Breakglass Intelligence reported that ACRStealer is running an active credential-theft operation through multiple delivery chains, including a compromised .edu WordPress site and a trojanized Chris-PC RAM Booster installer. The malware uses a four-stage infection flow that progresses from PowerShell or installer-based execution to Go and .NET loaders, then decrypts and injects shellcode in memory. Researchers said newer samples introduced a previously undocumented .NET loader, CoreHubManager, a new 16-byte XOR key, AES-256-CBC shellcode decryption, and Heaven’s Gate WoW64 transitions to run x64 code from a 32-bit process. Payloads were also signed with a stolen ASUSTeK EV code-signing certificate, allowing binaries such as sunwukongs.exe to better evade SmartScreen and other trust controls.
Once installed, ACRStealer steals credentials, browser data, DPAPI-protected secrets, Windows Hello NGC keys, smart card certificates, Azure AD OAuth tokens, wallets, documents, and tokens from more than 200 applications, then exfiltrates the data over HTTPS. The malware also uses custom AFD socket operations and dead-drop resolvers hosted on Steam, Google Docs/Slides, and Telegram pages to retrieve command-and-control infrastructure. Breakglass mapped 17 C2 IPs in the newer cluster and 9 live C2 servers in the earlier campaign, with the larger set hosted by VDSINA, pointing to a concentrated infrastructure footprint. Researchers also found overlap with SectopRAT, AmateraStealer, NetSupport RAT, OffLoader, HIjackLoader/IDATLoader, and ClickFix/FakeCAPTCHA chains, and said ACRStealer has been rebranded as AmateraStealer and marketed as a malware-as-a-service offering.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-14, SonicWall published a technical analysis describing ACRStealer as a stealthy Golang-based malware threat used to steal credentials and cryptocurrency wallet data. The report adds new technical characterization beyond the previously documented March 2026 campaign and infrastructure findings.
By 2026-03-16, reporting described an ACRStealer variant that used syscall-based evasion techniques, communicated with command-and-control over TLS, and was capable of deploying secondary payloads. The reference indicates a meaningful evolution in the malware's tradecraft beyond the earlier March 2026 campaign and infrastructure findings.
In the March 2026 follow-on analysis, researchers identified 17 command-and-control IPs used by the newer ACRStealer campaign and found they were all hosted by VDSINA. The report also stated that ACRStealer had been rebranded as AmateraStealer and was being marketed as a malware-as-a-service offering.
On 2026-03-09, a new ACRStealer sample surfaced on MalwareBazaar masquerading as a Chris-PC RAM Booster installer. Researchers said the sample used a revised four-stage chain with a new XOR key, a previously undocumented .NET loader called CoreHubManager, AES-256-CBC shellcode decryption, and Heaven's Gate transitions for in-memory execution.
By 2026-03-08, researchers reported an active ACRStealer (Arechclient2) credential-theft campaign using a four-stage PowerShell-to-Go infection chain, a compromised .edu WordPress site for payload hosting, and nine confirmed live command-and-control servers. The analysis also found abuse of a stolen ASUSTeK EV code-signing certificate and infrastructure overlap with SectopRAT and other malware families.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
sonicwall.com
Open sourcewebz.io
Open sourcegbhackers.com
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.