Amatera Stealer, also known as ACR Stealer and AcridRain Stealer, is a Windows information stealer and a rebrand of ACR Stealer. It is actively developed and has been used by multiple cybercrime operators, including in ClearFake-associated campaigns. Amatera targets browser credentials, session data, cryptocurrency-wallet information, browser extensions, messaging-application data, and local files. Recent variants include routines intended to recover Chromium encryption keys, including keys protected by Chromium Application-Bound Encryption, enabling theft of protected browser data.
Amatera is commonly delivered through multi-stage loader chains, including WordlistLoader, PavinLoader, and RenPy Loader. Observed distribution methods include ClickFix fake-CAPTCHA lures on compromised websites, malicious game, mod, crack, and software downloads, fake software-installation pages, and trojanized installers. Delivery chains frequently use in-memory loading, reflective loading, blockchain-based EtherHiding infrastructure resolution, DNS-over-HTTPS, code obfuscation, API hashing, anti-debugging, and anti-analysis techniques to limit detection and forensic visibility. Some campaigns have used Amatera alongside other payload families, indicating that its delivery infrastructure can support flexible criminal operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In late April 2026, eSentire's Threat Response Unit (TRU) intercepted an attempted delivery of Amatera Stealer within a customer environment in the Finance industry. Amatera Stealer is a rebranded version of ACR (AcridRain) Stealer, a C++ based information stealer previously marketed as Malware-as-a-Service (MaaS) on underground forums by the threat actor SheldIO.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actors are actually using it to host their malicious PowerShell script
The ClickFix command uses "conhost" to launch a hidden "cmd.exe" process, then map a remote WebDAV share using pushd, and finally launch the loader via "rundll32.exe."
This leads to the execution of a VBScript loader that decodes and runs PowerShell
Amatera skips the 32-bit ntdll part of that chain altogether, resolving the syscall numbers on its own and entering the WoW64 layer directly through wow64cpu!KiFastSystemCall. | a fixed set of twelve syscalls... is set up to skip the export entirely, with Amatera resolving their syscall numbers on its own... and issuing each call through an indirect x64 syscall trampoline built at runtime.
Rather than creating a remote thread, Amatera hijacks the browser's thread pool, using the technique known as PoolParty variant 7 (Remote TP_DIRECT Insertion)... and queues a TP_DIRECT work item on it with NtSetIoCompletion, leaving the execution to one of the browser's own worker threads.
They relaunch through conhost.exe, locate MSBuild, and reconstruct a loader from encoded data.
Resolves APIs using API hashing and GetDelegateForFunctionPointer()
Its contents included a renamed legitimate MSBuild executable... In the documented RenPy chain, the final file posed as WPA.exe, the name of Windows Performance Analyzer.
The C++-compiled PE disguises itself as WPA.exe (Windows Performance Analyzer).
Rather than creating a remote thread, Amatera hijacks the browser's thread pool, using the technique known as PoolParty variant 7 (Remote TP_DIRECT Insertion)... and queues a TP_DIRECT work item on it with NtSetIoCompletion, leaving the execution to one of the browser's own worker threads.
a VBScript loader that decodes and runs PowerShell
ACR Stealer has also been propagated via ClickFix prompts that trigger a command spawning MSHTA to retrieve and execute remote HTA content from a threat actor-controlled domain.
EtherHiding to obtain the C2 domain, followed by HTTP requests using paths such as assets/{two random words}.json to retrieve subsequent stages.
EtherHiding to obtain the C2 domain, followed by HTTP requests using paths such as assets/{two random words}.json to retrieve subsequent stages.
Amatera beacons to gw.proxyvector[.]cc over TLS and resolves that host over DNS-over-HTTPS to dns.google and cloudflare-dns.com.
249 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
66 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified only in the headline as a stealer; the body does not provide further behavioral or campaign details for Amatera.
A native Win32 PE32 x86 password stealer masquerading as WPA.exe (Windows Performance Analyzer). It steals credentials and system data, exfiltrates them, communicates with gw.proxyvector[.]cc over TLS, resolves C2 through DNS-over-HTTPS, and installs a root certificate.
Information-stealing malware delivered as a final payload by PavinLoader; in the documented chain it masqueraded as WPA.exe and appeared as an obfuscated Amatera Stealer 4.2.3-alpha1 sample.
An information-stealing malware family distributed in a ClearFake campaign via ClickFix lures using a WebDAV-based approach.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.