Created by: lindbergh

Date created: 2022-12-16

Last edited: 2023-01-24

Description: Heatmap of instances of ATT&CK techniques for Raccoon Stealer based on recent public CTI reporting (sources in notes for each technique).

Techniques (40)

  • Account Discovery

    ID: T1087

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Application Layer Protocol

    ID: T1071

    Tactics: Command and Control

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    Raccoon Stealer Detection: A Novel Malware Version 2.0 Named RecordBreaker Offers Hackers Advanced Password-Stealing Capabilities

  • Archive Collected Data

    ID: T1560

    Tactics: Collection

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Command and Scripting Interpreter

    ID: T1059

    Tactics: Execution

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Credentials from Web Browsers

    ID: T1555.003

    Tactics: Credential Access

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Credentials In Files

    ID: T1552.001

    Tactics: Credential Access

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Data from Local System

    ID: T1005

    Tactics: Collection

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Deobfuscate/Decode Files or Information

    ID: T1140

    Tactics: Defense Evasion

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Drive-by Compromise

    ID: T1189

    Tactics: Initial Access

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Encrypted Channel

    ID: T1573

    Tactics: Command and Control

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Exfiltration Over C2 Channel

    ID: T1041

    Tactics: Exfiltration

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Exploitation for Client Execution

    ID: T1203

    Tactics: Execution

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Ingress Tool Transfer

    ID: T1105

    Tactics: Command and Control

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Input Capture

    ID: T1056

    Tactics: Credential Access, Collection

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Native API

    ID: T1106

    Tactics: Execution

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Non-Application Layer Protocol

    ID: T1095

    Tactics: Command and Control

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Non-Standard Port

    ID: T1571

    Tactics: Command and Control

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Obfuscated Files or Information

    ID: T1027

    Tactics: Defense Evasion

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • OS Credential Dumping

    ID: T1003

    Tactics: Credential Access

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Phishing

    ID: T1566

    Tactics: Initial Access

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • PowerShell

    ID: T1059.001

    Tactics: Execution

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Process Discovery

    ID: T1057

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Process Injection

    ID: T1055

    Tactics: Privilege Escalation, Defense Evasion

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Query Registry

    ID: T1012

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Registry Run Keys / Startup Folder

    ID: T1547.001

    Tactics: Persistence, Privilege Escalation

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Remote Access Software

    ID: T1219

    Tactics: Command and Control

    Description: https://blog.talosintelligence.com/raccoon-and-amadey-install-servhelper/

  • Remote System Discovery

    ID: T1018

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Screen Capture

    ID: T1113

    Tactics: Collection

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block,

    https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Software Discovery

    ID: T1518

    Tactics: Discovery

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • Software Packing

    ID: T1027.002

    Tactics: Defense Evasion

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Spearphishing Attachment

    ID: T1566.001

    Tactics: Initial Access

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Steal Web Session Cookie

    ID: T1539

    Tactics: Credential Access

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • System Information Discovery

    ID: T1082

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • System Location Discovery

    ID: T1614

    Tactics: Discovery

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • System Network Configuration Discovery

    ID: T1016

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • System Owner/User Discovery

    ID: T1033

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • System Service Discovery

    ID: T1007

    Tactics: Discovery

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • System Time Discovery

    ID: T1124

    Tactics: Discovery

    Description: https://www.cybereason.com/blog/research/hunting-raccoon-stealer-the-new-masked-bandit-on-the-block

  • Unsecured Credentials

    ID: T1552

    Tactics: Credential Access

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/

  • User Execution

    ID: T1204

    Tactics: Execution

    Description: https://blog.cyble.com/2021/10/21/raccoon-stealer-under-the-lens-a-deep-dive-analysis/