Created by: lindbergh

Date created: 2022-12-16

Last edited: 2023-01-24

Description: Heatmap of instances of ATT&CK techniques for Raccoon Stealer based on recent public CTI reporting (sources in notes for each technique).

Techniques (40)

  • Account Discovery

    ID: T1087

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Application Layer Protocol

    ID: T1071

    Tactics: Command and Control

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    Raccoon Stealer Detection: A Novel Malware Version 2.0 Named RecordBreaker Offers Hackers Advanced Password-Stealing Capabilities

  • Archive Collected Data

    ID: T1560

    Tactics: Collection

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Command and Scripting Interpreter

    ID: T1059

    Tactics: Execution

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Credentials from Web Browsers

    ID: T1555.003

    Tactics: Credential Access

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Credentials In Files

    ID: T1552.001

    Tactics: Credential Access

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Data from Local System

    ID: T1005

    Tactics: Collection

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Deobfuscate/Decode Files or Information

    ID: T1140

    Tactics: Defense Evasion

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Drive-by Compromise

    ID: T1189

    Tactics: Initial Access

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Encrypted Channel

    ID: T1573

    Tactics: Command and Control

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Exfiltration Over C2 Channel

    ID: T1041

    Tactics: Exfiltration

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Exploitation for Client Execution

    ID: T1203

    Tactics: Execution

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Ingress Tool Transfer

    ID: T1105

    Tactics: Command and Control

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Input Capture

    ID: T1056

    Tactics: Credential Access, Collection

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Native API

    ID: T1106

    Tactics: Execution

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Non-Application Layer Protocol

    ID: T1095

    Tactics: Command and Control

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Non-Standard Port

    ID: T1571

    Tactics: Command and Control

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Obfuscated Files or Information

    ID: T1027

    Tactics: Defense Evasion

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • OS Credential Dumping

    ID: T1003

    Tactics: Credential Access

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Phishing

    ID: T1566

    Tactics: Initial Access

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • PowerShell

    ID: T1059.001

    Tactics: Execution

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Process Discovery

    ID: T1057

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Process Injection

    ID: T1055

    Tactics: Privilege Escalation, Defense Evasion

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Query Registry

    ID: T1012

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Registry Run Keys / Startup Folder

    ID: T1547.001

    Tactics: Persistence, Privilege Escalation

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Remote Access Software

    ID: T1219

    Tactics: Command and Control

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Remote System Discovery

    ID: T1018

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Screen Capture

    ID: T1113

    Tactics: Collection

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Software Discovery

    ID: T1518

    Tactics: Discovery

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Software Packing

    ID: T1027.002

    Tactics: Defense Evasion

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Spearphishing Attachment

    ID: T1566.001

    Tactics: Initial Access

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Steal Web Session Cookie

    ID: T1539

    Tactics: Credential Access

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • System Information Discovery

    ID: T1082

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • System Location Discovery

    ID: T1614

    Tactics: Discovery

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • System Network Configuration Discovery

    ID: T1016

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • System Owner/User Discovery

    ID: T1033

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • System Service Discovery

    ID: T1007

    Tactics: Discovery

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • System Time Discovery

    ID: T1124

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Unsecured Credentials

    ID: T1552

    Tactics: Credential Access

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • User Execution

    ID: T1204

    Tactics: Execution

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

infostealers-logo
favicon__1_ removebg-png

BE THE FIRST TO KNOW

Stay informed with the latest insights in our Infostealers weekly report.

Receive immediate notification if your email is involved in an infostealer infection.

No Spam, We Promise

favicon__1_ removebg-png

BE THE FIRST TO KNOW

Stay informed with the latest insights in our Infostealers weekly report.

Receive immediate notification if your email is involved in an infostealer infection.

No Spam, We Promise