Researchers studying cybersecurity are alerting people to a new operation that uses software cracks as a ruse to spread information thieves such as Lumma and ACR Stealer.
ACR Stealer’s distribution volume has increased since January 2025, according to the AhnLab Security Intelligence Center (ASEC).
The use of a method known as dead drop resolver to extract the actual command-and-control (C2) server is a noteworthy feature of the stealer malware. This involves depending on trustworthy platforms such as Google Forms, Google Slides, Steam, and Telegraph on Telegram.
According to ASEC, threat actors access the Base64-encoded C2 domain on a certain page read more about New Malware Campaign Uses Cracked Software to Spread Lumma and ACR Stealer.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
