SheldIO is a Russian-speaking cybercrime actor associated with the marketing and sale of the ACR Stealer malware family, later linked to its rebrand as Amatera Stealer. The actor is known primarily as an operator or seller within the malware-as-a-service ecosystem rather than as a formally tracked intrusion set tied to a government. SheldIO has been observed advertising the stealer on Russian-language underground forums and on Telegram, placing the actor within the broader Russian-speaking financially motivated cybercriminal marketplace. SheldIO is most closely associated with ACR Stealer, also written as AcridRain, an information stealer active since at least 2024 and described by some reporting as having older lineage. The malware has been characterized as part of a lineage involving GrMsk Stealer and later Amatera Stealer. Reporting indicates that sales of ACR Stealer were shut down in July 2024, after which the malware family was significantly updated and reintroduced as Amatera Stealer. Some reporting suggests source-code sale or ownership changes during this transition, so continuity between the original ACR operation and later Amatera activity is not fully certain. The malware sold under SheldIO’s name is designed for credential theft and broad information harvesting. Across observed versions, ACR/Amatera has targeted browser credentials, cookies, authentication tokens, cryptocurrency wallets, messaging application data, password-manager material, and sensitive local documents. Later Amatera variants expanded collection across numerous browsers, browser wallet extensions, desktop wallet applications, Discord and Signal data, and files likely to contain seed phrases, private keys, wallet exports, passwords, and other high-value financial or identity material. Campaigns delivering this malware have relied heavily on social engineering, especially ClickFix-style lures that trick victims into executing commands themselves. Observed delivery chains include fileless and near-fileless execution using mshta, VBScript, PowerShell, reflective loaders, and in-memory payload decryption and decompression. Other chains have used DLL delivery over WebDAV, Python-based loaders, scheduled-task persistence, timestomping, PowerShell history clearing, and techniques intended to evade endpoint defenses. More advanced Amatera samples have incorporated stronger string encryption, direct or indirect syscall-based evasion, anti-debugging, anti-analysis checks, geofencing behavior, and modern encrypted command-and-control session establishment. Victimology appears opportunistic and financially motivated rather than sector-exclusive. Observed lures have impersonated developer tooling and AI-related services, including fake installation pages and malvertising themes, while telemetry has also shown activity affecting enterprise environments, including finance-sector victims. The actor’s tooling and distribution model indicate participation in a broader access, loader, and stealer economy that overlaps with other Russian-speaking criminal services. Known aliases and associated names are limited. SheldIO is the principal name associated with the actor, while the malware families tied to the actor include ACR Stealer, AcridRain, and Amatera Stealer. No high-confidence evidence in the available information supports classifying SheldIO as a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
51 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Actor associated with marketing/selling ACR Stealer on Russian-speaking forums.
Associated with marketing ACR (AcridRain) Stealer as a Malware-as-a-Service offering; the content links SheldIO to the earlier branding of the Amatera Stealer malware family.
Operates and sells the Amatera MaaS infostealer on Telegram. Amatera is positioned as a Lumma successor and is used in the InstallFix malvertising campaign to steal browser credentials, cookies, session tokens, cryptocurrency wallets, messaging sessions, password manager data, FTP/email tokens, and system fingerprinting data.
Malware-as-a-Service seller associated with ACR Stealer on the RAMP forum; referenced as part of the ecosystem supplying payloads to the duboki PPI operation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.