ACRStealer, also associated with the Arechclient2 and later AmateraStealer branding, is a Windows-focused information stealer used in active cybercrime operations and frequently distributed through multi-stage malware delivery ecosystems. It is commonly delivered through cracked-software and keygen lures promoted via SEO poisoning, fake installer and documentation pages, ClickFix-style social engineering, PowerShell droppers, and DLL sideloading chains. It has also been observed as a payload delivered by other malware families and loaders including HijackLoader, OffLoader, and related staging components, and has appeared in broader campaigns such as ClearFake and ShadowLadder.
The malware is designed to harvest a wide range of victim data, including browser credentials, cookies, saved payment-card data, cryptocurrency wallet information, application credentials, tokens, password-manager data, email and FTP client data, VPN and remote-access data, cloud-related credentials, and documents. Reporting also links some variants to theft of Steam and other gamer-related credentials. More advanced components attributed to the ACRStealer ecosystem have been assessed to target DPAPI-protected secrets, Windows Hello key material, smart-card certificates, and Azure AD authentication tokens.
ACRStealer uses layered evasion and staging techniques. Observed tradecraft includes PowerShell-based first-stage loaders, Go- and .NET-based intermediate loaders, Python abuse, AMSI bypassing, shellcode execution, process injection, and extensive DLL sideloading with trojanized or modified libraries paired with legitimate executables. Variants have used dead-drop resolvers hosted on public platforms such as Steam profiles, Google services, and Telegraph pages to conceal real command-and-control endpoints. Newer variants have also adopted stronger command-and-control encryption, including ECDH key exchange with ChaCha20-Poly1305, and some campaigns used HTTPS-based exfiltration with encrypted upload paths.
The malware is associated with financially motivated credential-theft activity rather than espionage. Infrastructure and campaign overlap connect it with SectopRAT and other commodity malware operations, suggesting a broader shared ecosystem or common operator set in some cases. It has been marketed as a malware-as-a-service offering under the AmateraStealer name. Victims have included individual users, gamers, developers, and enterprise users, with lures tailored to software piracy, developer tooling, fake verification prompts, and compromised legitimate websites.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Experts found over 88 fake domains mimicking Claude Code and other developer sites. The campaign utilises SEO infection and Google ads to deploy malicious install web pages over genuine documentation.
MITRE ATT&CK Mapping Tactic Technique ID Notes Resource Development Acquire Infrastructure: Domains T1583.001 casyetnx[.]pw via CNOBIN, hosting via dataforest/VDSINA
ClearFake spreads by compromising legitimate websites and injecting hidden JavaScript code into their pages. Victims do not need to do anything suspicious to get infected. Simply visiting a tampered legitimate site can trigger the malware’s multi-stage delivery chain.
You copy a command. You paste it in your terminal. By then, it’s already too late.
Stage 1 -- ACRStealer Dropper : A PowerShell script hosted at hxxps://casyetnx[.]pw/eq8e1l4b0qjd22w
Stage 3 -- Legitimate Python Binary : The ZIP extracts to a directory containing FNPLicensingService.exe -- which is actually a renamed, legitimately signed CPython 3.15 pythonw.exe... Stage 4 -- Obfuscated Python Loader : chrome_100_percent.pak ... is an ASCII text file containing obfuscated Python code.
Experts found various delivery techniques, such as rundll32.exe loading infected DLLs, Base64-encoded commands, mshta.exe abuse, JavaScript-based payloads, and GitHub-hosted scripts.
Windows users were instructed to open the Run dialog and paste it, loading a remote DLL into memory with no file ever written to disk.
Windows users were instructed to open the Run dialog and paste it, loading a remote DLL into memory with no file ever written to disk.
The delivery diversity is striking: DLL Sideloading ... ZIPs containing a legitimate executable alongside a malicious DLL ... ISO Images ... MSI Installers ... HTA Droppers
The attacker directly tampered with and injected malicious code into a specific Python script (.py) inside the legitimate Python library folder (Lib). They then packaged this modified script together with a legitimate Python executable into a compressed archive and distributed it.
Experts found various delivery techniques, such as rundll32.exe loading infected DLLs, Base64-encoded commands... After execution, the malware uses a multi-level malicious chain that features encoded C2 communications...
After execution, the malware uses a multi-level malicious chain that features encoded C2 communications, anti-analysis capabilities, fileless execution tactics, and credential theft functions.
This report covers infostealers disguised as illegal software such as cracks and keygens... Microsoft Corporation was the most frequently impersonated company, followed by Auslogics, NVIDIA Corporation, Virtual Holding Resources, LLC, and Adobe Inc.
Experts found various delivery techniques, such as rundll32.exe loading infected DLLs, Base64-encoded commands, mshta.exe abuse, JavaScript-based payloads, and GitHub-hosted scripts.
Experts found various delivery techniques, such as rundll32.exe loading infected DLLs...
After execution, the malware uses a multi-level malicious chain that features encoded C2 communications, anti-analysis capabilities...
Victims on Windows and macOS were routed to separate payloads tailored to their operating system, with routing handled by real-time OS detection in the browser.
The attacker directly tampered with and injected malicious code into a specific Python script (.py) inside the legitimate Python library folder (Lib). They then packaged this modified script together with a legitimate Python executable into a compressed archive and distributed it.
Victims saw a convincing fake Google reCAPTCHA overlay complete with an “I’m not a robot” checkbox. Clicking it triggered the ClickFix social engineering panel...
Contrary to infostealers, the campaign pick on AI assets like authentication tokens, API Key, and cloud development credentials from tools such as Continue[.]dev, Cline.
Victims saw a convincing fake Google reCAPTCHA overlay complete with an “I’m not a robot” checkbox. Clicking it triggered the ClickFix social engineering panel...
ImageSharp Screenshot capture -- the stealer grabs what is on your screen
Clicking it triggered the ClickFix social engineering panel, which simultaneously injected a malicious command directly into the victim’s clipboard.
What It Steals ACRStealer targets a comprehensive list: Chrome, Firefox, Edge, Opera, Brave, and Vivaldi browser data (logins, cookies, history, autofill, credit cards); crypto wallets ... FTP clients ... email ... VPN configs ... password managers ... and chat apps
Threat actors used a technique called EtherHiding to store payload routing instructions inside blockchain smart contracts, bypassing all URL-based blocking methods entirely.
Dead Drop Resolver: Hiding C2 in Plain Sight ... The attacker creates profiles on Steam Community, Google Docs, Google Slides, or Telegram ... The malware fetches the page ... and decodes the Base64 to obtain the real C2 address
166 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer observed in June 2026 distribution activity, including campaigns disguised as cracks/keygens and delivered through SEO poisoning and cloud/file-sharing platforms.
Infostealer distributed disguised as illegal software such as cracks and keygens.
Information-stealing malware used as the primary payload in the campaign. It targets credentials, authentication tokens, API keys, and cloud development credentials, and is described as using sophisticated encryption, anti-analysis, encoded C2 communications, fileless execution, and evasion tactics.
Referenced only as a comparison family that did not technically match the observed sample.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.