Raccoon Stealer is Back with a New Version

Raccoon Stealer has returned with a new V2 version, resuming activity after a pause linked to a key developer’s death. The update introduces a more automated, faster builder/admin panel, and a Cracked Software distribution approach, with ongoing monitoring advised as the campaign unfolds. #RaccoonStealer #RaccoonStealerV2 #CrackedSoftware #FakeCrackCampaign #KeysTool #Exploit #S2W_TALON

Keypoints

  • Raccoon Stealer V2 activity resumed in mid-2022 after a temporary suspension tied to the Russia-Ukraine conflict affecting a core developer.
  • V2 is advertised as fully automated (builder, log processing) and rewritten in C/C++ for speed, with low AV detection and 32/64‑bit support.
  • The distribution shifts to Cracked Software channels (e.g., KEYS TOOL) with redirectors and fake installers, continuing a pattern seen in prior campaigns.
  • The admin panel offers features like fast log processing, flexible search/filters, CSV export, and geo-aware browsing, with pricing of $275/month or $125/week.
  • Raccoon Stealer V2 uses a redesigned configuration format and hard-coded C2 addresses, differing from the JSON-based V1 and signaling ongoing customization.
  • Technical analysis shows V2 logs as being traded among criminals and notes the presence of a V2 signature in logs, suggesting active use and further evolution.
  • IoCs include multiple file hashes, DLLs, and URLs associated with the campaign, plus C2-related addresses and cracked-software distribution sites to watch.

MITRE Techniques

  • [T1027] Obfuscated/Compressed Data – RC4/Base64 string decryption used to conceal strings; Encrypted String: “VVsEvhkqyZGsN0Qv”; RC4 Key: “edinayarossiya”; Decrypted String: “cookies.txt” – “…Encrypted String: ‘VVsEvhkqyZGsN0Qv’… RC4 Key: “edinayarossiya”… Decrypted String: “cookies.txt””
  • [T1105] Ingress Tool Transfer – The stealer downloads libraries/tools from the C2 server (libs_ fields) to enable collection and operation – “Download normal library files required for collection from the C&C server by referring to the libs_ field included in the configuration information.”
  • [T1071.001] Web Protocols – C2 communications occur over HTTP(S); basic device info is posted to C2 and configuration is retrieved over HTTP POST-based channels – “POST / HTTP/1.1… machineId=[MachineGuid]|[Username]&configId=[RC4 Key…]”
  • [T1041] Exfiltration – Exfiltration of stolen data from the infected device to the C2 server over HTTP – “Exfiltrate stolen data from the infected device” and “POST /[token] HTTP/1.1”
  • [T1562.001] Impair Defenses – Create Mutex to prevent multiple instances; this is used to avoid re-run and maintain stealth – “Duplicate execution is prevented through mutex.”
  • [T1036] Masquerading – Distribution disguised as Cracked Software to evade naive defenses and users – “distributed in the same way as V1, disguised as Cracked Software”
  • [T1082] System Information Discovery – Locale check to identify Russian (ru) environment, indicating region-aware logic – “Locale Name” check: It collects the “Locale Name” of the infected device and checks whether the string “ru” is included.
  • [T1555.003] Credentials from Web Browsers – Data stored in the browser (credentials, cookies, autofill, etc.) and wallet/currency extensions are listed for collection – “Data stored in the browser: Credentials, Profile, Autofill, Cookies, Credit card information, etc.”

Indicators of Compromise

  • [IP] 2.58.56.247 – C2 server address used for configuration download and data exfiltration
  • [Domain] keystool.com – Cracked software distribution site used to host/load the Raccoon Stealer V2 campaign
  • [URL] http://2.58.56.247/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll – DLL download target; example of libs_ download
  • [URL] http://2.58.56.247/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/msvcp140.dll – DLL download target; example of libs_ download
  • [File] 4.exe – Example of the V2 executable/packer output mentioned in the technical analysis
  • [File] System Information.txt – Example of data collected during exfiltration
  • [Hash] 05a000d526a6e95be2b08e650394fa40 – MD5 for the Raccoon Stealer V2 sample
  • [Hash] 40daa898f98206806ad3ff78f63409d509922e0c482684cf4f180faac8cac273 – SHA-256 for the Raccoon Stealer V2 sample
  • [Hash] 6e5d7b8bc69145a2b65b4be1a2d66a8dbc579e54c09660c4070c5667192864bf – Appendix IoC hash

Read more: https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d