ACR Stealer is a Windows information-stealing malware family active since 2024 and commonly described as a malware-as-a-service offering. It is widely associated with the Amatera Stealer ecosystem and is believed to represent either a rebrand of, or a closely related evolution from, Amatera. The malware is designed to harvest browser-stored credentials and other high-value user and enterprise data, with observed campaigns focusing on enterprise environments.
ACR Stealer steals saved browser passwords, cookies, authentication tokens, and live session data from Chromium-based browsers including Google Chrome and Microsoft Edge. Observed variants access browser credential databases and use Windows DPAPI to decrypt protected data. Beyond browser theft, the malware searches for and collects PDF files, Microsoft 365 documents, and files stored in Desktop and Downloads locations, as well as content synchronized through OneDrive and SharePoint. Some reporting also attributes theft of clipboard contents, system information, and cryptocurrency wallet-related data to the family.
Recent intrusion chains have relied heavily on social engineering rather than software exploitation. A prominent delivery method is ClickFix, in which victims are tricked into pasting and executing attacker-supplied commands through Windows interfaces. Observed chains include one that loads a malicious DLL from a remote WebDAV location via rundll32, followed by heavily obfuscated PowerShell, a bundled Python loader, hidden scheduled-task persistence, timestomping, PowerShell history clearing, and in-memory execution of the final payload. A second prevalent chain is more fileless and uses mshta, HTA or VBScript content, obfuscated PowerShell, and steganographic extraction of an encrypted payload from a JPEG image for in-memory execution. Some variants also use blockchain-based dead-drop resolution, often described as EtherHiding, to retrieve updated payload or command-and-control locations.
ACR Stealer has also been observed as a final payload in broader malware distribution ecosystems, including campaigns using fake software or AI-assistant installation pages, malicious advertising, SEO poisoning, cracked software, and trojanized game or software packages delivered through loaders such as RenEngine and HijackLoader. It has been linked in separate reporting to operators including SideCopy, while other campaigns have not been conclusively attributed beyond the malware family itself.
The malware’s operational focus is credential theft, session hijacking, and exfiltration of sensitive enterprise documents, making it particularly relevant to organizations that rely on browser-based authentication and cloud-synchronized document repositories.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.
ACR Stealer, a malware-as-a-service (MaaS) information stealer written in C++ that has been active since 2024, makes its debut in a tie for 6th thanks to its use as a payload in recent ClearFake campaigns.
ACR Stealer is a credential and data theft infostealer written in C++ and used by the SideCopy threat group.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
It persists through a hidden scheduled task posing as a software update
The routine installs a bundled Python loader, creates a scheduled task masked as a software update, manipulates timestamps, clears PowerShell history, and injects the final payload into a system process for in-memory execution.
Microsoft recommends that organizations reduce exposure to web-based delivery chains by enforcing filters, blocking low-reputation or new domains, and restricting access to online resources that are not required for business operations. Application control rules can restrict launching content from a remote resource using tools like PowerShell, Python, mshta.exe, or rundll32.exe, especially from user-writeable paths.
After establishing communication with the command-and-control (C2) infrastructure, "a heavily obfuscated PowerShell script" is executed to launch a malware installer and establish persistence.
Two of the three variants Defender Experts saw use pushd to mount the remote share as a temporary local drive first
An embedded VBScript loader leans on COM objects to decode and fire PowerShell
A bundled pythonw.exe then launches the Python script, so nothing flashes on screen.
It persists through a hidden scheduled task posing as a software update
The routine installs a bundled Python loader, creates a scheduled task masked as a software update, manipulates timestamps, clears PowerShell history, and injects the final payload into a system process for in-memory execution.
hides the strings for pushd , rundll32 , and the remote host behind delayed environment-variable expansion. What follows is obfuscated PowerShell.
The malware then extracts an encrypted payload concealed inside a publicly hosted steganographic JPEG image and executes it directly in memory.
The routine installs a bundled Python loader, creates a scheduled task masked as a software update, manipulates timestamps, clears PowerShell history, and injects the final payload into a system process for in-memory execution.
The last stage stays in memory, handing execution through the Windows Fiber API.
The routine installs a bundled Python loader, creates a scheduled task masked as a software update, manipulates timestamps, clears PowerShell history, and injects the final payload into a system process for in-memory execution.
The routine installs a bundled Python loader, creates a scheduled task masked as a software update, manipulates timestamps, clears PowerShell history, and injects the final payload into a system process for in-memory execution.
This DLL is then executed, often disguised as a legitimate file.
For the second delivery chain, the threat actor uses ClickFix to launch MSHTA, which retrieves malicious content from the attacker's server and executes an obfuscated PowerShell downloader.
saved browser passwords, live session tokens... and invoking DPAPI to decrypt the passwords, cookies, and tokens they hold.
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
In some instances, a secondary Python loader communicates with blockchain RPC endpoints to retrieve payloads or command and control addresses.
In some cases, secondary loaders query public blockchain RPC services and Web3 infrastructure for command-and-control resolution, a dead-drop technique known as EtherHiding.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as related cleanup context from another report.
Named as another malware family distributed via ClickFix in the broader threat landscape.
Information-stealing malware offered as a malware-as-a-service operation. It is used to steal browser-stored passwords, cookies, session data, authentication tokens, PDFs, Microsoft 365 documents, files from Desktop and Downloads, and enterprise-synchronized OneDrive and SharePoint data. It uses ClickFix-based delivery, WebDAV or MSHTA execution chains, obfuscated PowerShell, a bundled Python loader, persistence via scheduled tasks, in-memory execution, and in some variants blockchain-based dead-drop resolution ('EtherHiding').
Information-stealing malware active since 2024 that relies on social engineering and user-executed commands. It steals browser credentials and session tokens, collects PDFs and Microsoft 365 documents, accesses files from synced OneDrive and SharePoint folders, and can be delivered through fileless mshta/PowerShell execution or via a DLL downloaded from a WebDAV share. In some cases, a secondary Python loader uses blockchain RPC endpoints to retrieve payloads or C2 addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.