Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

ACR Stealer

9
Global rank
3 infographic chevron month
Month rank
3 infographic chevron week
Week rank

ACR Stealer is a modern information-stealing malware designed to harvest sensitive data from infected devices. Like other infostealers, it targets credentials, financial details, browser data, and files, enabling cybercriminals to monetize stolen information through direct fraud or underground market sales.

Stealer
Type
Unknown
Origin
1 March, 2024
First seen
8 October, 2026
Last seen

How to analyze ACR Stealer with ANY.RUN

Type
Unknown
Origin
1 March, 2024
First seen
8 October, 2026
Last seen

IOCs

IP addresses
23.11.41.157
2.23.246.101
135.233.95.144
184.31.95.119
48.209.138.189
20.42.65.90
131.253.33.203
52.111.243.8
52.110.17.68
150.171.110.152
48.192.1.64
20.190.160.128
52.123.129.14
2.16.204.151
204.79.197.203
172.211.123.249
150.171.109.104
135.232.92.97
48.209.138.168
172.211.123.248
Hashes
73e5a29f48d5ab979eeda062493bc7e679265c1344ef936978b8becec5549497
893bcf21001ed9567945a82e262e42a78c19968b6d6bd018e33db439318bc549
7c1c0df33df49e6bfaac423ee1d265c62366d59279b13656d21ff468d3232265
07b89776f6b6f43f6055599aad63abccbcf7cec48cbf4ef211a4426542a8fb0a
5838575dc944ff9fa697ea33f12416a02bf21dc7a978001fbf3c40467694a74c
44c353773e8dac24997cd8b5c8f80121d4434a94e6b1363070dccbdf5eb10cbc
a6d9897313393701115bbb81efbc4b9955162bee36c76ae01b0278f320fd9fcc
cfe5e390be0f7d9672669e62d06baf6a8479f57c0906791039423ca4119a394c
afdadb97964390e384ecdde4ecae263ac129f61883fbc225ed115f365192c443
40244c88129263b3b3a01ad15da45f940c45f63305cd3a25dee16df2aa1dc110
a48acbe81f33e5918b096a6b89687e505da0e79196f74dc48b6e068708378a3f
a8caa227bb4d3f5f831ba8756cb24a675dc0a97043eeefbdc0fca0b47ff3dd69
7684e0e089e6227f4b05c9382870bb447f94e4f28334cb744bfc155e8e66a7c4
fb600ea9dd2973eab6352b4411043e6262f7919ad3602eb7f81eb24c08d37822
d99aaa09108e56886ab53484575db5b11f400a8a6461d32adf630935ccd4b4d9
e2c2da27bf6e2c2f8d076b9a95419a249754dc51ce6a4940c80b4af6ec9472e1
beb6aa587bef3db138295dd091c5c0c465918b86e6d25d4bd67f229dc61dee35
a01b6c5cfac670336fb9011ffa0270a798f2ae0d718bd5a73fcf1309500f14d1
e07c3e7f2986b4cc15449cfe4bd7a0e0fe8b69a551ed1dbd41930f7652aac2ea
71480fecfaf39e2910e4fd704343fb4b0a65f576f153fb8a480059b53f1babe6
Domains
settings-win.data.microsoft.com
www.bing.com
fe3cr.delivery.mp.microsoft.com
ocsp.digicert.com
activation-v2.sls.microsoft.com
crl.microsoft.com
login.live.com
messaging.lifecycle.office.com
ecs.office.com
client.wns.windows.com
fs.microsoft.com
messaging.engagement.office.com
oneocsp.microsoft.com
slscr.update.microsoft.com
nexusrules.officeapps.live.com
google.com
www.microsoft.com
officeclient.microsoft.com
self.events.data.microsoft.com
roaming.svc.cloud.microsoft
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3
https://ecs.office.com/config/v2/office/excel/16.0.16026.20146/production/cc?&clientid=%7bd61ab268-c26a-439d-bb15-2a0dedfca6a3%7d&application=excel&platform=win32&version=16.0.16026.20146&msoversion=16.0.16026.20002&sdx=fa000000002.2.0.1907.31003&sdx=fa000000005.1.0.1909.30011&sdx=fa000000006.1.0.1909.13002&sdx=fa000000008.1.0.1908.16006&sdx=fa000000009.1.0.1908.6002&sdx=fa000000016.1.0.1810.13001&sdx=fa000000029.1.0.1906.25001&sdx=fa000000033.1.0.1908.24001&sdx=wa104381125.1.0.1810.9001&processname=excel.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2019&licensecategory=6&licensesku=professional2019retail&osversion=10.0&osbuild=19045&channel=cc&installtype=c2r&sessionid=%7bdff2851c-44ee-4bcd-b8ac-800874952cd3%7d&labmachine=false
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://fs.microsoft.com/fs/4.42/flatfontassets.pkg
https://nexusrules.officeapps.live.com/nexus/rules?application=excel.exe&version=16.0.16026.20146&osenvironment=10&msoappid=1&audiencename=production&audiencegroup=production&appversion=16.0.16026.20146&
https://messaging.engagement.office.com/campaignmetadataaggregator?app=1&platform=10&ofc_channel=cc&ofc_audience=production&ofc_flights=ofsh6c2b1tla1a31%3bofcrui4yvdulbf31%3bofhpex3jznepoo31%3bofaa1msspvo2xw31&ver=16.0.16026.20002&hwid=04111-083-043729aed3&osversion=10.0.19045&country=us&locale=en-us&ofc_licensecategory=6&ofc_licensesku=professional2019retail&contenttype=campaigncontent
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://messaging.lifecycle.office.com/getcustommessage16?app=1&ui=en-us&src=bizbar&messagetype=bizbar&hwid=04111-083-043729&ver=16.0.16026&lc=en-us&platform=10%3a0%3a19045%3a2%3a0%3a0%3a256%3a1%3a&productid=%7b1717c1e0-47d3-4899-a6d3-1022db7415e0%7d%3a00411-10830-43729-aa720%3aoffice%2019%2c%20office19professional2019r_retail%20edition&clientsessionid=%7bdff2851c-44ee-4bcd-b8ac-800874952cd3%7d&datapropertybag=%7b%22audience%22%3a%22production%22%2c%22audiencegroup%22%3a%22production%22%2c%22audiencechannel%22%3a%22cc%22%2c%22flight%22%3a%22ofsh6c2b1tla1a31%2cofcrui4yvdulbf31%2cofhpex3jznepoo31%2cofaa1msspvo2xw31%22%7d
https://self.events.data.microsoft.com/onecollector/1.0/
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
Last Seen at
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 230
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 2820
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 4352
comments 0

