memory scraping, keylogging, and API hooking, to gather data. Its payload often includes modules for specific data types (e.g., browser module, crypto module). The malware communicates with C2 servers, often using HTTPS to blend in with legitimate traffic, and frequently attempts to establish persistence through registry modifications or scheduled tasks.

Attack vector
Phishing emails, malicious downloads, or exploitation of vulnerable web services.
Attack method
Credential harvesting and data exfiltration.
Initial access
Phishing/Malicious Payload Delivery
Lateral movement
Network reconnaissance (if advanced modules are used)
Persistence
Registry Run Keys / Scheduled Tasks
Exfiltration
Encrypted HTTPS communication to C2 servers
Tool / malware
Raccoon Stealer
Malware family
InfoStealer
Malware type
Stealer

MITRE ATT&CK techniques

  • T1056.001
  • T1566.001
  • T1003

05Threat actor

Raccoon Operators are a financially motivated cybercrime group specializing in developing and distributing sophisticated info-stealers. They operate in a highly competitive market, constantly updating their tools to evade the latest security patches and detection methods.

Aliases

  • Raccoon Stealer Group

MITRE groups

  • T1056.001
  • T1566.001
  • T1003

Attribution sources

  • Security Vendors
  • Threat Intelligence Reports

06Victims and impact

Additional victims

  • Corporate Networks

Countries affected

  • Global

07Data exposed

Data types

  • Credentials
  • Passwords
  • Browser History
  • Session Tokens
  • Cryptocurrency Keys
  • PII

08Financial damage

Damage is estimated based on the potential loss of corporate intellectual property and identity theft costs.

09Timeline

  1. 2019-01-01Initial reports of Raccoon Stealer activity and capability demonstration.

10Reaction and fallout

Public reaction

The public reaction has been one of increased caution regarding online credentials and the necessity of using multi-factor authentication (MFA). Security awareness campaigns have intensified to warn users about sophisticated info-stealers.

Political impact

The prevalence of such stealers increases pressure on governments to mandate stronger, non-SMS-based MFA solutions across critical infrastructure.

11Legal

Law enforcement agencies are actively tracking the infrastructure used by these groups, but attribution and prosecution remain extremely difficult due to the decentralized nature of the cybercrime ecosystem.

Civil lawsuits

  • Class-action lawsuits against compromised services or companies failing to protect user data.

12Aftermath

Policy changes

  • Increased industry focus on password managers and hardware security keys (e.g., YubiKey) to mitigate credential theft.

Regulatory changes

  • Stricter enforcement of data breach notification laws (e.g., GDPR, CCPA).

Security improvements

  • Mandatory implementation of MFA for all critical accounts.
  • Use of anti-malware solutions with behavioral analysis capabilities.

13Significance and legacy

Significance

Raccoon Stealer exemplifies the maturity of the cybercrime industry, moving beyond simple vandalism to highly specialized, profit-driven data theft. It highlights the critical vulnerability of user credentials and the global reliance on digital identity, making it a benchmark for modern info-stealer malware.

Legacy

The existence and success of Raccoon Stealer have accelerated the adoption of zero-trust security models and hardware-backed authentication methods. It has also fueled the development of advanced endpoint detection and response (EDR) tools capable of detecting behavioral anomalies associated with data scraping.

14Disclosure and media

Authentication
Malware Analysis

Media partners

  • Security News Outlets

Publishing organisations

  • Threat Intelligence Firms

15Field notes

  1. 01The malware's modular design allows it to target specific data types without needing a full recompile.
  2. 02It often attempts to bypass security software by injecting code into legitimate processes (process hollowing).

16Resolution

The malware is constantly updated and re-released by its operators, making a permanent 'resolution' impossible; defense relies on continuous patching and behavioral monitoring.

17Sources

Official documents

  • Security Vendor Threat Reports

References

  1. [1]Mandiant Threat Reports
  2. [2]CrowdStrike Intelligence Briefings
Fact sheetEL-0217

Dates

Event
1 Jan 2019
Started
1 Jan 2019
Discovered
1 Jan 2019
Disclosed
1 Jan 2019
Ongoing
No

Target

Organisation
Global End Users
Type
Individual
Sector
General Consumer
Country
Global

Actor

Name
Raccoon Operators
Type
Criminal Gang
Motivation
Financial gain through credential theft and data sale
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Variable (depends on the victim's data stored)
Sensitivity
Confidential
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.