typeanalysisfamilyacrstealerconfidencehighcreated2026-08-16updated2026-08-16infostealergolangsigningcompilerevasionc2
SHA-256: a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992

acrstealer: a02296ce — Go 1.20.6 signed sibling, GlobalSign DV TLS cert, 34 randomized main functions

Executive Summary

Go 1.20.6 PE32 infostealer sibling of the acrstealer cluster, masquerading as CuService.exe and signed with a valid GlobalSign DV TLS certificate (CN=seekingalpha.com). Thirty-four randomized main.* functions, randomized module path XXjuhfDdZFXrSHR, two-icon .rsrc suite, and no static C2 — all consistent with the ACR baseline. Static-only analysis (CAPE skipped — no Windows guest). Resolves from contested OpenCTI label cloud55file-cc.

What It Is

  • SHA-256: a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992
  • Filename: CuService.exe ^[file.txt]
  • Type: PE32 executable (GUI) Intel 80386, 7 sections, stripped to external PDB ^[file.txt]
  • Size: 1 703 112 bytes
  • Timestamp: 0x0 (Thu Jan 1 00:00:00 1970 UTC) — null, typical of Go -trimpath builds ^[pefile.txt:34]
  • Family: acrstealer (resolved from OpenCTI cloud55file-cc contested label)
  • Dynamic analysis: skipped — no CAPE Windows guest available ^[dynamic-analysis.md]

How It Works

This is a cluster sibling; shared behavior (PRNG-seeded C2 decoding, browser/wallet credential targeting, TLS/HTTPS exfil) is documented on acrstealer. Per-sample deltas below.

Build / RE Lens

Toolchain: Go 1.20.6 (go1.20.6), gc compiler, -buildmode=exe, -trimpath=true, CGO_ENABLED=0, GOARCH=386, GOOS=windows, GO386=sse2 ^[strings.txt:944] ^[strings.txt:948–954]. No external packer or crypter — .text entropy 6.11, within normal range for Go static binaries ^[pefile.txt:92].

Signing: Authenticode-signed with a valid GlobalSign DV TLS certificate embedded in IMAGE_DIRECTORY_ENTRY_SECURITY (offset 0x19F408, size 0x8C8) ^[binwalk.txt] ^[pefile.txt:232–234]. Inner X.509:

  • Subject: CN = seekingalpha.com
  • Issuer: CN = GlobalSign Atlas R3 DV TLS CA 2025 Q4
  • Validity: Dec 9 2025 — Jan 10 2027
  • SHA-256 fingerprint: 0D:15:42:B8:AD:6F:4F:7F:F2:01:66:8D:32:15:59:69:BF:67:F3:A8:2E:18:39:1D:0E:87:1F:9F:1C:BE:6B:92

This is a TLS certificate chain reused for code signing, same chain observed on ACR sibling f0105851 ^[rabin2-info.txt:27]. The cert is commercially trusted at detonation time, which suppresses SmartScreen and reputation-based blocks.

Obfuscation / anti-analysis:

  • Randomized Go module path: XXjuhfDdZFXrSHR ^[strings.txt:946–947]
  • Thirty-four randomized main.* function names (e.g. main.dfmqjjppyfnrvuj, main.gkjiotaekzcz, main.mnadgmqvxxzfhf, main.ddloigjcgnryswk, main.jsytyw, main.xdtvbsszfax, main.ydyjyjkagev, main.ofyhqmbmlgzx) ^[strings.txt:4366–4375]. This poisons string-based clustering and complicates rule authorship.
  • No static C2 URLs, IPs, or domains in strings — C2 is runtime-decoded (inferred from family pattern and absence of any network constants)
  • No debug symbols, no PDB path, no Rich header
  • stripped true per radare2 ^[rabin2-info.txt:30]

Resources: .rsrc section contains a two-icon suite (RT_ICON id 1 and id 2, both LANG_ENGLISH US) ^[pefile.txt:329–378]. This is a reduced icon set compared to the five-icon suite common on the quiverquant.com/WE1 cert chain, suggesting builder configuration variation.

Code quality: Go standard-library binary. All imports routed through kernel32.dll (LoadLibraryA/W, GetProcAddress, VirtualAlloc, CreateThread, etc.) ^[pefile.txt:269–317]. No suspicious API imports directly visible in the IAT — Go runtime loads everything dynamically via syscall.LazyDLL / syscall.LazyProc, which is standard for Go on Windows but also serves as mild obfuscation.

