New ACRStealer Variant Uses Syscall Evasion, TLS C2 and Secondary Payload Delivery

A new variant of ACRStealer has emerged with upgraded capabilities that make it significantly harder to detect and more dangerous to the systems it targets. First reported by Proofpoint in early 2025 as a rebranded version of the Amatera Stealer, this latest iteration introduces low-level syscall evasion, encrypted C2 communication over TLS, and the ability […]

The post New ACRStealer Variant Uses Syscall Evasion, TLS C2 and Secondary Payload Delivery appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: