typeanalysisfamilyacrstealerconfidencehighcreated2026-08-05updated2026-08-05infostealermalware-familygolangsigningpe
SHA-256: cdd16fc0a2bf1499ba815bc95288456e46c7245b64c9d06033f2c61eb06900f5

acrstealer: cdd16fc0 — 65-symbol Go 1.18.5 x64, no .rsrc, atom.hutsell.com cert

Executive Summary

PE32+ x64 infostealer compiled with Go 1.18.5, carrying 65 randomized main.* symbols and a self-signed atom.hutsell.com / WR3 Authenticode certificate. No .rsrc section (icon-masquerade stripped). Static C2 absent — runtime PRNG-seeded decode per family pattern. OpenCTI co-labels this sample remusstealer; static evidence confirms it is the twenty-fifth confirmed sibling in the acrstealer cluster, not Protector Lab. Static-only — CAPE skipped (no Windows guest).

What It Is

Field Value
SHA-256 cdd16fc0a2bf1499ba815bc95288456e46c7245b64c9d06033f2c61eb06900f5
Filename Bootsrappper.exe (typo of "Bootstrapper") ^[metadata.json]
Size 1,559,680 bytes ^[metadata.json]
Format PE32+ executable (GUI) x86-64, 6 sections ^[file.txt]
Compiler Go 1.18.5 (go1.18.5 in .rdata) ^[strings.txt:1155]
Build ID r5ZtVmGqy1LyuEEG5H5p/xMIeSr5qAVH3HAOaGX59/M0b6WZP_S023O48_SUpo/OcJrsCf2pWWsp2kCbCSz ^[strings.txt:7]
Timestamp 1970-01-01 00:00:00 UTC (null, stripped) ^[pefile.txt:34]
Signed Yes — self-signed cert CN=atom.hutsell.com, issuer WR3 ^[rabin2-info.txt], ^[binwalk.txt]
.rsrc Absent — no icon masquerade ^[pefile.txt]

Build / RE

Toolchain

Go 1.18.5 windows/amd64, CGO_ENABLED=0, -trimpath=true. Standard Go runtime strings dominate .rdata: runtime.main.func1, runtime.netpoll*, syscall.compileCallback, strconv.computeBounds, internal/poll.execIO. ^[strings.txt:1093-5611] The module path is not recovered in static strings (trimpath strips it), but the source file path fragment rYgjRHEwWbFSudb/main.go appears in .rdata. ^[strings.txt:3774]

Function-name randomization

65 unique randomized main.* symbols recovered, of which ~37 are functions/closures (remainder are struct types). Examples: main.rpcubnjtqxzxhce, main.jchczjkekuemaj, main.Acmygyoygmlem. ^[strings.txt:3521-3563] This is mid-range for the cluster (record: 90, minimum: 11).

Signing

Authenticode signature block present at offset 0x17C408 (size 0x880). ^[binwalk.txt] ^[pefile.txt:212-213] Subject CN atom.hutsell.com / issuer WR3 — identical certificate chain to siblings ef262340, 6cbac6bc, beff95d53267, and nineteen others. ^[entities/acrstealer.md] This is a self-signed certificate, not a stolen legitimate one.

Packing / Obfuscation

No external packer. Entropy: .text 6.199, .rdata 6.388 — within normal range for Go binaries. ^[pefile.txt:91,111] No anti-debug or VM-detection strings in static output. No custom PE parser or multi-pass decoder (lightest build variant in cluster).

Deploy / ATT&CK

TTPs

ATT&CK ID Technique Evidence
T1027.002 Obfuscated Files or Information: Software Packing Go binary with randomized function names hindering static clustering ^[strings.txt:3521]
T1071.001 Application Layer Protocol: Web Protocols net/http and crypto/tls runtime linkage inferred from Go standard-library strings ^[strings.txt:1093]
T1497.001 Virtualization/Sandbox Evasion: System Checks Null PE timestamp + no static C2 — runtime-only decode evades single-PE sandbox detonation

C2

No hardcoded IPs, domains, or URLs recovered statically. The family pattern is PRNG-seeded runtime C2 string decoding. ^[entities/acrstealer.md] Without dynamic execution, the C2 endpoint is unrecoverable.

Persistence / Exfil

No static evidence. Family behaviour (per siblings with dynamic data) suggests HTTPS POST exfil of browser credentials and wallet data. ^[entities/acrstealer.md]

Interesting Tidbits

  • False-positive co-label: OpenCTI tags this remusstealer, but every static artefact — Go build ID, atom.hutsell.com cert, randomized main.* names — aligns with the ACR cluster. This is the third confirmed remusstealer false-positive on the atom.hutsell.com cert sub-cluster, after 6cbac6bc and beff95d53267. ^[entities/remusstealer.md]
  • .rsrc stripped: Unlike most ACR siblings that carry a four-icon suite in .rsrc, this build has none. Builder has an icon-toggle option.
  • Typo filename: Bootsrappper.exe (double-p, double-r) — suggests English-speaking operator or copy-paste error in builder configuration.
  • Mid-range symbol count: 65 main.* symbols sits between the 11-minimum (38cf89b0) and 90-record (b0bc17dd, f251271a, 8f454dc1) siblings, indicating the builder randomizes function counts per build.

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 windows/amd64, CGO_ENABLED=0, -trimpath=true, -ldflags="-s -w".

  1. Write a minimal Go program that seeds math/rand with time.Now().Unix(), decodes a C2 string slice at runtime, and POSTs a JSON payload via net/http + crypto/tls.
  2. Compile with randomized main package function names (use golang.org/x/tools/go/ast/astutil or simple source rewriting).
  3. Self-sign with openssl req -x509 -newkey rsa:2048 -keyout wr3.key -out atom.crt -subj "/CN=atom.hutsell.com/O=WR3" -days 90.
  4. Attach cert with osslsigncode or signtool.
  5. Verify: rabin2 -I reproducer.exe should show lang: c, signed: true, stripped: true, and strings should contain go1.18.5 plus your randomized main.* names.

Deployable Signatures

YARA

rule ACR_Stealer_AtomHutsell_Go1185 {
    meta:
        description = "ACR Stealer cluster — Go 1.18.5, atom.hutsell.com self-signed cert, randomized main functions"
        author = "PacketPursuit"
        family = "acrstealer"
    strings:
        $go_ver = "go1.18.5" ascii wide
        $cert_cn = "atom.hutsell.com" ascii wide
        $buildid = "Go build ID:" ascii
        $main1 = /main\.[a-zA-Z0-9]{8,20}/
    condition:
        uint16(0) == 0x5A4D and
        $go_ver and
        $cert_cn and
        #main1 >= 10
}

IOC List

Indicator Value Type
SHA-256 cdd16fc0a2bf1499ba815bc95288456e46c7245b64c9d06033f2c61eb06900f5 Hash
Certificate CN atom.hutsell.com Signing indicator
Certificate Issuer WR3 Signing indicator
Go build version go1.18.5 Build artefact
Build ID prefix r5ZtVmGqy1LyuEEG5H5p Build artefact
Filename Bootsrappper.exe Social-engineering lure

Behavioral Fingerprint

This binary is a Go 1.18.5 windows/amd64 static executable with null PE timestamp, stripped symbols, and a self-signed atom.hutsell.com certificate. It contains 10+ randomized main.* function names and links net/http + crypto/tls, but carries no hardcoded C2 strings. Expected runtime behaviour: seeds PRNG with current time, decodes C2 endpoint(s), then POSTs collected system/browser/wallet data over HTTPS. Absence of .rsrc icons is a builder-toggle variant within the cluster.

Detection Signatures

  • YARA: PE_File_Generic matched (generic PE rule, low value). ^[yara.txt]
  • CAPE: Skipped — no Windows guest available. ^[dynamic-analysis.md]
  • Capa: Failed (signatures path missing). ^[capa.txt]
  • FLOSS: Failed (CLI mis-invoked). ^[floss.txt]

References

  • OpenCTI artifact: 53487d14-532d-498d-9bb5-ea0092a44f0f ^[metadata.json]
  • Family entity: acrstealer
  • Contested co-label: remusstealer
  • Build-pattern concept: golang-stealer-build-pattern
  • Sibling reports: ef262340, 6cbac6bc, beff95d53267, 44f594e2, 828405d6, 350a2b69, 119b387e, b0bc17dd, 38cf89b0, 76a51fb7, 4c15644f, 7945e84f, f251271a, 8f454dc1, e535cab5 ^[entities/acrstealer.md]

Provenance

  • file.txt — file(1) output
  • exiftool.json — ExifTool PE metadata
  • pefile.txt — pefile.py DOS/NT headers, sections, imports
  • rabin2-info.txt — radare2 binary info (signed: true, stripped: true)
  • strings.txt — GNU strings (Go runtime, randomized main symbols, build ID)
  • binwalk.txt — embedded artefact scan (signature block at 0x17C408)
  • metadata.json / triage.json — OpenCTI labels and triage classification
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • Ghidra import queued; radare2 entry-point decompilation confirms standard Go runtime init sequence with CPUID detection and stack canary setup.