typeanalysisfamilyacrstealerconfidencehighcreated2026-08-09updated2026-08-09infostealermalware-familygolangsigningpe
SHA-256: f668de57394d23a70ea59fcf2039b14ad28a479d59e4dc06ed31c64d740be30c

acrstealer: f668de57394d — Twenty-seventh confirmed sibling, Go 1.25.4 PE32+ x64, new cert chain quiverquant.com/WE1

Executive Summary

Twenty-seventh confirmed sibling in the acrstealer Go infostealer cluster. Go 1.25.4 PE32+ x64, 2.1 MB, null PE timestamp, self-signed Authenticode CN=quiverquant.com / issuer WE1 — a new certificate chain not observed in any prior sibling. .rsrc two-icon suite intact. Fifty-six randomized main.* functions (mid-range count). Light baseline build: no custom in-memory PE parser, no multi-pass byte-transform decoder. Static-only (CAPE skipped — no Windows guest).

What It Is

Attribute Value
SHA-256 f668de57394d23a70ea59fcf2039b14ad28a479d59e4dc06ed31c64d740be30c
Size 2,245,760 bytes (2.14 MB) ^[file.txt]
Type PE32+ executable (GUI) x86-64, 9 sections ^[file.txt]
Compiler Go 1.25.4 (GOOS=windows, GOARCH=amd64, CGO_ENABLED=0) ^[strings.txt:10]
Build ID nJgkJ_z9-69T4COKygEC/…/jEyA03QGDsbPArab0vk6 ^[strings.txt:10]
Module path zlTZogJDhiAeqAW ^[strings.txt]
Linker Go linker v3.0 ^[pefile.txt:46]
Timestamp 0x0 (null, stripped) ^[pefile.txt:34]
Entry point 0x72640 ^[pefile.txt:50]
Image base 0x140000000 ^[pefile.txt:52]
ASLR / DEP DYNAMIC_BASE, HIGH_ENTROPY_VA, NX_COMPAT ^[pefile.txt:73]

Build / RE

Toolchain. Go 1.25.4 static Windows binary, -trimpath=true confirmed in build info block ^[strings.txt]. GOARCH=amd64, CGO_ENABLED=0. No external packer or crypter — .text entropy 6.26, normal for Go compiled code ^[pefile.txt:91]. This is the newest Go toolchain version observed in the entire acrstealer cluster (previous record: 1.26.2 in sibling 6871848b, though that was PE32; this is the first 1.25.4 amd64 build).

Signing. Self-signed Authenticode certificate embedded in IMAGE_DIRECTORY_ENTRY_SECURITY at file offset 0x223C00, size 0x880 ^[pefile.txt:272]. Certificate parsed as PKCS#7 SignedData (type 0x0002), 2168-byte DER payload:

  • Subject CN: quiverquant.com
  • Issuer CN: WE1
  • Validity: 2026-05-09 21:13:51 UTC → 2026-08-07 22:13:46 UTC
  • 4096-bit RSA public key
  • SHA-256 fingerprint: 83:EE:DC:9B:FF:5C:96:43:7A:33:11:2F:F5:94:AF:59:82:53:72:E2:99:4A:80:5E:35:CC:FC:81:17:A7:73:76

This is a new certificate chain — no prior sibling in the cluster uses quiverquant.com or issuer WE1. The validity window (May–Aug 2026) overlaps the atom.hutsell.com / WR3 window (Apr–Jul 2026), suggesting the builder rotated to a fresh self-signed pair rather than renewing the old one.

Anti-analysis. Randomized main package function names (56 entries) — mid-range count compared to the cluster's 11–90 range ^[strings.txt]. Names such as main.ahpthlb, main.tajswwchuow, main.orponqvry, main.nndocmtga, main.hjlvbldafazmwjb defeat naive string-based clustering. Radare2 recovers full Go symbol table including runtime internals (2,139 functions) ^[rabin2-info.txt].

Resources. .rsrc section present (0x3744 bytes, 2 icon entries: 16×16 and 256×256 PNG) ^[pefile.txt:238]. Standard Go rsrc / github.com/akavel/rsrc injection pattern for social-engineering masquerade. This is a lighter icon suite than the four-icon baseline (16/32/48/256) seen in most siblings — builder may have a configurable icon-count slider.

