Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

ACR Stealer

11
Global rank
6 infographic chevron month
Month rank
3 infographic chevron week
Week rank

ACR Stealer is a modern information-stealing malware designed to harvest sensitive data from infected devices. Like other infostealers, it targets credentials, financial details, browser data, and files, enabling cybercriminals to monetize stolen information through direct fraud or underground market sales.

Stealer
Type
Unknown
Origin
1 March, 2024
First seen
18 September, 2026
Last seen

How to analyze ACR Stealer with ANY.RUN

Type
Unknown
Origin
1 March, 2024
First seen
18 September, 2026
Last seen

IOCs

IP addresses
104.46.162.231
23.194.190.141
52.110.17.204
88.221.169.205
195.210.46.42
52.110.17.48
2.16.168.46
52.110.17.52
40.79.163.155
40.126.31.128
2.16.204.86
48.209.138.189
199.232.210.172
48.209.138.168
165.154.1.133
208.91.197.27
34.54.185.247
184.31.95.119
52.123.129.14
52.110.17.19
Hashes
93fa329ba9ef75af1d19df29a2b933bc1eb83336703bbdd3cbc60946a9f668b9
044aa7e93ec81b297b53aaebad9bbac1a9d754219b001aaf5d4261665af30bc7
057e3d39cd6e6b882c9cebfb56920db712f49cd628b35bf58e1fd544c0bea20b
0dfa017a86a8dd9c7b2f8a07af89f6e5a2dbacea8e0d2699b6176e055a8a1a15
438a487d96c184aafaf90bf796dfb7b551fbaec22e8b9ef432eb3675b8c814cf
b452ba00f4971736a7eadcf2187b7c008a145e84fb43b046594807625c065640
8a2cedeec7ca8ac2691f024af0f453170e8b6647a9de382a9a82c9ac8ef73025
66f47b2ef0d2b4c0fefecb0374412d59142cdc44d50c35b85bbb90b470b40fa6
ba19e9a6a3cc91582dc1005ce0239620208e2e8795086eef9ec94b9c75fe4ccc
c0b296e47062d9088be55e80bf9d99de03e3154daeea19e9c236f2d4d1c8faea
ff03f069281de852c003cf93e40247a03e3402c734ee2c6c9961e3f55965817f
b19162cec9afcb0ff202ccc366d23fd745aebf4e5dd9f23bfaaabc7ac4b2f240
198a134cff22c87dd3164ae1e82ada5ae6c5e49caefe2819bb8a607adf2ac2e0
14a73223fc963ee73477f64edb92dc03e9ef5c0044c56d9aa22a6dcb29c5bde2
ee66db98d5158e7e3107700632403cbeb7290b5c6fd5384f41d98f5585182ef6
c8c96c37ff8427467fc0b2c685ae6f231dfe841332f0783c785729c4451f976c
481e0734223e3bd2bc152e3e61b06e0462b193883e46004025bc7b0aba09c39c
32796f324e8a232310b9a81ddd576db25af78216117ba8d69cf3ad4d2f0c51d2
82f6db23e32b0b8ccec1c83ac426628fc38bc8c5884fbab0f20df068eee9f587
bada2719f2e86a81f7d330eaa38168b9418e35f09b4e971af421012d9be20659
Domains
binaries.templates.cdn.office.net
ecs.office.com
oubaina.com
google.com
officeclient.microsoft.com
licensing.m365.svc.cloud.microsoft
prod.ingestion-edge.prod.dataservices.mozgcp.net
self.events.data.microsoft.com
mrodevicemgr.officeapps.live.com
ctldl.windowsupdate.com
fs.microsoft.com
bike-nomad.com
metadata.templates.cdn.office.net
settings-win.data.microsoft.com
login.live.com
dns.msftncsi.com
v10.events.data.microsoft.com
incoming.telemetry.mozilla.org
www.msbc.kz
omex.cdn.office.net
URLs
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16626&crev=3
https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
https://ecs.office.com/config/v2/office/word/16.0.16626.20134/production/cc?&clientid=%7b72fa513c-1434-461c-bfdf-dcc1864a73f3%7d&application=word&platform=win32&version=16.0.16626.20134&msoversion=16.0.16626.20086&sdx=fa000000069.1.0.2211.2001&sdx=fa000000070.1.0.2211.4002&officefirstrunsdxversion=1.0.2211.2001&processname=winword.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2021&licensecategory=13&licensesku=homebusiness2021retail&osversion=10.0&osbuild=22000&channel=cc&installtype=c2r&providerid=9fcc1350af7dd254&sessionid=%7b63433ada-252e-4f79-a7be-e1a2a1814f7c%7d&labmachine=false
https://licensing.m365.svc.cloud.microsoft/licensing/user/renewperpetuallicense?api-version=5
https://fs.microsoft.com/fs/windows/config.json
https://www.msbc.kz/data/k527_5_cbdvv5bi19/
http://oubaina.com/wp-includes/lqkz_nvr_1avf4/
http://bike-nomad.com/cgi-bin/7n_0x0_62mnzyh9q/
https://metadata.templates.cdn.office.net/client/templates/gallery?lcid=1033&syslcid=1033&uilcid=1033&app=0&ver=16&tl=2&build=16.0.16626&gtype=0%2c1%2c2%2c5%2c
https://self.events.data.microsoft.com/onecollector/1.0/
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02835233.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851221.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851218.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851216.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851222.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851224.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851220.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851223.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851226.cab
https://binaries.templates.cdn.office.net/support/templates/en-us/tp02851217.cab
Last Seen at
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1351
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1647
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3241
comments 0

What is ACR Stealer?

