Google Docs used by infostealer ACRStealer as part of attack
ID: 57b50672-4611-5356-9232-3c45011ba82f
STIX ID: report--57b50672-4611-5356-9232-3c45011ba82f
Feed Name: Malwarebytes Blog
Threat Score
**ACRStealer** is an information-stealing malware active since mid-2024 and gaining traction in 2025; it is distributed via cracks/keygens and operated as Malware-as-a-Service. Notable capabilities include harvesting browser credentials, crypto wallets, FTP credentials, and reading text files, while leveraging Dead Drop Resolver techniques (using Google Docs and Steam) to obtain C2 domains and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
