Infostealer
ACR Stealer
First introduced in March 2024, ACR Stealer is an information stealer sold as a Malware-as-a-Service (MaaS) on Russian-speaking cybercrime forums by a threat actor named "SheldIO".
ACR Stealer is a Windows infostealer.
Background
ACR Stealer debuted in March 2024 as an information stealer marketed under a Malware-as-a-Service (MaaS) model on Russian-language cybercrime forums by an actor going by "SheldIO". Analysts believe it represents a further development of the GrMsk Stealer, which likely corresponds to the private stealer SheldIO had been selling since July 2023. Written in C++ and supporting Windows 7 through 10, the malware relies on the seller to operate all command-and-control (C2) infrastructure. It is capable of collecting system details, saved credentials, browser cookies, cryptocurrency wallets, and configuration files belonging to various applications. To hide its true C2 servers, ACR Stealer uses the dead drop resolver (DDR) technique.
Source: Malpedia (Fraunhofer FKIE).