ACR
ACR is an information-stealing malware family. In the provided reporting, it is described as stealing browser data and cryptocurrency wallet information. Kaspersky observed a Vidar infection chain in which Vidar, distributed via YouTube comments linking to password-protected ZIP or RAR archives on rotating file-sharing platforms, ultimately downloaded ACR as the exfiltration component; most victims in that campaign were located in Brazil. The same reporting notes that the chain used a legitimate ImageMagick converter.exe vulnerable to DLL hijacking, a malicious vcomp100.dll, an encrypted bake.docx first-stage loader, and a blindworm.avi IDAT loader. Separate reporting states that the Amatera infostealer is based on the ACR infostealer, with code overlap cited as evidence. In those reports, Amatera is characterized as an actively developed malware-as-a-service infostealer that collects browser data and credentials, but only the code relationship to ACR is directly established. High-confidence capabilities directly attributed to ACR in the content are theft of browser data and crypto-wallet data.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer downloaded by Vidar in the observed campaign. It targets browser data and cryptocurrency wallets and serves as the exfiltration module for Vidar.
Referenced as the infostealer codebase/family that Amatera is based on; no additional behavior details provided in the content.
Referenced as the infostealer codebase/family that Amatera is based on (code overlap). No additional behavior details provided in the content beyond being an infostealer lineage.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.