s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932726 high

📛 Threat Title

ACR Stealer: Domain that is used for botnet Command&control (C&C) wss.scriptlab.cc

Category: ACR Stealer Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: ACR Stealer. Confidence: 100. First seen: 2026-09-25 08:11:36 UTC. Reporter: abuse_ch. Tags: ACRStealer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain wss.scriptlab.cc VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/wss.scriptlab.cc
UrlVoid 0 / 36

IOC database

Type
domain
Value
wss.scriptlab.cc
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Domain that is used for botnet Command&control (C&C) attributed to ACR Stealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/wss.scriptlab.cc

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: ACR Stealer. Confidence: 100. First seen: 2026-09-25 08:11:36 UTC. Reporter: abuse_ch. Tags: ACRStealer.

Remediations (10)

  • web:cyberreplay.com

    Q: What is the first practical step if I suspect ACR Stealer in my environment? A: Isolate suspected hosts from domain controllers and cloud consoles, collect volatile evidence, and force rotation of impacted credentials. Use the 4-hour playbook above and run immediate SIEM hunts for browser profile reads and unusual POST activity.

  • web:cyble.com

    While the ACR Stealer gathers sensitive information from the victim and transmits it to a command and control (C&C) server, the Latrodectus uses evasion techniques to maintain persistence on the victim's machine. It also collects user information and sends it to the command-and-control server (C&C) to conduct other malicious activities. The figure below shows the infection chain of this ...

  • web:gbhackers.com

    A surge in ACR Stealer activity from late April through mid-June 2026, with operators combining ClickFix social engineering, WebDAV-hosted payloads.

  • web:ismalicious.com

    396 indicators of compromise attributed to the ACR Stealer malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.

  • web:labs.cloudsecurityalliance.org

    Key Takeaways Microsoft Defender Experts tracked a sustained rise in ACR Stealer activity from late April through mid-June 2026, delivered through two distinct ClickFix intrusion chains that both begin with a victim pasting an attacker-supplied command into the Windows Run dialog [1][2].

  • web:malpedia.caad.fkie.fraunhofer.de

    The malware, written in C++, is compatible with Windows 7 through 10, and the seller manages all command and control (C2) infrastructure. ACR Stealer can harvest system information, stored credentials, web browser cookies, cryptocurrency wallets, and configuration files for various programs.

  • web:socprime.com

    ACR Stealer is an information-stealing malware family that uses ClickFix-style social engineering lures to target enterprise environments. The malware operates through two main infection chains: one that relies on WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control, and another that uses MSHTA with ...

  • web:thehackernews.com

    ACR Stealer campaigns use ClickFix lures, JPEG steganography, and WebDAV to steal browser tokens, passwords, PDFs, and synced Microsoft 365 files.

  • web:winbuzzer.com

    Microsoft warns that increased ACR Stealer activity uses ClickFix, WebDAV, and MSHTA routes to steal enterprise credentials, tokens, and cloud documents.

  • web:www.microsoft.com

    From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.