Bitcoin Forum

Other => Beginners & Help => Topic started by: btc_angela on June 30, 2022, 09:43:32 AM



Title: [Read]: Raccoon is back with V2 that targets cryptocurrency wallets
Post by: btc_angela on June 30, 2022, 09:43:32 AM
Raccoon Stealer 2.0 is back. It was reported that the threat actors operation suddenly stop around March 2022 as it was reported that one of it's developer was killed in the Ukraine-Russia war.

However, SEKOIA.IO, a threat research team, recently discovered that version 2.0 was already released in the wild. What makes this malware very dangerous is that it targets most if not all desktop crypto wallets including,

Quote
(MetaMask, TronLink, BinanceChain, Ronin, Exodus, Atomic, JaxxLiberty, Binance, Coinomi, Electrum, Electrum-LTC, ElectronCash, etc.);

https://i.imgur.com/sK0eThX.png

Mode of Infection is downloading fake installers and crack softwares like:

  • F‑Secure FREEDOME VPN installer (F-Secure Freedome VPN 2.50.23.0.licensesrv.exe_KaHCr.exe)
  • R-Studio Network installer (R-Studio.v9.0.190312.licencekey.exe_v3G9m.exe)
  • Proton VPN installer (ProtonVPN.exe)

It's very dangerous to us since majority of could have been using VPN (including myself).

For a detailed technical explanation you can read it here: https://blog.sekoia.io/raccoon-stealer-v2-part-1-the-return-of-the-dead/