Raccoon might not be the cheapest option on the market but the malware had gained popularity among cybercriminals for its ability to target at least 60 applications, many of which are browsers we use today.
The Raccoon infostealer, also known as Racealer, has attracted a following in underground forums thanks to the aggressive marketing of its wide range of capabilities, use of bulletproof hosting and an easy-to-use backend. The malware is offered at a price of $200 a month and was first spotted by researchers from cybersecurity firm Cybereason in 2019.
While more expensive than other standalone, bareboned offerings, Raccoon's subscription-based model -- which includes technical support, bug fixes, and updates at a relatively cheap Malware-As-A-Service (MaaS) price point -- as well as its overall capabilities have made it a worthwhile investment for cybercriminals seeking to steal data and cryptocurrency.
A new analysis of the malware from Cyberark notes that many infostealers aren't generally sophisticated and use the same variety of techniques to steal information. However, in Raccoon's case, the C++ malware is able to steal data from 35 browsers and 60 overall applications.
According to Cyberark, Raccoon is generally delivered through phishing campaigns and exploit kits. Fraudulent emails sent to would-be victims contain Microsoft Office document attachments with malicious macros, whereas the exploit kits are usually hosted on websites.
Victims are profiled for any potential browser-based vulnerabilities and based on this analysis, they are redirected to the appropriate exploit kit.
See also:This easy-to-use information-stealing trojan malware is quickly gaining popularity among cybercriminals
The command-and-control (C2) server, necessary for the transfer of stolen information as well as for remote malware configuration updates, has its address hidden via several layers of encryption.
Raccoon is able to steal financial information, online credentials, PC data -- such as operating system types and versions, the language in use, and installed application lists -- cryptocurrency wallets, and browser information including cookies, history logs, and autofill content.
The malware targets a wide variety of popular Mozilla and Chromium browsers: Google Chrome, Google Chrome (Chrome SxS), Chromium, Xpom, Comodo Dragon, Amigo, Orbitum, Bromium, Nichrome, RockMelt, 360Browser, Vivaldi, Opera, Sputnik, Kometa, Uran, QIP Surf, Epic Privacy, CocCoc, CentBrowser, 7Star, Elements, TorBro, Suhba, Safer Browser, Mustang, Superbird, Chedot, Torch, Internet Explorer, Microsoft Edge, Firefox, WaterFox, SeaMonkey, and PaleMoon.
In addition, Raccoon attempts to compromise ThunderBird, Outlook, and Foxmail email clients.
Cyberark says the same procedure is in play for each target application. The malware will grab the application files containing sensitive data and copy it to a temp folder, perform routines to extract and decrypt information, write this content to a separate text file, and then send it off to a C2.
CNET:How schools are using kids' phones to track and surveil them
"In order to extract and decrypt the credentials from the applications, Raccoon downloads the specific DLLs for the applications," the researchers say. "The config JSON contains a URL from where the malware will download those libraries."
Cryptocurrency, too, is at risk. Raccoon will seek out Electrum, Ethereum, Exodus, Jaxx, Monero, and Bither wallets by scanning for their default application folders, and will also attempt to grab their wallet credentials.
Once Raccoon has stolen the data it requires, this information is compiled into a .zip archive file and sent to the C2. It may also act as a dropper for additional malware payloads.
TechRepublic:RSA president: Hackers have broken into our brains and created the wrong security story
The malware continues to be supported by a team and development is ongoing. Recently, Raccoon was also given the ability to steal FTP server credentials from FileZilla, UI errors were resolved, and the authors also created an option to encrypt custom malware builds from the UI for download as a DLL.
"Even though Raccoon is not the most sophisticated tool available, it is still very popular among cybercriminals and will likely continue to be," the researchers say. "What used to be reserved for more sophisticated attackers is now possible even for novice players who can buy stealers like Raccoon and use them to get their hands on an organization's sensitive data."
Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0
More here:
Raccoon malware targets massive range of browsers to steal your data and cryptocurrency - ZDNet
- New Bitcoin-Esque Cryptocurrency Named After Kanye West Launching [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Coinye West: A new cryptocurrency for the masses and an ode to Kanye [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Cryptocurrency gets hip: 'Coinye West' [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies, Such ... [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- AltCoins - Crypto()Currency - Cryptocurrency [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- CryptoCurrency.org [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- DimeCoin - The New Cryptocurrency - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Kanye West Sues Amazon, Others Over 'Coinye West' Cryptocurrency [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- $25,000 in Dogecoin raised to save the Jamaican bobsled team [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Gotangco: Is PH ready for Bitcoin and cryptocurrency? [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies ... [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Cryptominer.de Avalon 200GH/S Bitcoin Miner Asic 55nm Mining Cryptocurrency - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Cryptocurrency mining Rig build 1 - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Bitcoin Value and rise of the cryptocurrency - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- LeadCoin - Cryptocurrency - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Cryptocurrency Mining [Part 2] - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Cryptocurrency Mining [Part 1] - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Know How 74: Cryptocurrency - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Worlds First BITCOIN ATM Opens in Vancouver Canada - Is CryptoCurrency the Future Currency? - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- 42 Coin cryptocurrency contest - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- What is Bitcoin anyway? [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- The rise and rise of dogecoin, the internet's hottest cryptocurrency [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Cryptocurrency Mining Rigs by plugNmine - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- How Cryptocurrency, Crowdfunding And A Little Internet Altruism Saved Jamaica’s Hopes For Bobsled Gold [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Introducing Dogecoin the Greatest Cryptocurrency - Video [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Dogecoin - Wikipedia, the free encyclopedia [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Dummy plug for GPU for cryptocurrency mining - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- My first CryptoCurrency Miner up and running yet partially completed - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Thought of the Day - 01 / 28 / 2014 - CryptoCurrency - Dogecoin - What is this? - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Wall Street's Cryptocurrency Headquarters: Inside Bitcoin Center NYC - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- My Take on the Profitablity of Cryptocurrency - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Bitcoin steps a little closer to acceptance [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Bitcoin gets two hearings - and steps closer to acceptance [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Dogecoin cryptocurrency donors help send Indian athletes to Sochi [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- How To Create Your Own Cryptocurrency [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Cryptocurrency - Bitcoin Song (by 13inlet) - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Selling Dem Coins - How to convert your Cryptocurrency - Tutorial - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Dogecoin - From joke cryptocurrency to Bitcoin rival - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- New York to Regulate Bitcoin: Is the Cryptocurrency Biz Like "the Wild West?" - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Dogecoin: A 2014 Cryptocurrency Revolution - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- U.S. Treasury Goes Easy on the Bitcoin [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- WoW - Dogecoin The #1 Cryptocurrency - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- The Dark Horse of Cryptocurrency - Franko - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Think Bitcoin is Expensive? Try 42 Coin, The £100,000 Cryptocurrency [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- We Love DogeCoin The #1 Cryptocurrency - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Cryptocurrency Hackathon will talk Bitcoin, Dogecoin and more for coders and novices [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Dogecoin Kiss: An original song about the world's friendliest Cryptocurrency - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Cryptocurrency Hackathon will talk Bitcoin, Dogecoin and ... [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Dogecoin: cryptocurrency passes Bitcoin to reach the moon - Video [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- ZedCoin new CryptoCurrency - Video [Last Updated On: February 7th, 2014] [Originally Added On: February 7th, 2014]
- LiteCoin Trading Robot LTC Robot Cryptocurrency Trading Robot - Video [Last Updated On: February 7th, 2014] [Originally Added On: February 7th, 2014]
- Apple approves Dogecoin app after removing Bitcoin app [Last Updated On: February 8th, 2014] [Originally Added On: February 8th, 2014]
- Cryptocurrency - Wikipedia, the free encyclopedia [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Cryptocurrency, Permaculture, and 3D Printing - Video [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Litecoin Robot | The World's First Litecoin Trading Bot Review | Scrypt Money | Cryptocurrency LTC - Video [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Bitcoin Slump Shows the $8 Billion Cryptocurrency Lacks Mature Infrastructure [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- WE WIN COINS - EXCLUSIVE CRYPTOCURRENCY BETTING SOFTWARE TO INCREASE WINS - Video [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- Dogecoin Value Soars $40M in Value Following Chinese Exchange Opens [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- Cryptocurrency News Round-Up: Protests at Mt Gox as ... [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- Dogecoin Soars $40M in Value Following Chinese Exchange Opens [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Is the new cryptocurrency PotCoin worth it? A Crypto-Market-News review of PotCoin - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Cryptocurrency Expert - Lorraine Murphy - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- CryptoCurrency Con 2013 - Cathy Reisenwitz - Why a Free Society Needs a Free Money - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- How to transfer Bitcoins from one cryptocurrency exchange to another cryptocurrency exchange - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Cryptocurrency Explained The Tech Guy 1046127 - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- CryptoCurrency Hacking Hard - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- ** UPDATE ** Computer, Cryptocurrency, Games and More!! - Video [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- The glitch that will help kill Bitcoin [Last Updated On: February 16th, 2014] [Originally Added On: February 16th, 2014]
- Skinny Puppy at GITMO, NSA Myths, Dogecoin and Cryptocurrency #TMS 2/15/2014 - Video [Last Updated On: February 16th, 2014] [Originally Added On: February 16th, 2014]
- PotCoin, the cryptocurrency for the Cannabis Industrie - Video [Last Updated On: February 16th, 2014] [Originally Added On: February 16th, 2014]
- cryptocurrency mining rig - Video [Last Updated On: February 17th, 2014] [Originally Added On: February 17th, 2014]
- Quark - The Best Cryptocurrency - Video [Last Updated On: February 17th, 2014] [Originally Added On: February 17th, 2014]
- Cryptocurrencies: I Lived on Bitcoin for a Week - Video [Last Updated On: February 17th, 2014] [Originally Added On: February 17th, 2014]
- Cryptocurrencies: The State of Play - Video [Last Updated On: February 17th, 2014] [Originally Added On: February 17th, 2014]
- AMD graphics card pricing skyrockets due to cryptocurrency mining, could kill AMD’s gaming efforts [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- Could there be a $50,000 bitcoin? [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- CRYPTOCURRENCY - Bitcoin Overview... - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- CRYPTOCURRENCY - Money Changer Den of Thieves, The Federal Reserve - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- How to Buy PotCoins Part 2: Make a cryptocurrency trading account at swissex.com to buy PotCoin - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- BitPagar cryptocurrency - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]