Stealers on the rise: Kral, AMOS, Vidar and ACR
· Published 21/10/2024 15:16 · Modified 21/10/2024 16:54
Essential information
- Published
- 21/10/2024 15:16
- Modified
- 21/10/2024 16:54
- Tags
- 2024-10-21 acr amos aurora credential-theft cryptocurrency data exfiltration dll hijacking information stealers kral macos penguish vidar
- Related entities
- 16 techniques (mitre), 17 malware, 1 others
Description
This intelligence report analyzes the increasing prevalence of information stealers, focusing on Kral, AMOS, Vidar, and ACR. Kral, delivered by its downloader, targets cryptocurrency wallets and browser data. AMOS, a macOS stealer, spreads through malvertising impersonating Homebrew. Vidar distributes via YouTube comments and uses DLL hijacking, ultimately downloading the ACR stealer. The report highlights the widespread nature of stealers, their popularity among cybercriminals, and the potential for stolen data to be used in further attacks or sold on the dark web. It emphasizes the importance of basic security measures like 2FA and downloading software only from official sources to mitigate these threats.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Techniques (MITRE) (16)
-
GUI Input Capture
-
Hidden Files and Directories
-
Data Staged
-
Software Packing
-
Malicious Link
-
Registry Run Keys / Startup Folder
-
Account Discovery
-
Web Protocols
-
Match Legitimate Resource Name or Location
-
Malicious File
-
Data from Local System
-
Ingress Tool Transfer
-
Masquerading
-
Deobfuscate/Decode Files or Information
-
Obfuscated Files or Information
-
Command and Scripting Interpreter
Malware (17)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:17 · Modified 21/12/2025 13:21
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 20/05/2026 17:45 · Modified 20/05/2026 17:45
-
FamilyPublished 20/05/2026 17:45 · Modified 20/05/2026 17:45
-
FamilyPublished 18/05/2026 17:52 · Modified 18/05/2026 17:52
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
-
FamilyPublished 16/06/2026 09:50 · Modified 16/06/2026 09:50
-
FamilyPublished 21/10/2024 15:16 · Modified 21/10/2024 15:16
Others (1)
- Brazil