Malware.View on attack.mitre.org
Raccoon Stealer is an information stealer malware family active since at least 2019 as a malware-as-a-service offering sold in underground forums. Raccoon Stealer has experienced two periods of activity across two variants, from 2019 to March 2022, then resurfacing in a revised version in June 2022.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes. |
| T1012 Query Registry |
Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key. |
| T1020 Automated Exfiltration |
Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes. |
| T1027.007 Dynamic API Resolution |
Raccoon Stealer dynamically links key WinApi functions during execution. |
| T1027.013 Encrypted/Encoded File |
Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection. |
| T1033 System Owner/User Discovery |
Raccoon Stealer gathers information on the infected system owner and user. |
| T1041 Exfiltration Over C2 Channel |
Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration. |
| T1070.004 File Deletion |
Raccoon Stealer can remove files related to use and installation. |
| T1071.001 Web Protocols |
Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions. |
| T1082 System Information Discovery |
Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information. |
| T1083 File and Directory Discovery |
Raccoon Stealer identifies target files and directories for collection based on a configuration file. |
| T1087.001 Local Account |
Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`. |
| T1105 Ingress Tool Transfer |
Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft. |
| T1113 Screen Capture |
Raccoon Stealer can capture screenshots from victim systems. |
| T1119 Automated Collection |
Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.