ACR Stealer is a sophisticated information-stealing software sold as a Malware-as-a-Service (MaaS) on underground forums, primarily targeting credentials, browser data, and cryptocurrency wallets to facilitate identity theft and financial fraud.

It is lightweight, fast, and capable of exfiltrating a broad spectrum of data types, including login credentials, cryptocurrency wallet information, and system fingerprints. Its developers continuously update the malware to bypass traditional defenses, making it a persistent threat in the cybercrime ecosystem. According to Stamus Networks, ACR Stealer is an evolved version of GrMsk Stealer, which had been privately sold by the threat actor SheldIO since around July 2023. In 2025, Proofpoint researchers confirmed that ACR Stealer was significantly updated and rebranded as Amatera Stealer. Key enhancements included improved anti-analysis features and a shift away from previously used C2 mechanisms like Steam/Telegram dead drops.

ACR Stealer operates by injecting itself into system processes to avoid detection, then systematically scans the endpoint for valuable data. It uses encryption to obfuscate stolen information before exfiltrating it to C2 servers, sometimes leveraging unconventional platforms like Google Docs for command retrieval. The malware employs dead drop resolvers for dynamic C2 resolution, enhancing its resilience against takedowns. Variants like Amatera introduce advanced string obfuscation and virtual machine checks to evade sandboxes and antivirus software.

ACR Stealer commonly spreads through:

  • Phishing emails with malicious attachments or links.
  • Malvertising that redirects users to fake software downloads.
  • Cracked software and trojanized applications shared on forums or torrents.
  • Drive-by downloads from compromised websites.

While primarily single-device malware, once credentials are stolen, attackers often use them to move laterally within corporate networks.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

ACR Stealer Malware Victimology

ACR Stealer targets a broad spectrum of victims, with no specific industry or demographic limitation. The malware's distribution methods suggest that it primarily affects:

  • Individual users seeking cracked software or illegitimate downloads
  • Organizations whose employees fall victim to social engineering tactics
  • Users of popular platforms like Steam, where the malware leverages community features for C2 communication
  • Cryptocurrency enthusiasts and traders, given its specific focus on wallet theft
  • Users of mainstream web browsers who store sensitive credentials and financial information

The distribution trend of ACR Stealer from June 2024 to February 2025 indicates a dramatic rise in 2025, suggesting an expanding victim base and increased threat actor adoption of this malware family.

ACR Stealer Technical Analysis and Attack Example

Let’s observe an ACR Stealer typical attack chain on a sample analyzed in ANY.RUN’s Interactive Sandbox.

View analysis

ACR Stealer analysis in Interactive Sandbox ACR Stealer sample analysis in the Interactive Sandbox

HTTP Requests and Encryption

An interesting feature of ACR Stealer is that HTTP packet headers may use legitimate domains such as microsoft.com, although the packets are sent to IP addresses not associated with these domains.

ACR HTTP requests seen in Interactive Sandbox ACR HTTP requests seen in Interactive Sandbox

In the first response to an HTTP request, there is a large Base64-encoded string of 32 KB. When attempting to decode it, it turns out to be additionally encrypted using an XOR operation. After decryption, it produces a large configuration file, which is a key component of ACR Stealer’s operation.

Configuration File

The ACR Stealer configuration file is a structured JSON-like object that manages data theft in the Windows environment. It defines the targets and parameters for collecting sensitive information, ensuring flexibility and stealth of the malware.

The stealer targets data from numerous browsers, including Google Chrome, Microsoft Edge, Opera, Firefox, Brave, Vivaldi, and lesser-known ones such as CocCoc, 360Browser, and K-Meleon. It extracts cookies, passwords, browsing history, autofill data, credit card details, and extensions, many of which are cryptocurrency wallets (MetaMask, Coinbase Wallet), password managers, and censorship bypass tools.

Messengers such as Telegram, WhatsApp, Signal, Tox, and Psi+ are targeted for theft of session keys, chats, and contacts via files such as *.sqlite or accounts.xml located in %AppData% directories. Cryptocurrency wallets, including Bitcoin, Electrum, Exodus, Ledger Live, Binance, and others, are subject to theft of wallet.dat, *.json, *.config files containing private keys and seed phrases.