Deploy / ATT&CK Lens

Execution — T1204.002 (Malicious File — User Execution): CuService.exe filename masquerades as a benign system service. ^[triage.json:5]

Persistence — None observed statically; family pattern suggests no persistent installation in baseline builds (run-once infostealer). If the builder enables persistence, it would likely use registry Run keys (T1547.001) or scheduled tasks (T1053.005) — not visible in this sample.

Defense Evasion —

  • T1027 (Obfuscated Files or Information): randomized function names and module path. ^[strings.txt:4366–4375]
  • T1036.005 (Match Legitimate Name or Location): CuService.exe masquerade and seekingalpha.com certificate chain. ^[triage.json:5]
  • T1553.002 (Subvert Trust Controls — Code Signing): valid GlobalSign DV TLS certificate abused for code-signing trust. ^[binwalk.txt]
  • T1497.001 (Virtualization/Sandbox Evasion — System Checks): inferred from family pattern (PRNG-seeded sleep gates and runtime C2 decoding evade time-shifted sandboxes). No explicit anti-VM strings in this sample.

Discovery — T1083 (File and Directory Discovery): inferred from family targeting of browser profiles, wallet files, and credential stores. ^[entities/acrstealer.md]

Collection —

  • T1555 (Credentials from Password Stores): browser credential theft (family pattern). ^[entities/acrstealer.md]
  • T1555.003 (Credentials from Web Browsers): family-wide capability. ^[entities/acrstealer.md]
  • T1113 (Screen Capture): inferred from .rsrc icon masquerade and family behavior.
  • T1056.001 (Input Capture — Keylogging): family-wide capability on some siblings; not confirmed for this build.

Command and Control —

  • T1071.001 (Application Layer Protocol — Web Protocols): TLS-wrapped HTTP C2 via Go crypto/tls + net/http (inferred from family pattern and standard library linkage). ^[entities/acrstealer.md]
  • No static C2 observable — fully runtime-resolved (T1568 — Dynamic Resolution). ^[entities/acrstealer.md]

Exfiltration — T1041 (Exfiltration Over C2 Channel): family pattern POSTs collected data to C2 endpoints. ^[entities/acrstealer.md]

Impact — None observed statically; family behavior is credential theft and cryptocurrency wallet draining, not encryption or destruction.

C2 Infrastructure

No static C2 indicators recovered. The sample contains no hardcoded URLs, IPs, domains, or Telegram/Discord tokens in strings. C2 decoding is runtime-resolved via PRNG-seeded string transforms, consistent with the family pattern documented on acrstealer and prng-seeded-c2-url-decoding.

Interesting Tidbits

  • Go 1.20.6 divergence: This sibling uses an older toolchain than the dominant 1.25.4 builds in the cluster, matching only f0105851 (26th sibling). Suggests the builder supports multiple Go versions or the operator is recycling older toolchain VMs. ^[strings.txt:944]
  • GlobalSign DV TLS cert chain: First observed on f0105851 (26th sibling, Go 1.20.6 PE32, 90 randomized functions). This sample shares the identical cert chain but is a lighter build (34 functions, two icons). ^[entities/acrstealer.md]
  • Reduced icon suite: Two icons vs. the five-icon suite common on quiverquant.com/WE1 chain. Builder icon-toggle confirmed. ^[pefile.txt:329–378]
  • Null PE timestamp: Consistent with -trimpath=true Go builds; not a deliberate anti-forensic measure but useful for clustering. ^[pefile.txt:34]
  • No custom PE parser / no multi-pass decoder: Light baseline build. No code-reuse overlap with the orderreshop / lummastealer fork that added those features. ^[entities/acrstealer.md]

How To Mess With It (Homelab Replication)

Toolchain:

  • Go 1.20.6 (or any 1.18+ release)
  • Target: GOOS=windows GOARCH=386 CGO_ENABLED=0
  • Flags: -trimpath=true -ldflags="-s -w"

Working source snippet:

package main

import (
    "crypto/rand"
    "fmt"
    "math/big"
    "os"
    "time"
)

func main() {
    // PRNG-seeded C2 decoder simulation
    seed := time.Now().Unix()
    fmt.Printf("seed=%d\n", seed)
    // Randomized function names are compile-time only;
    // rename symbols with a post-processing script or Go build tags.
    os.Exit(0)
}

Verification: Build the reproducer, run strings and confirm go1.20.6, -trimpath=true, and randomized main.* symbols if you used a renaming script. Compare entropy (~6.0–6.2 in .text) and null PE timestamp to this sample.

