typeanalysisfamilyacrstealerconfidencehighcreated2026-08-16updated2026-08-16infostealergolangsigningobfuscationmalware-familymitre-attck
SHA-256: b39688635bb5b2a90bb9101b372080b61d6ba78f2cd78ee275a983a84e2a047d

acrstealer: b3968863 — cloud55filecc mislabel, Go 1.25.4 x64, 65 randomized main.* functions

Executive Summary

Go 1.25.4 PE32+ x64 infostealer, preliminary OpenCTI label cloud55filecc. Certificate chain (quiverquant.com/WE1), Go build fingerprint, and module-path randomization resolve it to the acrstealer cluster as the 41st confirmed sibling (16th on the quiverquant.com/WE1 cert chain). .rsrc five-icon suite is intact. No static C2, no custom PE parser, no multi-pass decoder — a light baseline build. Static-only (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 b39688635bb5b2a90bb9101b372080b61d6ba78f2cd78ee275a983a84e2a047d
Filename kythy.exe ^[triage.json]
Size 4,382,848 bytes (4.2 MB) ^[triage.json]
Type PE32+ executable (GUI) x86-64, 9 sections ^[file.txt]
Compiler Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt]
Build ID VNlBa05664SdWirgM_Nb/aaZg3rSxjkxXTzsPr5lU/ZIEYYxvROiXbJ7sEHv6I/4X_RMt9S-RlpJOS0Oc_0 ^[strings.txt]
Module path kDIdfdDYIETHOsK ^[strings.txt]
Entry point 0x72640 (ImageBase 0x140000000) ^[pefile.txt]
Timestamp 0x0 (null, stripped) ^[pefile.txt]
Subsystem Windows GUI ^[rabin2-info.txt]
ASLR / NX Enabled (DYNAMIC_BASE, HIGH_ENTROPY_VA, NX_COMPAT) ^[pefile.txt]

Build / RE

Toolchain. Standard Go 1.25.4 gc compiler for amd64 Windows. No CGO. -trimpath=true strips absolute source paths. Null PE timestamp — a cluster-wide trait. ^[strings.txt] ^[pefile.txt]

Signing. Authenticode self-signed certificate embedded at offset 0x42D808 (DER, PKCS#7). Subject CN=quiverquant.com, issuer CN=WE1, validity 2026-05-09 through 2026-08-07. 4096-bit RSA, SHA-256 signature. ^[openssl cert parse from raw binary]

Obfuscation. 65 randomized main.* function names (e.g. main.moowihnjzjmwuj, main.dlgycujlbuhhn, main.yybouhcfexaqzoi) — mid-range count for the cluster. No external packer; .text entropy ~6.26. ^[strings.txt] ^[pefile.txt]

Resources. .rsrc section contains five PNG icons (16×16, 32×32, 64×64, 128×128, 256×256 RGBA) — social-engineering masquerade intact. ^[binwalk.txt]

Anti-analysis. None observed statically beyond the Go runtime's natural symbol obfuscation and runtime C2 decoding (family pattern, see prng-seeded-c2-url-decoding). No anti-VM, no anti-debug, no sandbox gates. Light build.

Notable functions. main.main at 0x14009ad60 (per radare2 symbol recovery). Standard Go runtime init → main.main → goroutine spawn. No custom PE parser or multi-pass decoder present (unlike heavier ACR siblings such as d5655568 or 90d54589). ^[r2:sym.main.main]

How It Works

This is a cluster sibling of acrstealer; shared behaviour (browser credential theft, crypto wallet targeting, TLS C2 exfil) is documented on the family page. Per-sample deltas:

  • Module path kDIdfdDYIETHOsK — unique to this build.
  • 65 randomized main.* symbols — mid-range count (cluster spans 11–92). ^[strings.txt]
  • .rsrc icons intact — builder icon-toggle is ON. Contrast with siblings c69b14a0, cdd16fc0, 94cf86f6 which strip .rsrc. ^[binwalk.txt]
  • No custom PE parser / no multi-pass decoder — lightest-tier ACR build; relies on standard Go library API resolution. ^[strings.txt]
  • No static C2 — C2 endpoints are runtime-decoded via PRNG-seeded transform (see prng-seeded-c2-url-decoding). ^[strings.txt (absence of URLs)]

OpenCTI label cloud55filecc is contested. This label appears on 23 samples in the corpus; many (including 642ecaab, 8bb023f2, c88a5bba) share Go infostealer build fingerprints and resolve to the ACR/Lumma/OrderRe cluster. The cloud55filecc label is an opaque umbrella without independent technical fingerprint. This sample should be tracked under acrstealer.

Decompiled Behavior

Ghidra was not run for this sample (static analysis relied on radare2 + strings). Radare2 recovered 2,138 functions including standard Go runtime symbols and 65 main.* user functions. main.main sits at 0x14009ad60 and branches into multiple goroutines. No decompiled pseudo-C available beyond r2's function list. ^[r2:function list]

C2 Infrastructure

No hardcoded IPs, domains, or URLs recovered statically. C2 is runtime-resolved via PRNG-seeded string decoding (family-wide technique). Network capability is inferred from statically-linked net/http, crypto/tls, and crypto/x509 packages. ^[strings.txt]

Interesting Tidbits

  • The quiverquant.com/WE1 cert chain is now the most prolific in the ACR cluster with 16 confirmed samples (including this one), surpassing the atom.hutsell.com/WR3 chain (15 samples) and the me.muz.li/R13 chain (4 samples). ^[entities/acrstealer.md]
  • This cert's validity window is unusually short (~90 days), consistent with rapid rotation observed across the cluster.
  • The sample filename kythy.exe has no semantic value — likely a random builder output name.
  • The .symtab section is present and non-empty (0x1B0F4 bytes), which is unusual for malware but standard for unstripped Go binaries. It provides free symbol recovery.

