However, SEKOIA.IO, a threat research team, recently discovered that version 2.0 was already released in the wild. What makes this malware very dangerous is that it targets most if not all desktop crypto wallets including,
Mode of Infection is downloading fake installers and crack softwares like:
- F‑Secure FREEDOME VPN installer (F-Secure Freedome VPN 2.50.23.0.licensesrv.exe_KaHCr.exe)
- R-Studio Network installer (R-Studio.v9.0.190312.licencekey.exe_v3G9m.exe)
- Proton VPN installer (ProtonVPN.exe)
It's very dangerous to us since majority of could have been using VPN (including myself).
For a detailed technical explanation you can read it here: https://blog.sekoia.io/raccoon-stealer-v2-part-1-the-return-of-the-dead/