What is ACR Stealer?

ACR Stealer is a sophisticated information-stealing software sold as a Malware-as-a-Service (MaaS) on underground forums, primarily targeting credentials, browser data, and cryptocurrency wallets to facilitate identity theft and financial fraud.

It is lightweight, fast, and capable of exfiltrating a broad spectrum of data types, including login credentials, cryptocurrency wallet information, and system fingerprints. Its developers continuously update the malware to bypass traditional defenses, making it a persistent threat in the cybercrime ecosystem. According to Stamus Networks, ACR Stealer is an evolved version of GrMsk Stealer, which had been privately sold by the threat actor SheldIO since around July 2023. In 2025, Proofpoint researchers confirmed that ACR Stealer was significantly updated and rebranded as Amatera Stealer. Key enhancements included improved anti-analysis features and a shift away from previously used C2 mechanisms like Steam/Telegram dead drops.

ACR Stealer operates by injecting itself into system processes to avoid detection, then systematically scans the endpoint for valuable data. It uses encryption to obfuscate stolen information before exfiltrating it to C2 servers, sometimes leveraging unconventional platforms like Google Docs for command retrieval. The malware employs dead drop resolvers for dynamic C2 resolution, enhancing its resilience against takedowns. Variants like Amatera introduce advanced string obfuscation and virtual machine checks to evade sandboxes and antivirus software.

ACR Stealer commonly spreads through:

  • Phishing emails with malicious attachments or links.
  • Malvertising that redirects users to fake software downloads.
  • Cracked software and trojanized applications shared on forums or torrents.
  • Drive-by downloads from compromised websites.

