Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 25 hostnames
ACR
ACR is an information-stealing malware family. In the provided reporting, it is described as stealing browser data and cryptocurrency wallet information. Kaspersky observed a Vidar infection chain in which Vidar, distributed via YouTube comments linking to password-protected ZIP or RAR archives on rotating file-sharing platforms, ultimately downloaded ACR as the exfiltration component; most victims in that campaign were located in Brazil. The same reporting notes that the chain used a legitimate ImageMagick converter.exe vulnerable to DLL hijacking, a malicious vcomp100.dll, an encrypted bake.docx first-stage loader, and a blindworm.avi IDAT loader. Separate reporting states that the Amatera infostealer is based on the ACR infostealer, with code overlap cited as evidence. In those reports, Amatera is characterized as an actively developed malware-as-a-service infostealer that collects browser data and credentials, but only the code relationship to ACR is directly established. High-confidence capabilities directly attributed to ACR in the content are theft of browser data and crypto-wallet data.
C2 tracking
Derp observations, rolling seven-day window
Samples
135a043a8f82ba68f63d89b021cc59612a12cb99d45b03401e1336a182505263 46acea6234c6f736875da166cc4ab5846e8500068bee2c242b87a003cd6272fb 8cbe48fc14585b878bda6c568ae10e1c0f063034c86f868b3cc324354596d32f 980a72c6f89d4366c80501936b9426c9133efe5c874dce76c8749418ef265293 ad5d551335f98af221996306603a1618f990832bf6fdda23200e886be5a28f99 b2ab8825b84e6f0209cf713dcf7156c93ae82f37a6d9f0ca9072e228825c8d63 b871f50abbd7e06e6dbede78f499c2efc426d7f8ba08943f06e104f82d8ecc0c cd3ffa5bdcb46a7a311961ca8efeefdb0be5be87529bf8067424ce1d5e73de3b cdb2923a71676351102c609f1a878a9981a085bbd5eb901281d80571366f6557 ea8ca32d81cc45da52aa24f7b2f1808c612cff1904a6735582ce26b9c05f3567 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.