LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1148: Raccoon Stealer

Raccoon Stealer is an information stealer malware family active since at least 2019 as a malware-as-a-service offering sold in underground forums. Raccoon Stealer has experienced two periods of activity across two variants, from 2019 to March 2022, then resurfacing in a revised version in June 2022.[1][2]

EnterpriseS1148MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S1148: Raccoon Stealer describes [Raccoon Stealer](https://attack.mitre.org/software/S1148) is an information stealer malware family active since at least 2019 as a malware-as-a-service offering sold in underground forums. [Raccoon Stealer](https://attack.mitre.org/software/S1148) has experienced two periods of activity across two variants, from 2019 to March 2022, then resurfacing in a revised version in June 2022.(Citation: S2W Racoon 2022)(Citation: Sekoia Raccoon1 2022)

Executive priority

S1148: Raccoon Stealer is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S1148: Raccoon Stealer by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S1148: Raccoon Stealer appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Raccoon Stealer

Raccoon Stealer is an information stealer malware family active since at least 2019 as a malware-as-a-service offering sold in underground forums. Raccoon Stealer has experienced two periods of activity across two variants, from 2019 to March 2022, then resurfacing in a revised version in June 2022.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

24 rows
DomainIDNameRelationship / procedure
EnterpriseT1033System Owner/User Discovery

Raccoon Stealer gathers information on the infected system owner and user.[1][2]CitationSekoia Raccoon2 2022

EnterpriseT1071.001Web ProtocolsSub-technique

Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions.[1][2]CitationSekoia Raccoon2 2022

EnterpriseT1005Data from Local System

Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes.[1]CitationSekoia Raccoon2 2022

EnterpriseT1124System Time Discovery

Raccoon Stealer gathers victim machine timezone information.[1]CitationSekoia Raccoon2 2022

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection.[1][2]CitationSekoia Raccoon2 2022

EnterpriseT1105Ingress Tool Transfer

Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.[1]CitationSekoia Raccoon2 2022

EnterpriseT1020Automated Exfiltration

Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes.[1][2]CitationSekoia Raccoon2 2022

EnterpriseT1213Data from Information Repositories

Raccoon Stealer gathers information from repositories associated with cryptocurrency wallets and the Telegram messaging service.CitationSekoia Raccoon2 2022

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers.CitationSekoia Raccoon2 2022

EnterpriseT1560Archive Collected Data

Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration.CitationSekoia Raccoon2 2022

EnterpriseT1027.007Dynamic API ResolutionSub-technique

Raccoon Stealer dynamically links key WinApi functions during execution.[2]CitationSekoia Raccoon2 2022

EnterpriseT1195Supply Chain Compromise

Raccoon Stealer has been distributed through cracked software downloads.[1]

EnterpriseT1614System Location Discovery

Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present.[1]

EnterpriseT1119Automated Collection

Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers.[1][2]CitationSekoia Raccoon2 2022

EnterpriseT1113Screen Capture

Raccoon Stealer can capture screenshots from victim systems.[1]CitationSekoia Raccoon2 2022

EnterpriseT1041Exfiltration Over C2 Channel

Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration.[1][2]CitationSekoia Raccoon2 2022

EnterpriseT1070.004File DeletionSub-technique

Raccoon Stealer can remove files related to use and installation.[2]

EnterpriseT1012Query Registry

Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key.[2]CitationSekoia Raccoon2 2022

EnterpriseT1518Software Discovery

Raccoon Stealer is capable of identifying running software on victim machines.[2]CitationSekoia Raccoon2 2022

EnterpriseT1087.001Local AccountSub-technique

Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`.CitationSekoia Raccoon2 2022

EnterpriseT1539Steal Web Session Cookie

Raccoon Stealer attempts to steal cookies and related information in browser history.CitationSekoia Raccoon2 2022

EnterpriseT1140Deobfuscate/Decode Files or Information

Raccoon Stealer uses RC4-encrypted, base64-encoded strings to obfuscate functionality and command and control servers.[1][2]

EnterpriseT1082System Information Discovery

Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information.[1]CitationSekoia Raccoon2 2022

EnterpriseT1083File and Directory Discovery

Raccoon Stealer identifies target files and directories for collection based on a configuration file.[1]CitationSekoia Raccoon2 2022

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1015: Scattered Spider

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. [1] [2] The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. [2] Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. [3] [4] [5] Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. [6]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.1
Created
Modified
Raw hash
3213619188d3cc4a...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.1Current bundle3213619188d3…
19.11.1Older bundle3213619188d3…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    S2W Racoon 2022

    S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.

    Open source URL
  2. [2]
    Sekoia Raccoon1 2022

    Quentin Bourgue, Pierre le Bourhis, & Sekoia TDR. (2022, June 28). Raccoon Stealer v2 - Part 1: The return of the dead. Retrieved August 1, 2024.

    Open source URL
  3. [3]
    mitre-attackS1148
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.