While primarily single-device malware, once credentials are stolen, attackers often use them to move laterally within corporate networks.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

ACR Stealer Malware Victimology

ACR Stealer targets a broad spectrum of victims, with no specific industry or demographic limitation. The malware's distribution methods suggest that it primarily affects:

  • Individual users seeking cracked software or illegitimate downloads
  • Organizations whose employees fall victim to social engineering tactics
  • Users of popular platforms like Steam, where the malware leverages community features for C2 communication
  • Cryptocurrency enthusiasts and traders, given its specific focus on wallet theft
  • Users of mainstream web browsers who store sensitive credentials and financial information

The distribution trend of ACR Stealer from June 2024 to February 2025 indicates a dramatic rise in 2025, suggesting an expanding victim base and increased threat actor adoption of this malware family.

ACR Stealer Technical Analysis and Attack Example

Let’s observe an ACR Stealer typical attack chain on a sample analyzed in ANY.RUN’s Interactive Sandbox.

View analysis

ACR Stealer analysis in Interactive Sandbox ACR Stealer sample analysis in the Interactive Sandbox

HTTP Requests and Encryption

An interesting feature of ACR Stealer is that HTTP packet headers may use legitimate domains such as microsoft.com, although the packets are sent to IP addresses not associated with these domains.

ACR HTTP requests seen in Interactive Sandbox ACR HTTP requests seen in Interactive Sandbox

In the first response to an HTTP request, there is a large Base64-encoded string of 32 KB. When attempting to decode it, it turns out to be additionally encrypted using an XOR operation. After decryption, it produces a large configuration file, which is a key component of ACR Stealer’s operation.

Configuration File

The ACR Stealer configuration file is a structured JSON-like object that manages data theft in the Windows environment. It defines the targets and parameters for collecting sensitive information, ensuring flexibility and stealth of the malware.

The stealer targets data from numerous browsers, including Google Chrome, Microsoft Edge, Opera, Firefox, Brave, Vivaldi, and lesser-known ones such as CocCoc, 360Browser, and K-Meleon. It extracts cookies, passwords, browsing history, autofill data, credit card details, and extensions, many of which are cryptocurrency wallets (MetaMask, Coinbase Wallet), password managers, and censorship bypass tools.

Messengers such as Telegram, WhatsApp, Signal, Tox, and Psi+ are targeted for theft of session keys, chats, and contacts via files such as *.sqlite or accounts.xml located in %AppData% directories. Cryptocurrency wallets, including Bitcoin, Electrum, Exodus, Ledger Live, Binance, and others, are subject to theft of wallet.dat, *.json, *.config files containing private keys and seed phrases.

Additionally, the stealer attacks password managers (Bitwarden, NordPass, 1Password), FTP clients (FileZilla, WinSCP), email clients (The Bat!, eM Client, Outlook), VPNs (NordVPN, AzireVPN), and applications such as AnyDesk and Sticky Notes, extracting logins, passwords, and 2FA tokens. Global disk searches target files with keywords like bitcoin, wallet, seed, metamask in the Documents and Recent folders to locate seed phrases and keys.

The configuration supports downloading additional files from external URLs and uses a dictionary of strings for parsing browser data (Login Data, Cookies, key4.db), obfuscation, and adaptation to Windows versions, minimizing detection by antivirus software.

Data Exfiltration

ACR ZIP archive with stolen data in Interactive Sandbox ACR Stealer ZIP archive with stolen data

Data collected by ACR Stealer is sent to the attacker’s server as a ZIP archive. The configuration file usually contains a parameter responsible for downloading an additional executable file from an external resource. However, in the analyzed sample such a download was not performed.

Evolution

It is reported that in new versions of ACR Stealer, the Dead Drop Resolver (DDR) method is used. The malware connects to a legitimate web platform, where a configuration string with the actual C2 server domain is placed on a specific page. The malware retrieves this string, parses it, and obtains the C2 address to proceed with its operations. This approach complicates detection and tracking of the malware.

