ACR Stealer is a Windows information-stealing malware family active since 2024 and commonly described as a malware-as-a-service offering. It is widely assessed to be associated with, or a rebranding of, Amatera Stealer. The malware has been observed in enterprise-focused campaigns that prioritize theft of browser-stored credentials, cookies, authentication tokens, and business documents, including PDFs, Microsoft 365 files, and content synchronized through OneDrive and SharePoint.
ACR Stealer primarily relies on social engineering rather than software exploitation. A prominent delivery pattern uses ClickFix lures that trick users into pasting and executing attacker-supplied commands. Observed intrusion chains include a WebDAV-based path in which a remotely hosted DLL is executed through rundll32 and followed by obfuscated PowerShell and a bundled Python loader, as well as a largely fileless chain using MSHTA, HTA or VBScript stages, PowerShell, and steganographically concealed payloads extracted from image files and executed in memory. It has also been delivered by other malware loaders, including CountLoader, and in campaigns using fake software installers and phishing pages impersonating trusted brands or services.
On infected systems, ACR Stealer targets Chromium-family browser data, including saved passwords, cookies, and session material, and uses Windows DPAPI to decrypt protected browser secrets. Reported targeting also includes email clients, FTP clients, messengers, VPN clients, password managers, cryptocurrency wallets, and other desktop applications. In enterprise intrusions, the malware has been observed searching local and synchronized folders for sensitive documents and staging collected data for exfiltration.
ACR Stealer campaigns have used multiple defense-evasion and post-compromise techniques. Observed tradecraft includes in-memory execution, process injection, heavily obfuscated scripting, timestomping, clearing PowerShell history and other forensic traces, and persistence via scheduled tasks disguised as legitimate updates. Some variants or associated loaders have used dead-drop resolver techniques, including EtherHiding through public blockchain infrastructure, to retrieve command-and-control information or follow-on payload locations. The malware has been linked to broad criminal distribution activity rather than a single consistently identified threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.
ACR Stealer, a malware-as-a-service (MaaS) information stealer written in C++ that has been active since 2024, makes its debut in a tie for 6th thanks to its use as a payload in recent ClearFake campaigns.
ACR Stealer is a credential and data theft infostealer written in C++ and used by the SideCopy threat group.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
It downloaded the malware payload as a Python loader, installed scheduled tasks to maintain persistence
The script extracts, decrypts, and runs that payload in memory.
After establishing a connection to the command-and-control (C2) server, the attackers delivered an obfuscated PowerShell script that initiated the malware installation process.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
Defense Evasion(TA0005) Obfuscated Files or Information: Software Packing (T1027.002) Payload is encrypted inside the Resource section
The downloader then retrieved an encrypted payload from a public steganographic JPEG image and executed it in memory.
It hides a Python loader inside a folder that mimics real software. Then it sets a scheduled task disguised as an update for persistence.
The malware also used process injection to execute itself in memory, evading detection by security software.
The routine installs a bundled Python loader, creates a scheduled task masked as a software update, manipulates timestamps, clears PowerShell history, and injects the final payload into a system process for in-memory execution.
and attempted to clear the event logs, PowerShell history, and other tracking mechanisms.
It even copies file timestamps from a trusted Windows binary and wipes PowerShell history to blur the trail.
It even copies file timestamps from a trusted Windows binary and wipes PowerShell history to blur the trail.
If the suspicious installer ran, assume browser-saved passwords, cookies, authentication tokens, Discord or gaming sessions, and wallet data may have been exposed.
If the suspicious installer ran, assume browser-saved passwords, cookies, authentication tokens, Discord or gaming sessions, and wallet data may have been exposed.
Credential Access (TA0006) Credentials from Password Stores: Credentials from Web Browsers (T1555.003) Tries to collect credentials from browsers
Command and Control (TA0011) Application Layer Protocol: Web Protocols (T1071.001) Communicates to C&C over HTTP
Some ACR Stealer variants used blockchain-based dead-drop resolvers to receive updates or C2 addresses.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential and token stealing malware referenced as a possible later payload or related response case.
Mentioned only in related-articles text, not part of the primary event.
Information-stealing malware offered as a malware-as-a-service that likely repackages Amatera Stealer. It steals browser data, credentials, authentication tokens, cookies, passwords, and sensitive business files; uses ClickFix lures, WebDAV, MSHTA, obfuscated PowerShell, Python loaders, scheduled tasks, process injection, DPAPI abuse, and steganographic payload retrieval to evade detection and maintain persistence.
An infostealer sold via MaaS that is linked to a rebrand of Amatera Stealer. It is delivered through ClickFix lures via malvertising and poisoned search results, uses either a WebDAV/Python/PowerShell chain or a largely fileless MSHTA/VBScript/PowerShell chain, steals browser credentials, cookies, session tokens, and documents, and can use EtherHiding to retrieve C2 infrastructure from a public blockchain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.