Infostealer
Raccoon Stealer
Infostealer
16 detections found
Also known as: Racoon Stealer, RecordBreaker, Raccoon Stealer V2, Racealer
Raccoon Stealer is a Windows information-stealing malware sold as malware-as-a-service (roughly $200/month) since 2019, targeting browser passwords, cookies and autofill data, cryptocurrency wallets, and Telegram data. Administrator Mark Sokolovsky was arrested in the Netherlands in March 2022 (infrastructure was dismantled at that time), extradited to the U.S. in February 2024, and sentenced in December 2024 to 60 months in federal prison for his role running the service, which was tied to over 52 million stolen credentials; a revised version of the malware nonetheless resumed operating from June 2022 onward.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- Raccoon Stealer, Software S1148 — MITRE ATT&CK
- US v. Mark Sokolovsky (case page) — U.S. Department of Justice, W.D. Texas
- Ukrainian National Sentenced to Federal Prison in Raccoon Infostealer Cybercrime Case — U.S. Department of Justice, W.D. Texas