ACR Stealer Delivered via Fake Claude Download Page (fairpoint29[.]com) — Google Ads SEO Poisoning Targeting Windows — Threadlinqs Intelligence
As of 2026-05-30, ACR Stealer Delivered via Fake Claude Download Page (fairpoint29[.]com) — Google Ads SEO Poisoning Targeting Windows is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0584 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Active malvertising campaign observed by SANS ISC on 2026-05-25 abuses Google Ads and sites.google[.]com redirectors to deliver ACR Stealer (a.k.a. Amatera Stealer) through fairpoint29[.]com, a page
On 2026-05-25, SANS ISC handler Brad Duncan published telemetry for a live Windows infection that begins in Google search results. A malicious Google Ad surfaces a Google Sites page (sites.google[.]com) that conditionally redirects Windows visitors to fairpoint29[.]com — a clone of Anthropic's Claude download experience — while macOS visitors receive a different lure. Clicking the Windows ''Download'' button pulls a malformed ZIP from primemetricsa[.]com/1518925 (SHA256 70b5ecc1...213b2, 2,416,902 bytes). The ZIP requires manual extraction quirks to evade naive sandbox unpackers and drops a stager that fetches a 4,177,395-byte PowerShell script from hxxps://6ryuefl.creativecommunityinfo[.]art/Camel-91267b64-989f-49b4-89b4-9e015844d42d (SHA256 a14c3ecf...19692). The PowerShell stage in turn fetches a 628,035-byte JPEG (init-block.jpg, SHA256 47fa7464...4728f) hosted on the legitimate image-host i.ibb[.]co — a known technique for hiding shellcode or encrypted payloads in image steganography. Post-infection HTTPS callbacks were observed to yw.enhanceblabber[.]cc.
The traffic pattern, payload sizing, and use of an image-borne stage are consistent with ACR Stealer (also tracked by Proofpoint as Amatera Stealer after a 2025 rebrand). ACR Stealer is a Malware-as-a-Service infostealer that surfaced on Russian-language cybercrime forums in March 2024 as a fork of GrMsk Stealer and is sold under a subscription model. It targets over 200 applications across browsers (Chrome, Edge, Firefox, Brave, Opera), 100+ cryptocurrency wallets and browser extensions (MetaMask, Phantom, Trust Wallet, Exodus), password managers (Bitwarden, 1Password, KeePass), FTP clients (FileZilla, WinSCP, Total Commander), email clients (Thunderbird, Outlook), chat applications (Discord, Telegram, Signal), VPN clients, RDP/remote-admin tools, and authenticator apps. It also collects browser cookies, autofill data, credit cards, history, and bookmarks, then exfiltrates over HTTPS POSTs to its C2.
ACR Stealer''s defining tradecraft is its Dead Drop Resolver (DDR) C2 channel: instead of hard-coding C2 IPs/domains, the bot fetches an encoded blob (typically Base64 with an XOR layer) from operator-controlled profile fields on Steam Community, Google Docs, or Telegram, decodes the live C2 endpoint, then beacons. This lets operators rotate C2 without re-deploying binaries and makes traditional domain blocklisting brittle. Newer Amatera variants also use NTSockets to bypass userland networking APIs hooked by EDR, employ Heaven''s Gate (WoW64 32-to-64-bit transitions) for execution evasion, and persist via COM-object-created scheduled tasks that run every 10 minutes rather than only at logon.
Delivery via sites.google[.]com redirectors and Google Ads is operationally significant: the staging URL appears trusted to URL-reputation engines and Safe Browsing telemetry until the redirector chain is sinkholed. The fake Claude pages join a wider 2026 trend of impersonating AI tools (prior Threadlinqs cases include TL-2026-0546 PowerShell infostealer/EclecticIQ, TL-2026-0507 Pterodo+AMOS, TL-2026-0491 MacSync macOS, TL-2026-0463 RedLine via mshta). The ACR/Amatera operator(s) appear to be a distinct cluster — the C2 infrastructure (enhanceblabber[.]cc) and staging hosts (primemetricsa[.]com, creativecommunityinfo[.]art) do not overlap with those prior campaigns.
Defenders should block the listed domains and URL hosts, hunt for PowerShell child-of-archive-extraction patterns, monitor outbound HTTPS to .cc / .art / freshly-registered .com infrastructure following ZIP downloads from browsers, and inspect any process that reads a JPEG and then makes outbound network connections (typical image-steganography loader pattern). Browser-managed credential vaults and crypto-wallet extension directories should be force-rotated for any host that touched the IOCs.
Target sectors: consumers, developers, cryptocurrency, small-business, enterprise
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1608, T1588, T1189, T1566, T1204, T1204, T1059, T1053