SheldIO is a Russian-speaking cybercrime actor associated with the marketing and sale of the ACR Stealer malware family, later rebranded as Amatera Stealer, through underground forums and Telegram as a malware-as-a-service offering. The actor is linked to the commercialization of an infostealer lineage that has also been described in relation to AcridRain and GrMsk Stealer. The malware sold under SheldIO’s name is designed for credential and data theft at scale. Observed capabilities include theft of browser credentials, cookies, authentication tokens, cryptocurrency wallet data, messaging application data, password manager material, and sensitive local documents. Campaigns using this malware have relied heavily on social-engineering-driven initial access, especially ClickFix-style lures that trick victims into executing commands themselves. Delivery chains have included fileless and disk-based execution using native Windows utilities and scripting components, reflective in-memory loading, persistence via scheduled tasks or autorun mechanisms, timestomping, PowerShell history clearing, anti-debugging, anti-analysis checks, geofencing behavior, and syscall-based userland hook evasion. Amatera/ACR operations associated with this ecosystem have targeted both Windows and macOS users and have been distributed through fake software and developer-tool installation pages, malvertising, and other deceptive web lures. The malware has been observed harvesting data from browsers, synced cloud-storage folders, desktop cryptocurrency wallets, browser wallet extensions, and communication platforms such as Discord and Signal. Later variants incorporated stronger string encryption, improved command-and-control cryptography, and broader theft coverage. SheldIO is notable as the seller and promoter of the malware rather than as a clearly attributed intrusion set conducting all downstream operations directly. Reporting indicates that sales of ACR Stealer were shut down in July 2024, after which the malware family was reported to have been significantly updated and rebranded as Amatera Stealer; some reporting also indicates the source code was sold. This suggests either an ownership transition or continued evolution within the same Russian-speaking malware-as-a-service ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
51 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Actor associated with marketing/selling ACR Stealer on Russian-speaking forums.
Associated with marketing ACR (AcridRain) Stealer as a Malware-as-a-Service offering; the content links SheldIO to the earlier branding of the Amatera Stealer malware family.
Operates and sells the Amatera MaaS infostealer on Telegram. Amatera is positioned as a Lumma successor and is used in the InstallFix malvertising campaign to steal browser credentials, cookies, session tokens, cryptocurrency wallets, messaging sessions, password manager data, FTP/email tokens, and system fingerprinting data.
Malware-as-a-Service seller associated with ACR Stealer on the RAMP forum; referenced as part of the ecosystem supplying payloads to the duboki PPI operation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.