logo

New ACRStealer Variant Uses Syscall Evasion, TLS C2 and Secondary Payload Delivery

ID: d72d7d77-02f2-5bc4-a7f5-31e007c47afc

STIX ID: report--d72d7d77-02f2-5bc4-a7f5-31e007c47afc

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A technical analysis reports an actively maintained ACRStealer variant delivered via the HijackLoader/PiviGames distribution chain that uses syscall-level evasion (resolving ntdll via the PEB and invoking syscalls through WoW64), constructs AFD-based raw TCP sockets via NtCreateFile, and completes TLS handshakes via SSPI to communicate with hardcoded C2 (observed 157.180.40.106 and playtogga.com); the malware steals browser and Steam credentials, fingerprints hosts, compresses exfiltrated data into an in-memory ZIP, and has been observed in the US, Mongolia, and Germany while the same chain has also delivered LummaStealer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.