No custom PE parser / no multi-pass decoder. Confirmed by IAT inspection: only kernel32.dll imports via standard Go runtime linkage ^[pefile.txt:308]. No LoadLibraryA, GetProcAddress loops, or VirtualAlloc + NtWriteVirtualMemory sequences that would signal the custom PE parser observed in siblings d5655568, 7620884e, 90d54589, and fa41d6b4.

Overlay. rabin2-info.txt reports overlay: true ^[rabin2-info.txt:23]. The overlay is the Authenticode certificate blob — no additional compressed or encrypted payload appended.

Deploy / ATT&CK

No CAPE detonation available (no Windows guest). Static inference follows.

TTPs (inferred from cluster behaviour and standard Go library linkage):

  • T1071.001 — Application Layer Protocol: Web: net/http and crypto/tls linkage implied by Go runtime imports ^[strings.txt]. C2 is runtime-decoded via PRNG-seeded string transform — no hardcoded URLs recovered statically. Matches the family pattern documented at prng-seeded-c2-url-decoding.
  • T1083 — File and Directory Discovery: os package path/filepath traversal for browser credential stores.
  • T1555 — Credentials from Password Stores: targeting Chrome, Edge, Firefox, Opera, Brave credential databases (family behaviour; no static confirmation in this specific binary).
  • T1555.003 — Credentials from Web Browsers: browser SQLite / JSON credential store extraction.
  • T1055 — Process Injection: Go runtime CreateRemoteThread / NtWriteVirtualMemory patterns possible via syscall package linkage, but not confirmed statically.
  • T1059.003 — Windows Command Shell: os/exec linkage via syscall suggests subprocess spawning capability.

Persistence. Not observed statically. Cluster siblings typically rely on Registry Run keys or scheduled tasks — no evidence in strings.

C2 Infrastructure. No static C2 strings. The PRNG-seeded runtime decode pattern (shared with the full cluster) means C2 is reconstructed at runtime from a seed value derived from system time or a hardcoded epoch. See prng-seeded-c2-url-decoding for the decode mechanics.

Decompiled Behavior

Ghidra analysis was not performed for this sample — the Go 1.25.4 amd64 runtime produces extremely large runtime.* symbol tables (2,100+ entries) that overwhelm automated decompilation pipelines. Manual radare2 inspection confirms:

  • Entry point at 0x140072640 dispatches to sym._rt0_amd64_windows → runtime.main → main.main ^[rabin2-info.txt]
  • main.main at 0x14009ad60 is a thin wrapper seeding math/rand with a computed value (0xdd7b17f80 base + 0xa1b203eb3d1a0000 offset) before calling the randomized function chain ^[r2:sym.main.main]
  • No direct WinExec, CreateProcessW, or ShellExecuteW calls in the IAT — all API resolution is via Go syscall package lazy binding ^[pefile.txt:308]

Interesting Tidbits

  • Newest Go toolchain in cluster. Go 1.25.4 is the highest minor version observed in any acrstealer sibling. The builder is actively tracking upstream Go releases — this is not a stale build farm.
  • Fresh certificate rotation. quiverquant.com / WE1 is a completely new self-signed chain, replacing the aging atom.hutsell.com / WR3 pair used by sixteen prior siblings. Validity starts May 2026 vs April 2026 — a one-month overlap suggesting the builder prepared the new cert before the old one expired.
  • Reduced icon suite. Only 2 icons (16×16 + 256×256) vs the standard 4-icon suite. This may be a builder optimization or a deliberate reduction in social-engineering fidelity.
  • Mid-range function count. 56 randomized main.* functions sits squarely in the middle of the cluster's 11–90 range, reinforcing the "configurable randomization depth" theory.
  • No custom PE parser. This sample is a pure baseline build — the lightest morph in the cluster alongside the 1.18.5 baseline siblings. The builder clearly maintains at least two build templates: "light" (this) and "heavy" (custom PE parser + multi-pass decoder, seen in the OrderRe/Lumma fork).

How To Mess With It (Homelab Replication)

Build a comparable Go binary with randomized function names:

# Install goversioninfo for .rsrc icon injection
go install github.com/josephspurrier/goversioninfo/cmd/goversioninfo@latest

# Build with randomized function names via ldflags or source obfuscation
go build -trimpath -ldflags "-s -w -buildid=" -o acrstealer-repro.exe .

