Skip to content

ACR

ACR is an information-stealing malware family.

Profile source: Mallory opens in a new tab

ACR

Family profile

ACR is an information-stealing malware family. In the provided reporting, it is described as stealing browser data and cryptocurrency wallet information. Kaspersky observed a Vidar infection chain in which Vidar, distributed via YouTube comments linking to password-protected ZIP or RAR archives on rotating file-sharing platforms, ultimately downloaded ACR as the exfiltration component; most victims in that campaign were located in Brazil. The same reporting notes that the chain used a legitimate ImageMagick converter.exe vulnerable to DLL hijacking, a malicious vcomp100.dll, an encrypted bake.docx first-stage loader, and a blindworm.avi IDAT loader. Separate reporting states that the Amatera infostealer is based on the ACR infostealer, with code overlap cited as evidence. In those reports, Amatera is characterized as an actively developed malware-as-a-service infostealer that collects browser data and credentials, but only the code relationship to ACR is directly established. High-confidence capabilities directly attributed to ACR in the content are theft of browser data and crypto-wallet data.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 9, 2026
Feed role
C2 / Distribution
Host form
5 IP / 25 hostnames

Leading locations

  • US22
  • PL3
  • FI1
  • IT1
  • LU1

Leading providers

  • Cloudflare, Inc.22
  • GLOBAL CONNECTIVITY SOLUTIONS LLP2
  • ZORNTECH WEB SOLUTIONS2
  • Emil Vitukhnovskii trading as Great Flower1
  • Ghosty Networks LLC1

Infrastructure traits

  • Hosting 28
  • Anycast 22
  • Proxy 1

Samples

Recent associated samples

MITRE ATT&CK

ACR in ATT&CK

4 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.