What you'll learn: How Go static binaries strip timestamps, how -trimpath removes source paths, and how trivial it is to generate randomized symbol names that poison string-based clustering.

Deployable Signatures

YARA Rule

rule ACRStealer_Go1206_GlobalSign_SeekingAlpha
{
    meta:
        description = "ACR Stealer Go 1.20.6 sibling with GlobalSign DV TLS cert CN=seekingalpha.com"
        author = "PacketPursuit"
        date = "2026-08-16"
        sha256 = "a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992"
        family = "acrstealer"
    strings:
        $go_build = "go1.20.6"
        $trimpath = "build\t-trimpath=true"
        $cgo = "build\tCGO_ENABLED=0"
        $goarch = "build\tGOARCH=386"
        $mod1 = "path\tXXjuhfDdZFXrSHR"
        $mod2 = "mod\tXXjuhfDdZFXrSHR\t(devel)"
        $main1 = "main.dfmqjjppyfnrvuj"
        $main2 = "main.gkjiotaekzcz"
        $main3 = "main.mnadgmqvxxzfhf"
        $main4 = "main.jsytyw"
        $seekingalpha = "seekingalpha.com" ascii wide
        $globalsign = "GlobalSign Atlas R3 DV TLS CA 2025 Q4" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        ($go_build and $trimpath and $cgo and $goarch) and
        (2 of ($main*)) and
        any of ($mod*) and
        any of ($seekingalpha, $globalsign)
}

IOC List

Indicator Type Value Notes
SHA-256 hash a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992 Primary artifact
SHA-1 hash acb614eccf5d41ad3ac06904b7f2418a602441fb .text section
SSDeep hash 49152:aZ3JTQxZ6fIWrUdDcFIPiWr1HxW5d728DqYK1t:aZ3tQCZ+hga8g ^[triage.json:14]
Filename string CuService.exe Service masquerade
Certificate CN x509 seekingalpha.com GlobalSign DV TLS
Cert SHA-256 x509 0D:15:42:B8:AD:6F:4F:7F:F2:01:66:8D:32:15:59:69:BF:67:F3:A8:2E:18:39:1D:0E:87:1F:9F:1C:BE:6B:92 Valid 2025-12-09 → 2027-01-10
Go module string XXjuhfDdZFXrSHR Randomized module path
Go build ID string TYvBSq1zXdkPdC2asRVH/jFfxwOLNH58_3uMOU7VR/ng--kXfOyb90XvJK_CXy/a9auVj9wjw2z2Gb4TyOr Unique per build

Behavioral Fingerprint

This binary is a Go 1.20.6 static PE32 with null PE timestamp, 34 randomized main.* function names, and a valid GlobalSign DV TLS certificate. At runtime it decodes C2 strings via PRNG-seeded transforms (no static network indicators), then communicates over TLS/HTTPS to exfiltrate browser credentials and cryptocurrency wallet data. The .rsrc section contains exactly two PNG icons used for social-engineering masquerade. No custom in-memory PE parser or multi-pass byte-transform decoder is present in this light baseline build.

Detection Signatures

No capa output available (signature database missing on this host). Based on static surface:

  • Go static binary with GOARCH=386 and null timestamp
  • main.* symbol table flooded with randomized alphanumeric names
  • Valid but suspicious DV TLS code-signing cert on a binary named CuService.exe
  • No static C2, no obvious payload resource, no AMSI bypass imports

References

Provenance

Analysis performed 2026-08-16 on pp-hermes (Lab1BU). Tools: pefile 2023.x, ExifTool 12.76, strings, grep, radare2 (rabin2), openssl, binwalk, Python 3.x. CAPE sandbox skipped — no Windows guest available. Static-only inference is explicitly marked where dynamic evidence is absent. All claims carry ^[file:line] or ^[tool] provenance markers.