Raccoon Stealer Bundles Malware, Propagates Via Google SEO
#1
Information 
Quote:Criminals behind the Raccoon Stealer platform have updated their services to include tools for siphoning cryptocurrency from a target’s computer and new remote access features for dropping malware and scooping up files.
 
The stealer-as-a-service platform, whose customers are typically rookie hackers, offers turnkey services for pilfering browser-stored passwords and authentication cookies. According to new research from Sophos Labs published Tuesday, the platform has received a noteworthy update that includes new tools and distribution networks to boost infected targets.
 
For starters, Raccoon Stealer has pivoted from inbox-based infections to ones that leverage Google Search. According to Sophos, threat actors have been proficient in their optimization of malicious web pages to rank high in Google search results. The bait to lure victims in this campaign is software pirating tools such as programs to “crack” licensed software for illicit use or “keygen” programs that promise to generate registration keys to unlock licensed software.
 
“While the sites advertised themselves as a repository of ‘cracked’ legitimate software packages, the files delivered were actually disguised droppers. Clicking on the links to a download connected to a set of redirector JavaScripts hosted on Amazon Web Services that shunt victims to one of multiple download locations, delivering different versions of the dropper,” wrote Yusuf Polat and Sean Gallagher, both senior threat researchers at Sophos, who authored the report.

Read more: Raccoon Stealer Bundles Malware, Propagates Via SEO | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AirVPN
AirVPN - Toronto (On...jasonX — 09:15
Webroot SecureAnywhere 9.0.40.53
Webroot SecureAnyw...harlan4096 — 07:27
Java Runtime Environment 8.0 Update 461
Java Runtime Envir...harlan4096 — 07:25
AMD launches quad-core Ryzen AI 5 330 ba...
AMD releases Krack...harlan4096 — 07:24
Antivirus Removal Tool 2025.07 (v.1)
An updated version...harlan4096 — 07:22

[-]
Birthdays
Today's Birthdays
avatar (37)ixoqe
Upcoming Birthdays
avatar (42)lapedDow
avatar (48)rituabew
avatar (36)omyjul
avatar (40)papedDow
avatar (49)ArnoldFum
avatar (37)yfaza
avatar (48)Kevensi
avatar (38)boineDon
avatar (39)Grompelbawn
avatar (40)vkseogaF
avatar (36)usogy
avatar (39)ywixazok
avatar (35)pa.OpenTran

[-]
Online Staff
dhruv2193's profile dhruv2193

>