Malware
ACRStealer
- First Reported
- Sep 8, 2026
- Latest Reported
- Sep 8, 2026
Reported Context (1)
- from that overwritten region. G DATA documented module stomping in a HijackLoader chain that delivered ACRStealer, using different DLLs, "evr.dll", and "rasapi32.dll" rather than the "dbghelp.dll" observed in our ClearFake WebDAV Chains Deliver Amatera, ZigCryptoStealer and Unauthorized NetSupport
Malware (3)
Threat Actors (1)
MITRE ATT&CK (12)
Vendors (2)
Products (5)
Tools (3)
Industries (1)
Countries (7)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.