logo

ACRStealer Variant Deploys Syscall Evasion, TLS C2, Secondary Payloads

ID: ce0a762a-221e-548b-b086-a273ad6dd106

STIX ID: report--ce0a762a-221e-548b-b086-a273ad6dd106

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

New research identifies an actively maintained, rebranded ACRStealer variant used as a final payload by HijackLoader and distributed via the PiviGames ecosystem; the malware employs low-level NTDLL/WoW64 syscalls and AFD-based sockets to evade API/EDR hooks, upgrades TCP to TLS via SSPI, bypasses DPAPI/Chrome protections to steal browser and Steam credentials, supports process hollowing and PowerShell-based secondary payloads, and exfiltrates staged data to infrastructure including IP 157.180.40.106 and playtogga.com with telemetry across the USA, Mongolia, and Germany.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.