ACR Stealer is a C++ information-stealing malware family targeting Windows systems, active since 2024 and offered through a malware-as-a-service model. It is deployed by multiple criminal operators rather than attributed to a single named threat group. Its targets include individual users and enterprise environments, where it collects authentication material, cryptocurrency wallet data, and sensitive business documents.
ACR Stealer harvests saved browser passwords, cookies, session tokens, autofill information, clipboard contents, and system details. Targeted applications include web browsers, email and FTP clients, cryptocurrency wallets, messengers, VPN clients, and password managers. Observed variants use Windows Data Protection API functionality to recover stored browser secrets, including data from Google Chrome and Microsoft Edge. Enterprise campaigns also collect PDFs and Microsoft 365 documents, including files associated with OneDrive and SharePoint, and package stolen information for exfiltration.
Distribution mechanisms include ClickFix social engineering, phishing pages offering counterfeit software installers, and cracked software or game packages. ClickFix campaigns have attracted victims through malicious advertising and poisoned search results. Delivery chains abuse legitimate Windows utilities, WebDAV shares, PowerShell, and embedded Python runtimes. ACR Stealer has also been delivered through RenEngine Loader and HijackLoader, through CountLoader, and alongside Latrodectus in a counterfeit Google Authenticator installer campaign.
Observed deployments maintain persistence through scheduled tasks and use process injection and in-memory execution to reduce detection. Some campaigns clear event logs and PowerShell history. ACR Stealer uses dead-drop resolvers to conceal command-and-control configuration, including information hosted on Steam Community. Some variants employ EtherHiding, retrieving command-and-control addresses or configuration through public blockchain smart contracts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.
ACR Stealer, a malware-as-a-service (MaaS) information stealer written in C++ that has been active since 2024, makes its debut in a tie for 6th thanks to its use as a payload in recent ClearFake campaigns.
ACR Stealer is a credential and data theft infostealer written in C++ and used by the SideCopy threat group.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
run.pyw establishes persistence with a scheduled task, schtasks /Create /F /TN IntelSoftwareUpdater /XML %TEMP%\t.xml, whose action is pythonw.exe run.pyw.
The initial command uses iex(irm ...), while a later PowerShell process runs with "-NoProfile -NonInteractive -NoLogo -Command -" and receives its script via STDIN.
Execution (TA0002) Native API (T1106) The NtCreateUserProcess() API is used to create a child process
The campaign relies on ClearFake, a long-running operation that compromises legitimate websites and places fake CAPTCHA checks over real pages. Visitors are told to complete a verification step, but the prompt actually guides them into running a malicious command through the Windows Run dialog.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
run.pyw establishes persistence with a scheduled task, schtasks /Create /F /TN IntelSoftwareUpdater /XML %TEMP%\t.xml, whose action is pythonw.exe run.pyw.
The malware also used process injection to execute itself in memory, evading detection by security software.
It assembles the cmdlet name at runtime as 'Invoke-We' + 'bRequest'... The interpreter name pythonw.exe is built up a character at a time.
Defense Evasion(TA0005) Obfuscated Files or Information: Software Packing (T1027.002) Payload is encrypted inside the Resource section
The downloader then retrieved an encrypted payload from a public steganographic JPEG image and executed it in memory.
The hidden pythonw.exe RC4-decrypts an encrypted stage, j7gTcSQdBc15W11UfhQkrIw3WG.jsxi, with a hardcoded key and runs it entirely in memory through exec().
It creates %LOCALAPPDATA%\EdgeUpdate... The Inno Setup payload is named "Intel Software Updater"... a full sideloaded interpreter sits in %LOCALAPPDATA%\Microsoft\WindowsApps\Microsoft.PythonApp_mbs0geli24m2t\.
The malware also used process injection to execute itself in memory, evading detection by security software.
The decrypted stage... injects into a freshly spawned winver.exe... the winver.exe injection is the same move to hollow a small signed binary.
The loader then implements process doppelgänging, writing the shellcode extracted from the .tmp files into both ZoneInd.exe and chime.exe.
The second attack chain also began with a ClickFix lure but used MSHTA to execute the payload.
Specifically, the malicious command used rundll32.exe, a legitimate Windows process, to execute a DLL file located on the remote server.
ACR stealer... harvest[s]... cookies... This capability enables account takeover [and] session hijacking.
The stealer can target browser-held information, including credentials and data that may be valuable for account takeover or further fraud.
ACR stealer... is designed to harvest sensitive user data such as saved browser passwords, cookies... and autofill information.
run.pyw then runs host recon: cmd /c ver and (Get-CimInstance Win32_OperatingSystem).Caption.
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Delivered through a ClickFix infection chain that used blockchain contracts to supply a subsequent payload or command-and-control address.
A named stealer associated with malware domains concentrated in .cfd and .cc. The article does not describe its collection capabilities or execution methods.
A privately operated information stealer mentioned only for comparison with Remus.
Mentioned only as an example of a privately available infostealer, contrasting with Remus's commercial Malware-as-a-Service model. No technical capabilities or operational associations are provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.