Raccoon Stealer Under the Lens: A Deep-dive Analysis
ID: b2e28a71-f3c2-5f32-abce-9ecfa2cf9a2b
STIX ID: report--b2e28a71-f3c2-5f32-abce-9ecfa2cf9a2b
Feed Name: Cyble Blog
Threat Score
Raccoon Stealer is an actively observed infostealer that retrieves its C2 via a Telegram channel, decrypts configuration with RC4, downloads modules (saved as sqlite3.dll) to parse browser SQLite databases and harvest credentials, wallets, and other sensitive data, then exfiltrates results and self-deletes; the report provides static/dynamic analysis, IoCs (SHA-256, C2 IP, Telegram channel), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