How To Mess With It (Homelab Replication)

To reproduce a comparable static fingerprint:

  1. Install Go 1.25.4 on Windows or cross-compile from Linux:
    GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe .
    
  2. Use a self-signed Authenticode certificate with CN matching a legitimate-sounding domain.
  3. Randomize all exported function names in the main package (10–90 functions, 8–16 character mixed-case names).
  4. Embed 5 PNG icons in .rsrc (16×16 through 256×256).
  5. Implement PRNG-seeded C2 URL decoding to ensure static extraction yields nothing.
  6. Verify with capa and strings — should match the ACR cluster fingerprint: no static C2, heavy runtime.* strings, randomized main.* names, null PE timestamp.

What you'll learn: How trivial it is for a Go builder to evade static string-based detection while retaining full infostealer capability via standard libraries.

Deployable Signatures

YARA Rule

rule ACR_Stealer_QuivQuant_We1_Chain {
    meta:
        description = "ACR Stealer variant with self-signed quiverquant.com/WE1 certificate"
        author = "PacketPursuit"
        date = "2026-08-16"
        hash = "b39688635bb5b2a90bb9101b372080b61d6ba78f2cd78ee275a983a84e2a047d"
        reference = "https://raw.githubusercontent.com/packetpursuit/wiki/main/entities/acrstealer.md"
    strings:
        $go_build = "go1.25.4" ascii
        $go_build_id = "Go build ID:" ascii
        $mod_path = "path\tkDIdfdDYIETHOsK" ascii
        $cert_cn = "quiverquant.com" ascii
        $we1 = "WE1" ascii
        $main_prefix = "main." ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize < 6MB and
        $go_build and
        $go_build_id and
        $cert_cn and
        $we1 and
        #main_prefix > 50
}

Behavioral Hunt Query (KQL)

DeviceFileEvents
| where FileName endswith ".exe"
| where FileSize < 6MB
| where (InitiatingProcessCommandLine contains "kythy" or FileName == "kythy.exe")
| union (
    DeviceProcessEvents
    | where ProcessCommandLine contains "kythy.exe"
    | where AccountName != "SYSTEM"
)
| union (
    DeviceNetworkEvents
    | where RemoteUrl contains "quiverquant.com"
    | where InitiatingProcessFileName endswith ".exe"
)

IOC List

Indicator Type Notes
b39688635bb5b2a90bb9101b372080b61d6ba78f2cd78ee275a983a84e2a047d SHA-256 This sample
kythy.exe Filename Random builder output
CN=quiverquant.com, issuer=WE1 Certificate Self-signed, 4096-bit RSA
kDIdfdDYIETHOsK Module path Unique to this build
2026-05-09 → 2026-08-07 Cert validity 90-day rotation window

Behavioral Fingerprint

This binary is a Go 1.25.4 x64 static executable (no CGO, -trimpath) with a null PE timestamp and a self-signed Authenticode certificate (CN quiverquant.com, issuer WE1). It contains 50–70 randomized main.* functions, a populated .rsrc section with five PNG icons, and no hardcoded C2 strings. Upon execution, it spawns multiple goroutines and contacts a TLS-encrypted C2 endpoint decoded at runtime via a PRNG-seeded transform. Network traffic originates from the Go standard net/http and crypto/tls stacks. Static string extraction yields only runtime error messages and standard library symbols.

Detection Signatures

No capa output available for this sample (capa signatures missing on host). Based on cluster analysis, expected ATT&CK mappings:

  • T1071.001 — Application Layer Protocol: Web Protocols (HTTPS C2)
  • T1083 — File and Directory Discovery (browser profile enumeration)
  • T1005 — Data from Local System (credential stores)
  • T1041 — Exfiltration Over C2 Channel
  • T1078.003 — Valid Accounts: Local Accounts (masquerade via self-signed cert)
  • T1027.002 — Obfuscated Files or Information: Software Packing (Go static binary obfuscation)
  • T1059.003 — Command and Scripting Interpreter: Windows Command Shell (indirect, via goroutine spawn)

Static-only inference; runtime TTPs would require CAPE detonation.

References

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile Python library header dump
  • rabin2-info.txt — radare2 rabin2 -I header summary
  • strings.txt — strings -n 8 output (7,977 lines)
  • binwalk.txt — binwalk embedded-artefact scan
  • exiftool.json — ExifTool PE metadata
  • triage.json — triage pipeline metadata
  • OpenSSL x509 — manual certificate extraction from IMAGE_DIRECTORY_ENTRY_SECURITY
  • radare2 — aa analysis, aang Go symbol recovery, 2,138 functions recovered

Report authored: 2026-08-16 by Demetrian Titus (pp-hermes).