ACR Stealer is a Windows information-stealing malware family active since 2024 and commonly described as a malware-as-a-service offering. It is widely assessed to be closely associated with, or a rebranding of, Amatera Stealer. The malware targets enterprise and individual victims by harvesting browser-stored credentials, cookies, authentication tokens, session data, and sensitive files, including PDFs, Microsoft 365 documents, and content from synchronized OneDrive and SharePoint folders. Reporting also links it to theft of data from cryptocurrency wallets, password managers, messengers, email clients, FTP clients, VPN clients, and other desktop applications.
Observed campaigns heavily rely on ClickFix-style social engineering rather than software exploitation. Victims are lured through fake verification or software-related prompts and tricked into pasting and executing attacker-supplied commands. Documented delivery chains include WebDAV-hosted DLL execution via rundll32, MSHTA- and HTA-based fileless execution, obfuscated PowerShell downloaders, Python-based loaders, and steganographic payload concealment in image files. ACR Stealer has also been delivered by phishing pages impersonating trusted brands, fake software installers, malicious ads, and cracked-software distribution chains, sometimes alongside other malware such as Latrodectus.
On infected systems, ACR Stealer accesses Chromium-family browser databases and uses Windows DPAPI to decrypt stored secrets. It steals saved passwords, cookies, and live session tokens, then searches local and synchronized storage for business-relevant documents and other high-value files before staging data for exfiltration. Some campaigns use in-memory execution, shellcode loaders, process injection, timestomping, log and history clearing, and hidden scheduled tasks to reduce visibility and maintain persistence. Certain variants or associated loaders have used blockchain-based dead-drop resolution techniques, including EtherHiding, to retrieve configuration data or command-and-control information.
Recent activity has particularly affected enterprise Windows environments, with campaigns observed stealing credentials and documents from corporate users. Because ACR Stealer is distributed through a MaaS ecosystem and overlapping delivery infrastructure, activity is not consistently attributable to a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.
ACR Stealer, a malware-as-a-service (MaaS) information stealer written in C++ that has been active since 2024, makes its debut in a tie for 6th thanks to its use as a payload in recent ClearFake campaigns.
ACR Stealer is a credential and data theft infostealer written in C++ and used by the SideCopy threat group.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
It downloaded the malware payload as a Python loader, installed scheduled tasks to maintain persistence
The script extracts, decrypts, and runs that payload in memory.
After establishing a connection to the command-and-control (C2) server, the attackers delivered an obfuscated PowerShell script that initiated the malware installation process.
Execution (TA0002) Native API (T1106) The NtCreateUserProcess() API is used to create a child process
The campaign relies on ClearFake, a long-running operation that compromises legitimate websites and places fake CAPTCHA checks over real pages. Visitors are told to complete a verification step, but the prompt actually guides them into running a malicious command through the Windows Run dialog.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
Defense Evasion(TA0005) Obfuscated Files or Information: Software Packing (T1027.002) Payload is encrypted inside the Resource section
The downloader then retrieved an encrypted payload from a public steganographic JPEG image and executed it in memory.
It hides a Python loader inside a folder that mimics real software. Then it sets a scheduled task disguised as an update for persistence.
The malware also used process injection to execute itself in memory, evading detection by security software.
The routine installs a bundled Python loader, creates a scheduled task masked as a software update, manipulates timestamps, clears PowerShell history, and injects the final payload into a system process for in-memory execution.
and attempted to clear the event logs, PowerShell history, and other tracking mechanisms.
It even copies file timestamps from a trusted Windows binary and wipes PowerShell history to blur the trail.
It even copies file timestamps from a trusted Windows binary and wipes PowerShell history to blur the trail.
If the suspicious installer ran, assume browser-saved passwords, cookies, authentication tokens, Discord or gaming sessions, and wallet data may have been exposed.
The stealer can target browser-held information, including credentials and data that may be valuable for account takeover or further fraud.
Credential Access (TA0006) Credentials from Password Stores: Credentials from Web Browsers (T1555.003) Tries to collect credentials from browsers
Command and Control (TA0011) Application Layer Protocol: Web Protocols (T1071.001) Communicates to C&C over HTTP
Some ACR Stealer variants used blockchain-based dead-drop resolvers to receive updates or C2 addresses.
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named stealer family referenced as the basis for Amatera.
Related Articles: Microsoft warns of surge in ACR Stealer attacks on customers
A credential and token stealing malware referenced as a possible later payload or related response case.
Mentioned only in related-articles text, not part of the primary event.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.