ACRStealer is a Windows information-stealing malware family used in financially motivated cybercrime campaigns. It harvests browser passwords, cookies, payment-card information, cryptocurrency wallet data, and credentials from applications including email clients, FTP clients, VPN software, password managers, and terminal tools. Its collection targets also include AI development environments, particularly API keys and configuration data associated with Cline and Continue AI. Stolen information is transmitted to attacker-controlled infrastructure, including through HTTPS POST requests.
ACRStealer uses dead-drop resolvers to obtain command-and-control addresses from encoded content hosted on legitimate services, including Steam Community, Google document services, and Telegram's Telegraph platform. Delivery chains employ malicious DLL side-loading, obfuscated scripts, encrypted payloads, and in-memory execution to hinder detection and analysis. Distribution includes cracked software and key generators promoted through SEO poisoning, trojanized installers, and ClickFix or fake-CAPTCHA lures. Campaigns targeting developers also impersonate software documentation and use paid search advertisements to direct victims to malicious installation commands. Legitimate file-hosting and cloud-storage services are frequently abused to stage payloads. ACRStealer has been deployed alongside SectopRAT in ClearFake campaigns involving compromised websites and blockchain-hosted routing logic.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
ClearFake spreads by compromising legitimate websites and injecting hidden JavaScript code into their pages. Victims do not need to do anything suspicious to get infected. Simply visiting a tampered legitimate site can trigger the malware’s multi-stage delivery chain.
Blackpoint SOC alerted to suspicious cmd.exe usage by a user on a host... The command used cmd.exe to pull a second-stage DLL from an attacker-controlled WebDAV server and launch it via rundll32.
Stage 1 -- ACRStealer Dropper : A PowerShell script hosted at hxxps://casyetnx[.]pw/eq8e1l4b0qjd22w
Distribution exploiting Renpy (a Python-based open-source game development tool) was identified. Inside a ZIP file, setup.Exe and setup.Py were linked to execute malicious scripts sequentially, ultimately launching ACRStealer.
Experts found various delivery techniques, such as rundll32.exe loading infected DLLs, Base64-encoded commands, mshta.exe abuse, JavaScript-based payloads, and GitHub-hosted scripts.
Windows users were instructed to open the Run dialog and paste it, loading a remote DLL into memory with no file ever written to disk.
A ClickFix-style social engineering attack tricked a user into running a command that pulled a malicious DLL loader from an attacker-controlled WebDAV server and launched it using rundll32.
The attacker directly tampered with and injected malicious code into a specific Python script (.py) inside the legitimate Python library folder (Lib). They then packaged this modified script together with a legitimate Python executable into a compressed archive and distributed it.
Experts found various delivery techniques, such as rundll32.exe loading infected DLLs, Base64-encoded commands... After execution, the malware uses a multi-level malicious chain that features encoded C2 communications...
After execution, the malware uses a multi-level malicious chain that features encoded C2 communications, anti-analysis capabilities, fileless execution tactics, and credential theft functions.
The report includes cases involving disguising as cracks and keygens... Statistics on companies disguised by new malware... were extracted based on version and certificate information.
Experts found various delivery techniques, such as rundll32.exe loading infected DLLs, Base64-encoded commands, mshta.exe abuse, JavaScript-based payloads, and GitHub-hosted scripts.
The command used cmd.exe to pull a second-stage DLL from an attacker-controlled WebDAV server and launch it via rundll32.
After execution, the malware uses a multi-level malicious chain that features encoded C2 communications, anti-analysis capabilities...
Victims on Windows and macOS were routed to separate payloads tailored to their operating system, with routing handled by real-time OS detection in the browser.
The attacker directly tampered with and injected malicious code into a specific Python script (.py) inside the legitimate Python library folder (Lib). They then packaged this modified script together with a legitimate Python executable into a compressed archive and distributed it.
Victims saw a convincing fake Google reCAPTCHA overlay complete with an “I’m not a robot” checkbox. Clicking it triggered the ClickFix social engineering panel...
Contrary to infostealers, the campaign pick on AI assets like authentication tokens, API Key, and cloud development credentials from tools such as Continue[.]dev, Cline.
ACRStealer, a C++ infostealer that harvests passwords, credit card numbers, cookies, and cryptocurrency wallet data.
The agents actively searched server-side systems, identified weaknesses, and carried out targeted actions against online infrastructure... [The Recon] dashboard was designed to organize, validate, and manage more than 23,800 stolen secrets in real time, including API keys connected to cloud and AI services.
Victims saw a convincing fake Google reCAPTCHA overlay complete with an “I’m not a robot” checkbox. Clicking it triggered the ClickFix social engineering panel...
Clicking it triggered the ClickFix social engineering panel, which simultaneously injected a malicious command directly into the victim’s clipboard.
What It Steals ACRStealer targets a comprehensive list: Chrome, Firefox, Edge, Opera, Brave, and Vivaldi browser data (logins, cookies, history, autofill, credit cards); crypto wallets ... FTP clients ... email ... VPN configs ... password managers ... and chat apps
Threat actors used a technique called EtherHiding to store payload routing instructions inside blockchain smart contracts, bypassing all URL-based blocking methods entirely.
Dead Drop Resolver: Hiding C2 in Plain Sight ... The attacker creates profiles on Steam Community, Google Docs, Google Slides, or Telegram ... The malware fetches the page ... and decodes the Base64 to obtain the real C2 address
432 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer distributed through cracked-software disguises and through a Renpy-based archive chain in which setup.exe and setup.py execute malicious scripts that launch the stealer.
A credential-stealing malware/tool referenced only through collection rules targeting AI coding-assistant configuration files that may contain secrets.
A credential-stealing malware referenced only through its collection rules targeting AI coding-assistant configuration files, including secrets.json and config.yaml.
Credential stealer identified in the IoC listing as targeting Cline and Continue AI configuration files for plaintext API keys and model-routing endpoints.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.