ACRStealer Infostealer Exploiting Google Docs as C2
ID: 8a273b56-0831-5b03-87b1-9ed4f40ae306
STIX ID: report--8a273b56-0831-5b03-87b1-9ed4f40ae306
Feed Name: ASEC
AhnLab ASEC warns of increasing distribution of ACRStealer, an infostealer masquerading as cracks/keygens that uses Dead Drop Resolver (DDR) hosted on legitimate services (Steam, telegra.ph, Google Docs) to obtain Base64-encoded C2 domains, download XOR/Base64-encrypted configuration, and exfiltrate a wide range of sensitive data (browser data, cryptocurrency wallets, password managers, FTP/chat/email clients). The report includes sample SHA256 hashes, C2 URLs and FQDNs and recommends avoiding illegal software and untrusted downloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
