Last seven days
- First activity
- Sep 18, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 12 hostnames
ACR
ACR is an information-stealing malware family. In the provided reporting, it is described as stealing browser data and cryptocurrency wallet information. Kaspersky observed a Vidar infection chain in which Vidar, distributed via YouTube comments linking to password-protected ZIP or RAR archives on rotating file-sharing platforms, ultimately downloaded ACR as the exfiltration component; most victims in that campaign were located in Brazil. The same reporting notes that the chain used a legitimate ImageMagick converter.exe vulnerable to DLL hijacking, a malicious vcomp100.dll, an encrypted bake.docx first-stage loader, and a blindworm.avi IDAT loader. Separate reporting states that the Amatera infostealer is based on the ACR infostealer, with code overlap cited as evidence. In those reports, Amatera is characterized as an actively developed malware-as-a-service infostealer that collects browser data and credentials, but only the code relationship to ACR is directly established. High-confidence capabilities directly attributed to ACR in the content are theft of browser data and crypto-wallet data.
C2 tracking
Derp observations, rolling seven-day window
Samples
c9b1a9c171ca07c8fcc9154921305c24fef69644497f30db163e5700700f7fcb ed47d851bb0644f5f18fc573ec2456b34e004aac16b0d4d4b786cc054cc64fe1 5d05c8ae987c36c61344ec7f51bc4620059ad8f40b2629ba6595a24d67f6ec46 aba46c8f2f66a99733597746712c45a4a1750c2adf54c9d57c1c84df2b775750 ad0e92ef0a0e5be102819c951ddd0adcd668cf2592521bc170fd2f639cca621b c26b798fa5d4e7a5b9dc5478ccdc7f57af8d5d66f343cf4ed86c32e5ef2d1dcb efe6312c44c25aa49f246dd488b229556aba23b46a40ad7f1ea0dec09da03f03 398c56fb3a7ccf93374eeb367dae6fdaa1e49404c7fa59748bf16d87af39ad4d 431f3f1064aa30efe9df89246dbfac78edb1a1b82b1adadfce500540c002949f 4b5215ae343c6dff3fabbd68214f42e5d59e4bdaa4d0ee3cfc45d6f9af07efec MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.