New Variant of ACRStealer Actively Distributed with Modifications
Essential information
- Published
- 21/08/2025 16:16
- Modified
- 21/08/2025 20:26
- Tags
- 2025-08-21 acrstealer amaterastealer anti-analysis c2 communication data encryption detection evasion heaven's gate infostealer
- Related entities
- 2 malware
Description
A modified version of the ACRStealer infostealer is being actively distributed, featuring enhanced detection evasion and analysis obstruction techniques. The malware uses the Heaven's Gate technique for executing x64 code in WoW64 processes and implements low-level NT functions for C2 communications. It employs domain disguising, self-signed certificates, and data encryption. Recent variants have introduced random string paths for exfiltration and changed the configuration request method. ACRStealer, now rebranded as AmateraStealer, can steal sensitive information from various sources and install additional malware. The ongoing feature updates make it one of the most active infostealer variants, posing a significant threat to users.