Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

ACR

ACR is an information-stealing malware family. In the provided reporting, it is described as stealing browser data and cryptocurrency wallet information. Kaspersky observed a Vidar infection chain in which Vidar, distributed via YouTube comments linking to password-protected ZIP or RAR archives on rotating file-sharing platforms, ultimately downloaded ACR as the exfiltration component; most victims in that campaign were located in Brazil. The same reporting notes that the chain used a legitimate ImageMagick converter.exe vulnerable to DLL hijacking, a malicious vcomp100.dll, an encrypted bake.docx first-stage loader, and a blindworm.avi IDAT loader. Separate reporting states that the Amatera infostealer is based on the ACR infostealer, with code overlap cited as evidence. In those reports, Amatera is characterized as an actively developed malware-as-a-service infostealer that collects browser data and credentials, but only the code relationship to ACR is directly established. High-confidence capabilities directly attributed to ACR in the content are theft of browser data and crypto-wallet data.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Stealth

1 technique
T1036MasqueradingEvidence1

The website impersonated the Homebrew package manager.

Credential Access

2 techniques
T1539Steal Web Session CookieEvidence1

In terms of functionality, the stealer is particularly interested in cryptocurrency wallets and browser data.

T1649Steal or Forge Authentication CertificatesEvidence1

Information stealers, which are used to collect credentials to then sell them on the dark web or use in subsequent cyberattacks, are actively distributed by cybercriminals.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

What is interesting here is that instead of stealing data, Vidar actually downloads the ACR stealer.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.