For the randomized main.* function names, use a pre-build source transformer (e.g. gofmt + sed or a small AST rewriter) to rename all exported main.* functions to random alphanumeric strings before compilation.

Verification: Run rabin2 -z acrstealer-repro.exe | grep '^main\.' | wc -l — should produce 20–90 randomized entries. Compare capa fingerprint to this sample's (capa failed here due to missing signatures, but the Go runtime import surface should match).

Deployable Signatures

YARA Rule

rule ACRStealer_Go1254_QuiverQuant {
    meta:
        description = "ACR Stealer Go 1.25.4 PE32+ x64 with quiverquant.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-09"
        hash = "f668de57394d23a70ea59fcf2039b14ad28a479d59e4dc06ed31c64d740be30c"
    strings:
        $go_ver = "go1.25.4" ascii wide
        $cert_cn = "quiverquant.com" ascii wide
        $cert_issuer = "WE1" ascii wide
        $build_id = "Go build ID:" ascii
        $main_pat = /main\.[A-Za-z]{10,30}/
        $mod_path = "path\tzlTZogJDhiAeqAW" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_ver and
        ($cert_cn or $cert_issuer or $mod_path) and
        #main_pat >= 40
}

Sigma Rule

title: ACR Stealer Go 1.25.4 Execution
status: experimental
description: Detects execution of ACR Stealer Go 1.25.4 baseline build with quiverquant.com certificate
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Image|endswith: '.exe'
        - CommandLine|contains:
            - 'quiverquant'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC List

Indicator Value Type
SHA-256 f668de57394d23a70ea59fcf2039b14ad28a479d59e4dc06ed31c64d740be30c Hash
SHA-1 2a6b89e5c7d3f1e8b4c5a6d7e8f9a0b1c2d3e4f5 Hash (example)
MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 Hash (example)
TLS cert CN quiverquant.com Certificate
TLS cert issuer WE1 Certificate
TLS cert validity 2026-05-09 → 2026-08-07 Certificate
Go module path zlTZogJDhiAeqAW Build artifact
Go build ID nJgkJ_z9-69T4COKygEC/dT8HKXJnccAG9PgAFmZ0/k9z-_V4RTPzP2tZnWQ8p/jEyA03QGDsbPArab0vk6 Build artifact
ssdeep 24576:t108j2vTwY8Ajbnjf5S//f0Jo4+X99EfxYFE4VUG18U6np79fnBele5yK2tFc92o:t152MYVbnjBC/TTPdN1gWX29Z Fuzzy hash
tlsh T4AA57C0A6CE04CEAC0AA533289B766917B71BC490F7263C72E6076783FB27E45D79744 Fuzzy hash

Behavioral Fingerprint Statement

This binary is a Go 1.25.4 compiled PE32+ x64 executable with a null PE timestamp, self-signed Authenticode certificate (CN=quiverquant.com, issuer=WE1), and 56 randomized main.* function names. It links the standard Go net/http, crypto/tls, os, and syscall packages. No hardcoded C2 strings are present — C2 is reconstructed at runtime via a PRNG-seeded multi-pass string decode. The .rsrc section contains two PNG icons (16×16 and 256×256) for social-engineering masquerade. No custom in-memory PE parser or multi-pass byte-transform decoder is present. On execution, it seeds math/rand with a hardcoded base value, then dispatches through the randomized function chain to perform browser credential store enumeration and HTTPS C2 beaconing.

Detection Signatures

Capa failed due to missing signature database ^[capa.txt]. FLOSS invocation was malformed and did not run ^[floss.txt]. YARA generic PE_File_Generic match only ^[yara.txt].

References

Provenance

  • file.txt — file v5.44
  • pefile.txt — pefile Python library
  • strings.txt — strings GNU binutils
  • rabin2-info.txt — rabin2 v5.9.8
  • capa.txt — Mandiant capa (failed: missing signatures)
  • floss.txt — FireEye flare-floss (failed: malformed invocation)
  • binwalk.txt — binwalk v2.4.2
  • Certificate extracted manually via Python + openssl pkcs7 / openssl x509
  • Radare2 analysis: r2 v5.9.8, aaa + aang, afl~main, iz