A new breed of easy-to-use malware trojan, Raccoon is becoming popular among cybercriminals, providing them with simple ways to steal credit card data, passwords, and cryptocurrency – and has already infected hundreds of thousands of Windows users around the world.
Raccoon Stealer first appeared in April of this year and quickly became very popular on underground forums.
Cybereason researchers have been tracking Raccoon since its first appearance and note that, while not sophisticated, it is aggressively marketed to potential criminal users by providing them with an easy-to-use back end, along with bulletproof hosting and 24/7 support – all for the price of $200 per month.

This could be considered a high price compared to other dark web offerings, but users are likely to be compensated considering the financial and personal data that can be stolen using the malware.
Raccoon's flexible nature allows it to be delivered to victims in many ways, but it is most commonly distributed through exploit kits, phishing , and corrupted software downloads .
Phishing attacks use an Office document to deliver the malware via email, while Raccoon is also known to deliver itself in compromised versions of legitimate software downloaded from third-party websites.
After a successful infection, Raccoon begins communicating with a command-and-control server to gain access to the resources needed to carry out its malicious activity. At this stage, it also gathers the locale settings on the target machine and if it detects that the language is Russian, Ukrainian, Belarusian, Kazakh, Kyrgyz, Armenian, Tajik, or Uzbek, it will terminate its activity.
This, along with analysis of the creators' posts on underground forums, led researchers to believe that Raccoon's authors are Russian-speaking and likely based in Russia. It is common for malware originating from Russia and surrounding countries to avoid targeting Russian users.
Once installed on a target machine, Raccoon can take screenshots, steal system information, steal information from browsers, including login information and banking details, as well as intercept emails and steal cryptocurrency wallets.
The code behind Racoon is not very sophisticated, but the malware's capabilities combined with its ease of use allow attackers to steal large amounts of data from individuals or businesses, which they can either sell on the dark web or exploit in attacks.
"Racoon, like other information spies, pose significant risks to both individuals and organizations. Any malware designed to steal passwords and personal information from browsers and email programs could cause great damage to its victims," Assaf Dahan said.
Raccoon receives regular updates from its authors, and analysis of threads advertising the malware on underground forums suggests that the developers are willing to listen to users for ideas about new functionality. For example, several forum users have suggested adding a keylogger , and Raccoon's authors responded that they were "considering" adding it in the future.
Although the Raccoon malware is relatively new, it is quickly gaining traction among cybercriminals and has already been used to infect hundreds of thousands of endpoints across North America, Europe, and Asia. And the way it is offered as a service could lead to a significant threat to internet.
However, despite its growing popularity, Racoon can be prevented: it uses known exploits to infect victims, so if users have applied security updates to software , they should be able to stay safe from this malware attack.
