New ACRStealer Variant Uses Syscall Evasion, TLS C2 and Secondary Payload Delivery
ID: d72d7d77-02f2-5bc4-a7f5-31e007c47afc
STIX ID: report--d72d7d77-02f2-5bc4-a7f5-31e007c47afc
Feed Name: cybersecurityNews.com
A technical analysis reports an actively maintained ACRStealer variant delivered via the HijackLoader/PiviGames distribution chain that uses syscall-level evasion (resolving ntdll via the PEB and invoking syscalls through WoW64), constructs AFD-based raw TCP sockets via NtCreateFile, and completes TLS handshakes via SSPI to communicate with hardcoded C2 (observed 157.180.40.106 and playtogga.com); the malware steals browser and Steam credentials, fingerprints hosts, compresses exfiltrated data into an in-memory ZIP, and has been observed in the US, Mongolia, and Germany while the same chain has also delivered LummaStealer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
