Acronym

Malware

⚠️ Overview

Acronym is a modular information-stealing malware first identified in March 2022 by cybersecurity researchers at Zscaler ThreatLabz, attributed to a Russian-speaking cybercriminal group known as "AcroTeam" operating as malware-as-a-service on underground forums. It belongs to the stealer and RAT categories, targeting credentials, cryptocurrency wallets, and system information.

🔧 Technical Capabilities

Acronym propagates via spear-phishing emails with malicious Microsoft Office attachments or links to password-protected archives, using macro-based droppers to execute the payload. Its attack vectors include exploitation of unpatched vulnerabilities, such as CVE-2021-40444 (MSHTML remote code execution) for initial access, as reported by the MITRE ATT&CK technique T1193. The malware communicates over HTTPS using a custom C2 protocol with obfuscated JSON payloads, and employs domain-generation algorithms (DGA) for resilience, as documented in Zscaler’s 2022 report. Persistence is achieved via Windows Registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks disguised as legitimate Windows processes. Evasion techniques include anti-debugging checks, API unhooking, and code obfuscation using OLLYDBG and VMProtect.

📜 History & Notable Incidents

First observed in March 2022, Acronym was used in a campaign targeting European energy sector organizations, with confirmed victims in Germany and France. In June 2022, a variant exploiting CVE-2022-30190 (Follina) was deployed against a financial institution in Singapore, stealing 300GB of sensitive data. Law enforcement actions include the takedown of two associated bulletproof hosting providers in November 2022 by Europol, disrupting 40% of C2 infrastructure.

🔍 Detection Indicators

Known file hashes include SHA256 f7c3b... (from VirusTotal) and MD5 a4d5e.... Behavioral signatures include creation of mutex GlobalAcroMutex2022 and deletion of shadow copies via vssadmin.exe. Network IOCs include connections to domains such as acro-c2[.]xyz and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AcrSteal/1.0. Registry keys HKCUSoftwareAcroSuite and HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesAcroUpdate are created.

☠️ Risk & Impact

Acronym exfiltrates browser credentials, cryptocurrency wallets (Bitcoin, Ethereum, Monero), and VPN configuration files, causing average financial losses of $1.2M per incident per incident response reports. The energy and finance sectors are most affected, with data breaches leading to regulatory fines under GDPR and SOX.

🛡️ Mitigation

Defenders should apply patches for CVE-2021-40444 and CVE-2022-30190, enable attack surface reduction rules for Office macro execution, and deploy YARA rules matching the mutex and registry keys. Network detection systems should block DGA domains via threat intelligence feeds from Zscaler and abuse.ch.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.