TF-1932726
high
📛 Threat Title
ACR Stealer: Domain that is used for botnet Command&control (C&C) wss.scriptlab.cc
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: ACR Stealer. Confidence: 100. First seen: 2026-09-25 08:11:36 UTC. Reporter: abuse_ch. Tags: ACRStealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
wss.scriptlab.cc
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/wss.scriptlab.cc
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
wss.scriptlab.cc- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Domain that is used for botnet Command&control (C&C) attributed to ACR Stealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/wss.scriptlab.cc
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: ACR Stealer. Confidence: 100. First seen: 2026-09-25 08:11:36 UTC. Reporter: abuse_ch. Tags: ACRStealer.
Remediations (10)
-
web:cyberreplay.com
Q: What is the first practical step if I suspect ACR Stealer in my environment? A: Isolate suspected hosts from domain controllers and cloud consoles, collect volatile evidence, and force rotation of impacted credentials. Use the 4-hour playbook above and run immediate SIEM hunts for browser profile reads and unusual POST activity.
-
web:cyble.com
While the ACR Stealer gathers sensitive information from the victim and transmits it to a command and control (C&C) server, the Latrodectus uses evasion techniques to maintain persistence on the victim's machine. It also collects user information and sends it to the command-and-control server (C&C) to conduct other malicious activities. The figure below shows the infection chain of this ...
-
web:gbhackers.com
A surge in ACR Stealer activity from late April through mid-June 2026, with operators combining ClickFix social engineering, WebDAV-hosted payloads.
-
web:ismalicious.com
396 indicators of compromise attributed to the ACR Stealer malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.
-
web:labs.cloudsecurityalliance.org
Key Takeaways Microsoft Defender Experts tracked a sustained rise in ACR Stealer activity from late April through mid-June 2026, delivered through two distinct ClickFix intrusion chains that both begin with a victim pasting an attacker-supplied command into the Windows Run dialog [1][2].
-
web:malpedia.caad.fkie.fraunhofer.de
The malware, written in C++, is compatible with Windows 7 through 10, and the seller manages all command and control (C2) infrastructure. ACR Stealer can harvest system information, stored credentials, web browser cookies, cryptocurrency wallets, and configuration files for various programs.
-
web:socprime.com
ACR Stealer is an information-stealing malware family that uses ClickFix-style social engineering lures to target enterprise environments. The malware operates through two main infection chains: one that relies on WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control, and another that uses MSHTA with ...
-
web:thehackernews.com
ACR Stealer campaigns use ClickFix lures, JPEG steganography, and WebDAV to steal browser tokens, passwords, PDFs, and synced Microsoft 365 files.
-
web:winbuzzer.com
Microsoft warns that increased ACR Stealer activity uses ClickFix, WebDAV, and MSHTA routes to steal enterprise credentials, tokens, and cloud documents.
-
web:www.microsoft.com
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.