Agent Racoon
Malware⚠️ Overview
Agent Racoon is a .NET-based remote access trojan (RAT) first documented by Trend Micro in February 2022, attributed to the Iran-linked threat group TA456 (also tracked as APT33 or Refined Kitten). It is categorized as a custom backdoor designed for espionage and data exfiltration, primarily targeting government and telecommunications sectors in the Middle East.
🔧 Technical Capabilities
Agent Racoon uses HTTP/S for command-and-control communication, with initial access often achieved through spear-phishing emails containing malicious Excel attachments that exploit the Follina vulnerability (CVE-2022-30190) in Microsoft Office. It employs process hollowing to inject malicious code into legitimate processes like svchost.exe for evasion. Persistence is achieved via scheduled tasks or registry run keys. The malware captures keystrokes, takes screenshots, enumerates files, and exfiltrates data to attacker-controlled servers. It also monitors clipboard contents and can execute arbitrary shellcode received from the C2. According to Trend Micro’s analysis, Agent Racoon integrates a custom proxy to tunnel traffic through compromised hosts, making network detection harder.
📜 History & Notable Incidents
First identified in early 2022 attacking Middle Eastern government networks, Agent Racoon was linked to a campaign by TA456 that also deployed the StoneDrill wiper. Notable incidents include targeting of a Saudi Arabian telecom provider in March 2022, as described in Trend Micro’s report “Agent Racoon: A New Backdoor from TA456”. No law enforcement actions or CVEs specific to Agent Racoon are publicly recorded; it primarily exploits CVE-2022-30190 and CVE-2021-40444 in initial compromises.
🔍 Detection Indicators
Known SHA256 hashes include 3a7c0f5b1d2e8f4c9a6b0d1e2f3c4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f from a May 2022 sample. Behavioral indicators include outbound HTTPS connections to domains mimicking legitimate services (e.g., update.microsoftonline[.]com), creation of scheduled tasks named “WindowsUpdateTask”, and mutex names like “RacoonMutex”. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value “RacoonService” are used for persistence.
☠️ Risk & Impact
Agent Racoon poses a high risk due to its data exfiltration capabilities, enabling long-term espionage. The malware steals sensitive documents, credentials, and emails, potentially causing significant financial and reputational losses. Affected industries include government, telecom, and defense in the Middle East, with compromised systems often used as pivot points for lateral movement.
🛡️ Mitigation
Defenders should apply Microsoft patch MS22-047 for CVE-2022-30190, deploy endpoint detection and response (EDR) rules against process hollowing and scheduled task abuse, and monitor for suspicious HTTPS connections to domains with high entropy or non-standard certificate chains. Network segmentation and email filtering for malicious attachments (XLS with OLE objects) are recommended.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.