Raccoon Info Stealer: The Return of a Legend
Blog

Raccoon Info Stealer: The Return of a Legend

Background

In recent years, info stealers have become very popular with cybercriminals due to the ease and simplicity of operation, affordability of most info stealers sold on the Dark Web, and high functionality1. Raccoon Info Stealer is a great example of a successful Malware-as-a-Service product that managed to gain trust and reputation among cybercriminals. Raccoon has launched its sales in April 2019 on three most prominent Russian-speaking underground forums – Exploit2, XSS3 and WWH4. Since then, it managed to obtain hundreds of devoted customers and positive reviews on the underground forums. According to the research we conducted in January 2023, out of almost 1.1 billion of info stealer logs5 available for free on the underground forums and marketplaces in 2022, 10.2% (112 million) were originated from Raccoon.

Raccoon Stealer official thread on WWH forum
Raccoon Stealer official thread on WWH forum

However, in 2022 Raccoon has suffered a series of failures that led to the shutdown of its operations in February 2023. First, in March 2022 the vendor of Raccoon Stealer has announced that one of its key developers was killed during one of the rocket attacks that Russian conducted against Ukraine. As a result, Raccoon had temporarily ceased its operations, however in June 2022 Raccoon made a comeback with v2. In October 2022, a 26-year-old Ukrainian national named Mark Sokolvsky was arrested in the Netherlands. He was charged for involvement in the Raccoon Info Stealer cybercrime operation. While this event didn’t prevent the stealer from continuing its operations, many cybercriminals called to avoid from working with Raccoon, since they suspected the service could be compromised by law enforcement. Finally, in February 2023, an arbitration dispute against Raccoon Stealer was opened on Exploit forum. According to this dispute, the vendor of Raccoon defaulted on his obligations to one of the forum members and refused to pay a penalty. As a result of this arbitration dispute, on February 7th, 2023, Raccoon Stealer was banned on Exploit and other underground communities such as XSS and went off the radars.

The posting of Exploit forum admin where he notifies that Raccoon Stealer is banned on forum for not paying its obligations
The posting of Exploit forum admin where he notifies that Raccoon Stealer is banned on forum for not paying its obligations

The Comeback

On August 14th, 2023, after more than six month of silence, Raccoon made an announcement on XSS forum that they are back with an updated version of a stealer.

Raccoon's announcement on XSS forum
Raccoon’s announcement on XSS forum

The next day, an administrator of Exploit forum made a posting where he explained that a very reputable Russian-speaking threat actor, the owner of ransomware-oriented RAMP forum6 – “Stallman” has vouched for Raccoon Stealer, and that if the vendor deposits 1BTC on Exploit and XSS forums, the ban will be removed. After the deposit was made, Raccoon was allowed to advertise its new version on these two forums.

Explanation of Exploit forum admin regarding the return of Raccoon
Explanation of Exploit forum admin regarding the return of Raccoon

Raccoon V.2.3.0

The new version 2.3.0 of Raccoon Stealer includes the following updates:

  1. Quick search function: an optimized search engine allows the user to find a necessary URL in millions of stealer logs within a couple of seconds.
  2. Automated blocking of honeypots and anti-virus scanners: the system identifies suspicious activity of the infected devices (bots), such as multiple pings from the same IP address or IP range, blocks such devices and removes them from the botnet admin panel.
  3. Activity indicators: every infected device (bot) has an activity indicator that indicates if the device (bot) belongs to a human or used by various anti-virus scanners or honeypots.
  4. Reporting system: every infected device’s (bot’s) IP address or IP range can be reported as belonging to a honeypot, anti-virus scanner or other “not legitimate” victim.
  5. Logs statistics: the detailed statistics of stealer victims by their geo-location. In addition, detailed charts of number of infected devices by day/week/month/year.
  6. Bandwidth increase: stealer’s bandwidth was increasedby 60%. Traffic limit on reverse proxies was increased from 125MB to 200MB. The size of a single log was increased from 150MB to 250MB.
  7. Malware build7: stealer’ssource code was optimized, and all the bugs were fixed and patched. The file became FUD (Fully Undetectable) for Windows Defender and most of the anti-viruses. The current file size varies between 90KB to 120KB.
  8. Chrome update: all the bugs for Chrome browser versions of 114 and above were fixed.

Conclusions

It is too soon to tell if the unexpected comeback of Raccoon Stealer will have a meaningful impact on the info stealers ecosystem, especially given that such flagships as Redline Stealer still exist and rule the market. In addition, it is hard to say whether the vouching of very reputable members of cyber underground, and the total deposit of 2BTC will help to wash Raccoon’s reputation that was spoiled with the latest events and six months forums ban.

However, Raccoon’s vendors invested a lot of recourses and efforts to improve their product, make it more user friendly and less detectable by anti-viruses. With that said, the information security industry should not ignore that comeback and pay closer attention to stealer’s operations and possible harm it can cause.

* Disclaimer: This document is provided ‘as is’ for informational purposes only, without any warranties of any kind regarding any information contained within.



1For more insights on info stealers please refer to our blog post “Info Stealers: Cheap But Dangerous”
2www.exploit.in
3www.xss.is
4www.wwh-club.link
5All the data stolen by an info stealer from victim’s device after its infection.
6http://rampjcdlqvgkoz5oywutpo6ggl7g6tvddysustfl6qzhr5osr24xxqqd.onion
7Converted source code to a single standalone file that can be run on a victim’s device.