Previously, ACRStealer used characteristic HTTP request signatures such as:

  • GET domain.com/ujs/uuid
  • POST domain.com/up

However, according to some sources, still newer versions of the malware have abandoned this format, making identification more difficult.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Notable ACR Stealer Attacks

Best known campaigns include a 2025 operation using cracked software to distribute ACR alongside Lumma Stealer, resulting in widespread credential theft since January.

Another involved a fake Google Safety Centre phishing site spreading Latrodectus loader and ACR Stealer, compromising user security globally. In 2024, exploitation of CVE-2024-21412 facilitated delivery of ACR, Lumma, and Meduza stealers, evading Microsoft Defender and affecting numerous endpoints.

Additionally, web inject campaigns via ClearFake deployed Amatera variant, targeting cryptocurrency users with high success in data exfiltration.

Gathering Threat Intelligence on ACR Stealer Malware

Threat intelligence empowers defenders with real-time knowledge of ACR Stealer’s infrastructure, tactics, and IOCs. By enriching alerts with contextual data, security teams can distinguish real threats from noise, respond faster, and block communication with known C2 servers before data exfiltration succeeds.

Start using Threat Intelligence Lookup for free: collect IOCs, browse sandbox detonations.

Start with a malware name search request to ANY.RUN’s Threat Intelligence Lookup and dive deeper into contextual data on ACR Stealer. View public analyses of the malware’s fresh samples, extract the behavioral patterns, gather IOCs from each session.

threatName:"acr" and threatLevel:"malicious"

ACR Stealer samples found via Threat Intelligence Lookup ACR Stealer malware analyses found via Threat Intelligence Lookup

Gather indicators of compromise by clicking the IOCs button in Interactive Sandbox and look them up to find correlating IPs, domains, URLs, and more.

destinationIP:"85.208.139.75"

IP found in ACR Stealer samples delivers more IOCs via Threat Intelligence Lookup Lookup search for an IP found in ACR Stealer samples delivers more IOCs

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

ACR Stealer represents a significant evolution in information-stealing malware, combining sophisticated evasion techniques with comprehensive data harvesting capabilities. Its ability to leverage legitimate platforms for command and control communication, employ advanced anti-analysis techniques, and continuously evolve demonstrates the dynamic nature of modern cyber threats. Organizations must adopt a proactive, multi-layered security approach that combines technical controls, user education, and threat intelligence to effectively defend against ACR Stealer and similar threats.

The rise in ACR Stealer incidents, particularly the dramatic increase observed in 2025, underscores the urgent need for enhanced security awareness and robust defensive measures across all sectors of the digital economy.

Sign up to use ANY.RUN’s TI Lookup for free: gather fresh actionable threat intelligence for quick detection and response.

HAVE A LOOK AT

BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More
Black Basta screenshot
Black Basta
blackbasta
Black Basta is a ransomware-as-a-service operated by Storm-1811. It emerged in 2022 and uses double extortion tactics, encrypting data and stealing it for ransom. The malware often gains access through spear-phishing and uses tools like QakBot and Cobalt Strike. It's known for exploiting system vulnerabilities and using advanced obfuscation techniques.
Read More
Jigsaw screenshot
Jigsaw
jigsaw
The Jigsaw ransomware, initially detected in 2016, encrypts files on compromised systems and requires a ransom payment in Bitcoin. If the ransom is not paid, the malware starts deleting files, increasing the pressure on victims to comply. Its source code is publicly accessible, allowing various threat actors to customize and repurpose the malware for different objectives.
Read More
Lynx screenshot
Lynx
lynx
Lynx is a double extortion ransomware: attackers encrypt important and sensitive data and demand a ransom for decryption simultaneously threatening to publish or sell the data. Active since mid-2024. Among techniques are terminating processes and services, privilege escalation, deleting shadow copies. Distribution by phishing, malvertising, exploiting vulnerabilities.
Read More
Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More
Overlord RAT screenshot
Overlord RAT
overlord
Overlord RAT is a cross-platform remote access framework with Go-based agents and a TypeScript/Node/Bun server. It supports encrypted WebSocket C2, remote control, persistence, and multiple operating systems, including Windows, Linux, and macOS.
Read More