APT2__2020__The_footprints_of_Raccoon_a_story_about_operators_of_JS-sniffer_FakeSecurity_distributing_Raccoon_stealer.pdf
ID: 04c2ee83-7e9c-44cb-925c-1c4ccb964622
STIX ID: report--04c2ee83-7e9c-44cb-925c-1c4ccb964622
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2020-12-09
Last Modified Date: 2020-12-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** This report describes a multi-wave campaign (Feb–Sep 2020) by FakeSecurity operators who distributed Raccoon stealer (and Vidar) using phishing docs with malicious macros, Mephistophilus phishing kits, modified FakeSecurity JS-sniffer injections on e‑commerce sites, and Telegram-based C2 updates; the report provides timelines, dozens of malicious domains and IPs, sample hashes, and mitigation recommendations.
