logo

The footprints of Raccoon

ID: 5c9c991a-8cde-5747-ae56-3379bab17f43

STIX ID: report--5c9c991a-8cde-5747-ae56-3379bab17f43

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2020-12-07

Date Updated: 2026-04-27

...
...

Group-IB analyzed a multi-stage 2020 malicious campaign attributed to FakeSecurity operators that distributed Raccoon stealer (and earlier Vidar) via malicious Office macros, Mephistophilus phishing pages, and loaders (Buer, Smoke); the stealer exfiltrates passwords, cookies, payment card data and crypto wallets and uses Telegram channels to update C2 addresses. The report provides timelines of four waves, infrastructure and WHOIS linkages, dozens of domains and IP IoCs, examples of malicious samples and behaviors (including RAT AveMaria), and mitigation recommendations mapped to MITRE ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.