ACR Stealer
- First seen
- 2024-03-01 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:33:43
- Profile updated
- 2026-07-07 14:42:27
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
First introduced in March 2024, ACR Stealer is an information stealer sold as a Malware-as-a-Service (MaaS) on Russian-speaking cybercrime forums by a threat actor named "SheldIO". Researchers posit that this malware is an evolved version of the GrMsk Stealer, which likely aligns with the private stealer that SheldIO has been selling since July 2023. The malware, written in C++, is compatible with Windows 7 through 10, and the seller manages all command and control (C2) infrastructure. ACR Stealer can harvest system information, stored credentials, web browser cookies, cryptocurrency wallets, and configuration files for various programs. Additionally, it employs the dead drop resolver (DDR) technique to obfuscate the actual C2 infrastructure.
Detection coverage
- 1 YARA rules
Exploited vulnerabilities
- CVE-2024-21412 (vulnerability)
Detection rules
- SEKOIA_Infostealer_Win_Acrstealer_Str (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Acr Stealer (report)
- fortinet.com — Exploiting Cve 2024 21412 Stealer Campaign Unleashed (report)
- linkedin.com — Teethador Tdr Threat Brief Acreed Activity 7384201370855165952 Vhaw (report)
- blackpointcyber.com — Novel Fake Captcha Chain Delivering Amatera Stealer (report)
- proofpoint.com — Amatera Stealer Rebranded Acr Stealer Improved Evasion Sophistication (report)
- blog.gdatasoftware.com — 38385 Acr Stealer Infrastructure (report)
- twitter.com — 1784943443157930449 (report)
- cyderes.com — Acr Stealer Rides On Upgraded Countloader (report)
- cyble.com — Double Trouble Latrodectus And Acr Stealer Observed Spreading Via Google Authenticator Phishing Site (report)