logo

Google Docs used by infostealer ACRStealer as part of attack

ID: 57b50672-4611-5356-9232-3c45011ba82f

STIX ID: report--57b50672-4611-5356-9232-3c45011ba82f

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-02-20

Date Updated: 2026-04-28

...
...

**ACRStealer** is an information-stealing malware active since mid-2024 and gaining traction in 2025; it is distributed via cracks/keygens and operated as Malware-as-a-Service. Notable capabilities include harvesting browser credentials, crypto wallets, FTP credentials, and reading text files, while leveraging Dead Drop Resolver techniques (using Google Docs and Steam) to obtain C2 domains and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.