ACR Stealer is an information-stealing malware first documented in mid-2022 by the Cyble Research and Intelligence Labs (CRIL). It is a stealer-type malware, written primarily in .NET (C#), designed to harvest credentials, browser data, cryptocurrency wallets, and system information from infected Windows hosts. The malware is offered for sale on underground forums and marketed as a commodity stealer with a low price point, targeting individuals and small organizations.
ACR Stealer propagates primarily through phishing emails containing malicious attachments (e.g., .RAR archives with .LNK files) and via drive-by downloads. Once executed, it collects data from over 30 browser-related applications, including Chrome, Firefox, Edge, and Opera, targeting saved passwords, cookies, autofill data, and credit card information. It also extracts data from cryptocurrency wallets such as Exodus, Electrum, and MetaMask browser extensions. The malware uses HTTP POST requests to exfiltrate stolen data to a command-and-control (C2) server, with the C2 address hardcoded or fetched from a Pastebin-like service. Persistence is achieved by adding a registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include anti-debugging checks, process hollowing detection, and the use of obfuscated strings via base64 encoding and XOR encryption.
ACR Stealer was first observed in the wild in June 2022, with Cyble reporting a campaign targeting users in the United States, India, and Brazil. No high-profile nation-state victims or CVEs have been directly linked to ACR Stealer; it remains a low-tier commodity stealer. Law enforcement actions have not been publicly documented. The malware has been updated occasionally, with version 2.0 released in late 2022 adding file upload capabilities and improved anti-analysis features.
Known file hashes for ACR Stealer samples are available on VirusTotal (e.g., SHA256: a1b2c3d4e5f6...) — specific hashes vary by campaign. Behavioral signatures include unauthorized access to browser local storage directories (%AppData%Roaming...Login Data) and Windows Credential Manager. Network indicators include HTTP POST requests to a C2 endpoint often hosted on low-reputation VPS services (e.g., hxxp://[IP]:8080/grab/gate.php). Registry persistence is created under HKCU...Run with a value name derived from the malware's mutex string (ACR_Stealer_Mutex). User-Agent strings mimic Chrome on Windows (e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ...).
ACR Stealer poses moderate risk due to its ability to exfiltrate sensitive credentials, browser-autofill data, and cryptocurrency keys, leading to account takeovers and financial theft. Affected sectors include individual users and small-to-medium businesses in technology, finance, and e-commerce. No major data breaches or multi-million-dollar losses have been publicly attributed solely to ACR Stealer, but it is frequently part of broader phishing and credential-stuffing campaigns.
Defenses include enabling multi-factor authentication (MFA) on accounts, using endpoint detection and response (EDR) tools with signatures for ACR Stealer (e.g., SentinelOne, CrowdStrike), and blocking known C2 domains and IPs via firewalls or threat intelligence feeds. Phishing awareness training and regular patch management for browsers and Windows reduce initial infection vectors. Cyble provides detection rules (YARA, Sigma) in their public reports.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.