Additionally, the stealer attacks password managers (Bitwarden, NordPass, 1Password), FTP clients (FileZilla, WinSCP), email clients (The Bat!, eM Client, Outlook), VPNs (NordVPN, AzireVPN), and applications such as AnyDesk and Sticky Notes, extracting logins, passwords, and 2FA tokens. Global disk searches target files with keywords like bitcoin, wallet, seed, metamask in the Documents and Recent folders to locate seed phrases and keys.

The configuration supports downloading additional files from external URLs and uses a dictionary of strings for parsing browser data (Login Data, Cookies, key4.db), obfuscation, and adaptation to Windows versions, minimizing detection by antivirus software.

Data Exfiltration

ACR ZIP archive with stolen data in Interactive Sandbox ACR Stealer ZIP archive with stolen data

Data collected by ACR Stealer is sent to the attacker’s server as a ZIP archive. The configuration file usually contains a parameter responsible for downloading an additional executable file from an external resource. However, in the analyzed sample such a download was not performed.

Evolution

It is reported that in new versions of ACR Stealer, the Dead Drop Resolver (DDR) method is used. The malware connects to a legitimate web platform, where a configuration string with the actual C2 server domain is placed on a specific page. The malware retrieves this string, parses it, and obtains the C2 address to proceed with its operations. This approach complicates detection and tracking of the malware.

Previously, ACRStealer used characteristic HTTP request signatures such as:

  • GET domain.com/ujs/uuid
  • POST domain.com/up

However, according to some sources, still newer versions of the malware have abandoned this format, making identification more difficult.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Notable ACR Stealer Attacks

Best known campaigns include a 2025 operation using cracked software to distribute ACR alongside Lumma Stealer, resulting in widespread credential theft since January.

Another involved a fake Google Safety Centre phishing site spreading Latrodectus loader and ACR Stealer, compromising user security globally. In 2024, exploitation of CVE-2024-21412 facilitated delivery of ACR, Lumma, and Meduza stealers, evading Microsoft Defender and affecting numerous endpoints.

Additionally, web inject campaigns via ClearFake deployed Amatera variant, targeting cryptocurrency users with high success in data exfiltration.

Gathering Threat Intelligence on ACR Stealer Malware

Threat intelligence empowers defenders with real-time knowledge of ACR Stealer’s infrastructure, tactics, and IOCs. By enriching alerts with contextual data, security teams can distinguish real threats from noise, respond faster, and block communication with known C2 servers before data exfiltration succeeds.

Start using Threat Intelligence Lookup for free: collect IOCs, browse sandbox detonations.

Start with a malware name search request to ANY.RUN’s Threat Intelligence Lookup and dive deeper into contextual data on ACR Stealer. View public analyses of the malware’s fresh samples, extract the behavioral patterns, gather IOCs from each session.

threatName:"acr" and threatLevel:"malicious"

ACR Stealer samples found via Threat Intelligence Lookup ACR Stealer malware analyses found via Threat Intelligence Lookup

Gather indicators of compromise by clicking the IOCs button in Interactive Sandbox and look them up to find correlating IPs, domains, URLs, and more.

destinationIP:"85.208.139.75"

IP found in ACR Stealer samples delivers more IOCs via Threat Intelligence Lookup Lookup search for an IP found in ACR Stealer samples delivers more IOCs

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

ACR Stealer represents a significant evolution in information-stealing malware, combining sophisticated evasion techniques with comprehensive data harvesting capabilities. Its ability to leverage legitimate platforms for command and control communication, employ advanced anti-analysis techniques, and continuously evolve demonstrates the dynamic nature of modern cyber threats. Organizations must adopt a proactive, multi-layered security approach that combines technical controls, user education, and threat intelligence to effectively defend against ACR Stealer and similar threats.

The rise in ACR Stealer incidents, particularly the dramatic increase observed in 2025, underscores the urgent need for enhanced security awareness and robust defensive measures across all sectors of the digital economy.

Sign up to use ANY.RUN’s TI Lookup for free: gather fresh actionable threat intelligence for quick detection and response.

HAVE A LOOK AT

Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More
EvilProxy screenshot
EvilProxy
evilproxy
EvilProxy is a phishing-as-a-service (PhaaS) platform that enables cybercriminals to bypass multi-factor authentication (MFA) and hijack user sessions. It leverages reverse proxy techniques to harvest credentials and session cookies, posing a serious threat to both individuals and enterprises.
Read More
Sality screenshot
Sality
sality
Sality is a highly sophisticated malware known for infecting executable files and rapidly spreading across networks. It primarily creates a peer-to-peer botnet that is used for malicious activities such as spamming, data theft, and downloading additional malware. Sality has strong persistence mechanisms, including disabling security software, making it difficult to remove. Its ability to spread quickly and silently, along with its polymorphic nature, allows it to evade detection by traditional antivirus solutions.
Read More
Stealc screenshot
Stealc
stealc
Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.
Read More
Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More
XRed screenshot
XRed
xred
XRed operates as a stealthy backdoor, enabling cybercriminals to gain unauthorized remote access to infected systems. XRed has gained particular notoriety for its distribution through trojanized legitimate software and hardware drivers, making it exceptionally dangerous due to its ability to masquerade as trusted applications.
Read More