Cyber Nightmare Returns: ACRStealer Rebrands as AmateraStealer, Unleashes New Powers

Listen to this Post

Featured Image
Silent but Deadly: A Rising Threat in the Cyber Shadows

The cybersecurity world is once again on high alert as AhnLab Security Intelligence Center (ASEC) reports a dramatic resurgence of the ACRStealer malware, now repackaged and rebranded as AmateraStealer. This malicious software, known for its relentless focus on stealing sensitive information, has returned stronger than ever — equipped with stealthier techniques, more advanced evasion capabilities, and improved communication strategies that make it nearly invisible to traditional defenses. With its roots stretching back to earlier this year, this new wave is part of an alarming trend where cyber threats evolve faster than most detection tools can respond.

The rebirth of ACRStealer isn’t just a cosmetic rebranding. The malware has integrated new methods such as Heaven’s Gate and direct interaction with the AFD driver using low-level system calls. These changes aren’t just for show — they’re designed to bypass API-level monitoring, making detection tools blind to its activity. Even more troubling, the malware now uses mismatched hostnames and IP addresses to fake legitimate traffic, hijacking names like microsoft.com and facebook.com to trick analysts and systems alike. Add AES-256 encryption, randomized endpoints, and a dynamic handshake process to the mix, and what you get is a chameleon-like infostealer that adapts per victim and remains hidden under layers of obfuscation.

The Shape-Shifting Menace in Detail

ACRStealer — now going by the name AmateraStealer, according to ProofPoint — is back in the wild with frightening improvements that challenge even the most robust cybersecurity protocols. Originally designed as an infostealer, it has evolved significantly to become a fully-fledged data exfiltration weapon, integrated with dynamic command-and-control (C2) architectures and anti-analysis techniques. ASEC researchers highlight how the new variant harnesses the Heaven’s Gate technique, which allows 64-bit shellcode to execute in a 32-bit environment using WoW64 processes. This unique setup hampers many behavioral analysis tools, allowing the malware to remain undetected as it operates under the radar.

Even more alarming is its novel method of communication. Instead of relying on traditional Windows network APIs like Winsock or WinHTTP, AmateraStealer communicates directly with the AFD driver using undocumented NT system calls like NtCreateFile and NtDeviceIoControlFile. This low-level approach enables the malware to construct and control HTTP traffic manually, circumventing many monitoring systems that rely on DLL hooks and high-level API tracing.

Further deepening the complexity, the malware manipulates HTTP request headers with false domain names, inserting trustworthy-sounding names like google.com or avast.com to mislead analysts and bypass filters. However, the actual traffic is sent to malicious IPs that have no connection to these domains, essentially smuggling stolen data through cloaked communication paths.

When it comes to encryption, earlier versions of the malware employed Base64 and RC4 with a hardcoded static key. But the latest variants have taken a serious leap forward, adopting AES-256-CBC encryption with embedded keys and initialization vectors. This ensures that every transmission remains confidential and difficult to reverse-engineer. Moreover, the malware now uses unique endpoints per victim session, determined through a JSON handshake during the initial infection. This dynamic path generation breaks signature-based detection, which often relies on static indicators.

AmateraStealer isn’t just stealing browser credentials or cryptocurrency wallets anymore. It’s targeting cloud storage accounts, FTP credentials, email access, and even sensitive documents. It also has the capability to deliver secondary payloads, making it a flexible tool in the attacker’s arsenal — whether for ransomware deployment, spyware installation, or extended network infiltration.

The situation is made worse by how quickly the malware’s infrastructure evolves. From using Cloudflare-protected servers in its early stages to now leveraging self-signed HTTPS certificates and altered header configurations, AmateraStealer is staying one step ahead of every containment method. The indicators of compromise (IOCs) reveal a spread of MD5 hashes and IPs that are already circulating in blacklists and threat reports, but with its dynamic nature, each day brings new versions and variants into the cyber battleground.

What Undercode Say:

Malware Innovation: A Dangerous Trend

What’s most concerning about AmateraStealer is how rapidly it’s innovating. In the span of a few months, it has progressed from a run-of-the-mill infostealer to an extremely advanced malware strain, armed with low-level API manipulation, dynamic endpoint generation, and hardened encryption. This isn’t just a testament to the capabilities of the developers behind it — it’s a stark reminder that the cybersecurity industry must constantly adapt or fall behind.

Command-and-Control Evolution

The decision to bypass traditional network APIs and engage directly with system-level drivers like AFD is no accident. It’s a targeted move designed to outwit behavioral detection engines, making the malware almost impossible to detect unless you’re monitoring at the kernel level. This bypass undermines conventional endpoint security tools and makes traditional logging strategies ineffective.

Network Obfuscation by Deception

Using spoofed domain names like microsoft.com in headers is particularly effective because it capitalizes on the trust built into network traffic. Many filters rely on DNS or hostname checks, so when fake domains are introduced into traffic logs, defenders often waste time chasing ghosts. This technique is not only clever, but also very difficult to reverse-engineer in real-time.

Encryption as a Weapon

By shifting from RC4 to AES-256-CBC encryption, the malware significantly increases its resilience. Static key detection no longer works. With embedded keys and vectors, and a unique session per victim, AmateraStealer makes traditional reverse engineering frustrating and time-consuming.

Rebranding Strategy: Marketing in Malware

The rebranding of ACRStealer to AmateraStealer isn’t just a name change — it reflects a wider trend in malware marketing. Just like companies rebrand to reposition their identity, threat actors do the same to dodge threat intel databases and sidestep pattern recognition tools. It’s an obfuscation tactic not just in code, but in reputation.

Broader Cybersecurity Implications

This evolution shows how malware authors are responding directly to defenses. Each layer of innovation in AmateraStealer answers a specific detection mechanism. From DLL monitoring evasion to dynamic session generation, every piece is engineered to neutralize a cybersecurity tool. It’s a battle of escalation, and currently, the attackers are winning.

Organizational Preparedness Lacking

Most businesses, especially small-to-medium enterprises, are not prepared for such deeply embedded threats. Standard firewalls, EDRs, or antivirus solutions won’t catch this unless configured at a forensic level. Few have that capability.

The Growing Infostealer Marketplace

ProofPoint’s research pointing to AmateraStealer as one of the most active infostealers further validates the rise of malware-as-a-service (MaaS). The developers behind this malware are clearly engaging in continuous updates and agile development, which makes it even more accessible to non-technical cybercriminals.

Final Warning: Watch the Indicators

Even with IOCs provided, organizations must understand that static defenses are outdated. AmateraStealer’s techniques require behavioral analysis, sandboxing at the kernel level, and advanced threat intelligence correlation. This is the future of malware defense — and we are already behind.

🔍 Fact Checker Results:

✅ The malware now uses AES-256-CBC encryption with embedded keys

✅ Rebranded as AmateraStealer and identified by ProofPoint

✅ Uses Heaven’s Gate and AFD-based communication to evade detection

📊 Prediction:

🔥 Expect more rebranded versions of AmateraStealer to appear with each month

💥 Malware-as-a-service platforms will continue adopting similar evasion tactics

🛡️ Next-gen cybersecurity tools will need to evolve toward kernel-level behavior analysis to stay effective

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin