ACR Stealer Delivered via Fake Claude Download Page (fairpoint29[.]com) — Google Ads SEO Poisoning Targeting Windows
ACR Stealer Delivered via Fake Claude Download Page (TL-2026-0584), also tracked as Amatera Stealer (Proofpoint name for 2025 rebrand), is a high-severity malware campaign, first published 2026-05-25. It has no confirmed attribution, affects Microsoft Windows, maps to 26 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0584
- Threat ID
- TL-2026-0584
- Also known as
- Amatera Stealer (Proofpoint name for 2025 rebrand), ACRStealer, GrMsk Stealer (predecessor)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-05-25
- Last reviewed
- 2026-05-25
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- consumers, developers, cryptocurrency, small-business, enterprise
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in ACR Stealer Delivered via Fake Claude Download Page
Malware and tooling: ACR Stealer, Amatera Stealer
Active malvertising campaign observed by SANS ISC on 2026-05-25 abuses Google Ads and sites.google[.]com redirectors to deliver ACR Stealer (a.k.a. Amatera Stealer) through fairpoint29[.]com, a page impersonating Anthropic's Claude. The Windows infection chain stages a 2.4MB malformed ZIP, a 4.1MB PowerShell loader, and a 628KB JPEG decoy before establishing HTTPS C2 with yw.enhanceblabber[.]cc. ACR Stealer is a MaaS infostealer descended from GrMsk Stealer that harvests credentials, crypto wallets, and session data from 200+ applications and uses Dead Drop Resolvers on legitimate platforms (Steam, Google Docs, Telegram) to hide live C2 endpoints.
How ACR Stealer Delivered via Fake Claude Download Page works
On 2026-05-25, SANS ISC handler Brad Duncan published telemetry for a live Windows infection that begins in Google search results. A malicious Google Ad surfaces a Google Sites page (sites.google[.]com) that conditionally redirects Windows visitors to fairpoint29[.]com — a clone of Anthropic's Claude download experience — while macOS visitors receive a different lure. Clicking the Windows ''Download'' button pulls a malformed ZIP from primemetricsa[.]com/1518925 (SHA256 70b5ecc1...213b2, 2,416,902 bytes). The ZIP requires manual extraction quirks to evade naive sandbox unpackers and drops a stager that fetches a 4,177,395-byte PowerShell script from hxxps://6ryuefl.creativecommunityinfo[.]art/Camel-91267b64-989f-49b4-89b4-9e015844d42d (SHA256 a14c3ecf...19692). The PowerShell stage in turn fetches a 628,035-byte JPEG (init-block.jpg, SHA256 47fa7464...4728f) hosted on the legitimate image-host i.ibb[.]co — a known technique for hiding shellcode or encrypted payloads in image steganography. Post-infection HTTPS callbacks were observed to yw.enhanceblabber[.]cc.
The traffic pattern, payload sizing, and use of an image-borne stage are consistent with ACR Stealer (also tracked by Proofpoint as Amatera Stealer after a 2025 rebrand). ACR Stealer is a Malware-as-a-Service infostealer that surfaced on Russian-language cybercrime forums in March 2024 as a fork of GrMsk Stealer and is sold under a subscription model. It targets over 200 applications across browsers (Chrome, Edge, Firefox, Brave, Opera), 100+ cryptocurrency wallets and browser extensions (MetaMask, Phantom, Trust Wallet, Exodus), password managers (Bitwarden, 1Password, KeePass), FTP clients (FileZilla, WinSCP, Total Commander), email clients (Thunderbird, Outlook), chat applications (Discord, Telegram, Signal), VPN clients, RDP/remote-admin tools, and authenticator apps. It also collects browser cookies, autofill data, credit cards, history, and bookmarks, then exfiltrates over HTTPS POSTs to its C2.
ACR Stealer''s defining tradecraft is its Dead Drop Resolver (DDR) C2 channel: instead of hard-coding C2 IPs/domains, the bot fetches an encoded blob (typically Base64 with an XOR layer) from operator-controlled profile fields on Steam Community, Google Docs, or Telegram, decodes the live C2 endpoint, then beacons. This lets operators rotate C2 without re-deploying binaries and makes traditional domain blocklisting brittle. Newer Amatera variants also use NTSockets to bypass userland networking APIs hooked by EDR, employ Heaven''s Gate (WoW64 32-to-64-bit transitions) for execution evasion, and persist via COM-object-created scheduled tasks that run every 10 minutes rather than only at logon.
Delivery via sites.google[.]com redirectors and Google Ads is operationally significant: the staging URL appears trusted to URL-reputation engines and Safe Browsing telemetry until the redirector chain is sinkholed. The fake Claude pages join a wider 2026 trend of impersonating AI tools (prior Threadlinqs cases include TL-2026-0546 PowerShell infostealer/EclecticIQ, TL-2026-0507 Pterodo+AMOS, TL-2026-0491 MacSync macOS, TL-2026-0463 RedLine via mshta). The ACR/Amatera operator(s) appear to be a distinct cluster — the C2 infrastructure (enhanceblabber[.]cc) and staging hosts (primemetricsa[.]com, creativecommunityinfo[.]art) do not overlap with those prior campaigns.
Defenders should block the listed domains and URL hosts, hunt for PowerShell child-of-archive-extraction patterns, monitor outbound HTTPS to .cc / .art / freshly-registered .com infrastructure following ZIP downloads from browsers, and inspect any process that reads a JPEG and then makes outbound network connections (typical image-steganography loader pattern). Browser-managed credential vaults and crypto-wallet extension directories should be force-rotated for any host that touched the IOCs.
MITRE ATT&CK techniques used in TL-2026-0584
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1546 Event Triggered Execution
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
execution
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
defense-impairment
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities
Affected products and versions in ACR Stealer Delivered via Fake Claude Download Page
- Microsoft — Windows
Vulnerable versions: 10; 11; Server 2019; Server 2022 - Google — Chrome / Chromium-based browsers (data harvest target)
Vulnerable versions: all - Mozilla — Firefox (data harvest target)
Vulnerable versions: all
Remediation for ACR Stealer Delivered via Fake Claude Download Page
Immediate actions
- Block fairpoint29[.]com, primemetricsa[.]com, creativecommunityinfo[.]art, and enhanceblabber[.]cc (and all subdomains) at perimeter DNS, web proxy, and EDR network filter
- Sinkhole or alert on the four listed IOC URLs in proxy logs going back 14 days
- Hunt EDR for SHA256 70b5ecc110e074dbca92932c0e840ea3492ea0a43c3f215b71392c12b02213b2, a14c3ecf5eb3d2543358482e43dc765dbf9ee7a4bec7571f5ecb8829ca719692, 47fa746422f1bf6b7712dc6803378e6a995488007193a7441d790f70d204728f
- For any host that touched the staging chain: rotate all browser-saved credentials, revoke active session cookies, force-rotate seed phrases for crypto wallets, and review password manager export logs
- Quarantine and re-image confirmed-infected hosts — ACR Stealer harvests credential material before any cleanup is possible
Workarounds
- Browser uBlock Origin + privacy filter lists block most malvertising redirector chains
- Group policy block on PowerShell.exe child-of-Explorer.exe execution under user temp paths
Longer-term hardening
- Deploy EDR with behavioral detection for PowerShell-spawned-from-archive-extractor chains and image-file-followed-by-outbound-connection patterns
- Enforce browser group policy to disable saved-password export and require OS-keychain-backed credential storage
- Mandate hardware-backed 2FA (WebAuthn/FIDO2) for all SaaS and crypto accounts to neutralise stolen cookie/session reuse
- Subscribe to Dead Drop Resolver feeds (Steam profile, Google Docs, Telegram channel monitoring) for ACR/Amatera C2 rotation
- Train staff that AI tool downloads should originate only from claude.ai, anthropic.com, openai.com, etc. — never from Google Ads results
Timeline of ACR Stealer Delivered via Fake Claude Download Page
- ACR Stealer first advertised as Malware-as-a-Service on Russian-speaking cybercrime forums; evolved from GrMsk Stealer predecessor
- AhnLab ASEC documents ACRStealer use of Google Docs as Dead Drop Resolver for C2 endpoint distribution
- Malwarebytes publishes analysis of ACRStealer Google Docs DDR technique and 200+ application targeting
- Proofpoint identifies rebrand to Amatera Stealer with NTSockets bypass, Heaven''s Gate WoW64 evasion, and COM-object scheduled task persistence
- Post-infection HTTPS C2 callbacks observed to yw.enhanceblabber[.]cc consistent with ACR Stealer family traffic patterns
- Multi-stage payload chain captured: 2.4MB malformed ZIP from primemetricsa[.]com, 4.1MB PowerShell from creativecommunityinfo[.]art, 628KB JPEG steganography stage from i.ibb[.]co
- SANS ISC handler Brad Duncan observes live Windows infection chain via Google Ads -> sites.google[.]com -> fairpoint29[.]com fake Claude download page
- SANS ISC diary entry #33018 published with full IOC set (4 URLs, 4 domains, 3 SHA256 hashes)
- As of 2026-05-29, this is still active: ACR/Amatera Stealer remains a live MaaS infostealer in active development (eSentire intercepted Amatera in a finance environment in late April 2026; new 4.0.2 beta with ChaCha20/ECDH and expanded harvesting). Fake-Claude/AI-tool malvertising delivery is an ongoing 2026 trend with no takedown or arrest; only rotating DDR C2 infra changes.
Sources cited for ACR Stealer Delivered via Fake Claude Download Page
- Possible ACR Stealer From Page Impersonating Claude
- Google Docs used by infostealer ACRStealer as part of attack
- ACR Stealer – Uncovering Attack Chains, Functionalities And IOCs
- ACRStealer Infostealer Exploiting Google Docs as C2
- Amatera Stealer: Rebranded ACR Stealer With Improved Evasion, Sophistication
- ACR Stealer (Malware Family) — Malpedia
- ACR (Infostealer) – CyberMaterial
Threats related to ACR Stealer Delivered via Fake Claude Download Page
- Cross-Platform Node.js NPM Stealer — Browser Credentials, Sensitive File Exfiltration, and WebSocket Reverse Shell (SHA256 049300aa…ddeb9, C2 216.126.225.243)
- Anthropic claude.ai Shared-Chat Feature Abused in ClickFix Malvertising Campaign Delivering MacSync macOS Infostealer
- ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest Browser and Microsoft 365 Data
- SHub Reaper - macOS Stealer Variant Bypasses Tahoe 26.4 Terminal Mitigation via applescript:// URL Scheme, Spoofs Apple/Google/Microsoft (SentinelOne)
Detection coverage for TL-2026-0584
As of 2026-05-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0584 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.