TF-1932724
high
📛 Threat Title
ACR Stealer: Domain that is used for botnet Command&control (C&C) sso.activeloop.cc
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: ACR Stealer. Confidence: 100. First seen: 2026-09-25 08:11:04 UTC. Reporter: abuse_ch. Tags: ACRStealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
sso.activeloop.cc
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/sso.activeloop.cc
IOC database
- Type
- domain
- Value
sso.activeloop.cc- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Domain that is used for botnet Command&control (C&C) attributed to ACR Stealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/sso.activeloop.cc
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: ACR Stealer. Confidence: 100. First seen: 2026-09-25 08:11:04 UTC. Reporter: abuse_ch. Tags: ACRStealer.
Remediations (10)
-
web:any.run
ACR Stealer is a modern information-stealing malware designed to harvest sensitive data from infected devices. Like other infostealers, it targets credentials, financial details, browser data, and files, enabling cybercriminals to monetize stolen information through direct fraud or underground market sales.
-
web:cyberreplay.com
Q: What is the first practical step if I suspect ACR Stealer in my environment? A: Isolate suspected hosts from domain controllers and cloud consoles, collect volatile evidence, and force rotation of impacted credentials. Use the 4-hour playbook above and run immediate SIEM hunts for browser profile reads and unusual POST activity.
-
web:cybersecuritynews.com
ACR Stealer represents one of the most sophisticated information-stealing malware families actively circulating in 2025, distinguished by its advanced evasion techniques and comprehensive data harvesting capabilities. Originally emerging in March 2024 as a Malware-as-a-Service (MaaS) offering on Russian-speaking cybercrime forums, ACR Stealer has rapidly evolved from its predecessor, GrMsk ...
-
web:ismalicious.com
396 indicators of compromise attributed to the ACR Stealer malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.
-
web:malpedia.caad.fkie.fraunhofer.de
The malware, written in C++, is compatible with Windows 7 through 10, and the seller manages all command and control (C2) infrastructure. ACR Stealer can harvest system information, stored credentials, web browser cookies, cryptocurrency wallets, and configuration files for various programs.
-
web:socprime.com
ACR Stealer is an information-stealing malware family that uses ClickFix-style social engineering lures to target enterprise environments. The malware operates through two main infection chains: one that relies on WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control, and another that uses MSHTA with ...
-
web:thehackernews.com
ACR Stealer campaigns use ClickFix lures, JPEG steganography, and WebDAV to steal browser tokens, passwords, PDFs, and synced Microsoft 365 files.
-
web:www.microsoft.com
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.
-
web:www.proofpoint.com
This shellcode ultimately runs Amatera Stealer . Malware analysis Overview Amatera Stealer is a stealer written in C++ which is actively being developed and maintained as a MaaS. The rebranded malware is equipped with new features, including improved stealer capabilities and evasion features used to circumvent detection.
-
web:www.rescana.com
The use of PowerShell obfuscation, in-memory execution, and timestamp manipulation enables the malware to evade traditional endpoint detection and response (EDR) solutions. ACR Stealer targets browser databases, including those of Chrome, Edge, and Firefox, as well as applications such as Discord and Telegram.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.