Listen to this Post
Cybersecurity experts are sounding the alarm about a new wave of cyberattacks exploiting cracked software to distribute dangerous information-stealing malware, including Lumma and ACR Stealer. The AhnLab Security Intelligence Center (ASEC) has reported a notable increase in the distribution of ACR Stealer since January 2025. This stealer malware utilizes a sophisticated technique known as dead drop resolver to locate and exploit command-and-control (C2) servers by leveraging legitimate platforms such as Steam, Telegram’s Telegraph, Google Forms, and Google Slides.
In this new attack vector, threat actors encode the actual C2 domain in Base64 format on specific web pages, which the malware accesses and decodes to carry out its malicious operations. Previously spread through Hijack Loader malware, ACR Stealer can harvest a wealth of sensitive information from compromised systems, including files, browser data, and cryptocurrency wallet extensions.
ASEC also uncovered another campaign that employs files with an “MSC” extension, executable by the Microsoft Management Console (MMC), to deliver Rhadamanthys stealer malware. This type of malware exploits vulnerabilities like CVE-2024-43572, also known as GrimResource, and downloads malicious PowerShell scripts masquerading as harmless documents. Recent reports indicate that over 30 million computers have been infected by such information stealers in recent years, allowing cybercriminals to sell stolen credentials on underground forums for profit.
The evolution of these malware campaigns underscores the persistent risks posed by information stealers, serving as initial access points for cybercriminals into sensitive corporate environments.
What Undercode Says:
The emergence of cracked software as a distribution method for information-stealing malware marks a concerning trend in cybersecurity. Cybercriminals are increasingly leveraging everyday software users might download, making it essential for individuals and organizations to be vigilant about the origins of their software. The ACR Stealer’s dead drop resolver technique illustrates a shift in sophistication, indicating that attackers are not only using traditional methods but are now embedding their operations within widely trusted platforms. This blend of malware with legitimate services complicates detection and response efforts.
Moreover, the discovery of the Rhadamanthys stealer, which uses MSC files to exploit Microsoft vulnerabilities, highlights the ongoing challenge of keeping systems secure against zero-day exploits. As CVE-2024-43572 demonstrates, even recently patched vulnerabilities can be exploited by malicious actors until users update their systems. The risk posed by these information stealers is compounded by their ability to harvest critical corporate credentials and session cookies, which can then be weaponized by other cybercriminals, further complicating the threat landscape.
The alarming statistic from Hudson Rock, indicating that cybercriminals can purchase stolen data for as little as $10 per log, underscores the economic incentives driving these cyberattacks. The commodification of stolen credentials enables a thriving underground economy, where access to sensitive information is readily available to those with malicious intent. This highlights the need for comprehensive cybersecurity strategies that encompass not only detection and response but also preventative measures to secure systems and educate users about the risks associated with downloading cracked software.
The ClickFix technique, which uses fake CAPTCHA pages to trick users into executing malicious PowerShell commands, illustrates the creative tactics employed by threat actors. This method not only broadens the attack surface but also indicates a shift towards more interactive and deceptive phishing techniques. As malware families continue to evolve, organizations must remain proactive in their defense strategies, investing in employee training, threat intelligence, and robust security protocols.
In conclusion, the landscape of cybersecurity is rapidly evolving, with information stealers playing a critical role as initial access vectors for cybercriminals. Understanding these threats and implementing multi-layered defenses is essential for safeguarding sensitive information in an increasingly perilous digital world.
References:
Reported By: https://thehackernews.com/2025/02/new-malware-campaign-uses-cracked.html
Extra Source Hub:
https://stackoverflow.com
Wikipedia: https://www.wikipedia.org
Undercode AI
Image Source:
OpenAI: https://craiyon.com
Undercode AI DI v2




