PULSE NAME
Endgame Harvesting: Inside ACRStealer's Modern Infrastructure
WHITE AlienVault 2026-03-17 Modified: 2026-03-17
6
IOCs
LOW VOLUME
ACRStealer, a sophisticated Malware as a Service, has evolved with enhanced evasion techniques and C2 communication strategies. It employs low-level syscalls and AFD for stealthy operations, bypassing user-mode hooks. The malware uses layered communication, establishing raw TCP connections followed by SSL/TLS over SSPI. ACRStealer's data-stealing capabilities are extensive, targeting browsers, Steam accounts, and performing victim fingerprinting. It can execute secondary payloads and capture screenshots. The malware shows an active infection pattern in countries like the USA, Mongolia, and Germany, communicating with specific IP addresses and domains. Recent developments indicate a shift to LummaStealer, suggesting ongoing threat actor activities targeting gaming platforms and social media.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ACRStealer HijackLoader LummaStealer
Indicators of Compromise (6)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 59db3cea92ecf965c435fdc4ea204f76 2026-03-17
FileHash-SHA1 d8a074cb8bd8710078694d08a814a37b65572e84 2026-03-17
FileHash-SHA256 f88c6e267363bf88be69e91899a35d6f054ca030e96b5d7f86915aa723fb268b 2026-03-17
FileHash-SHA256 59202cb766c3034c308728c2e5770a0d074faa110ea981aa88f570eb402540d2 2026-03-17
URL https://pivigames.blog/adbuho 2026-03-17
domain playtogga.com 2026-03-17