Author

Topic: [Read]: Raccoon is back with V2 that targets cryptocurrency wallets (Read 58 times)

hero member
Activity: 2660
Merit: 551
Raccoon Stealer 2.0 is back. It was reported that the threat actors operation suddenly stop around March 2022 as it was reported that one of it's developer was killed in the Ukraine-Russia war.

However, SEKOIA.IO, a threat research team, recently discovered that version 2.0 was already released in the wild. What makes this malware very dangerous is that it targets most if not all desktop crypto wallets including,

Quote
(MetaMask, TronLink, BinanceChain, Ronin, Exodus, Atomic, JaxxLiberty, Binance, Coinomi, Electrum, Electrum-LTC, ElectronCash, etc.);



Mode of Infection is downloading fake installers and crack softwares like:

  • F‑Secure FREEDOME VPN installer (F-Secure Freedome VPN 2.50.23.0.licensesrv.exe_KaHCr.exe)
  • R-Studio Network installer (R-Studio.v9.0.190312.licencekey.exe_v3G9m.exe)
  • Proton VPN installer (ProtonVPN.exe)

It's very dangerous to us since majority of could have been using VPN (including myself).

For a detailed technical explanation you can read it here: https://blog.sekoia.io/raccoon-stealer-v2-part-1-the-return-of-the-dead/
Jump to: