Security researchers are warning of a new campaign that leverages cracked versions of software to lure users and infect them with the info-stealer malware Lumma and ACR Stealer.

According to AhnLab Security Intelligence Center (ASEC), a sharp increase in the distribution of ACR Stealer has been detected since January 2025. A notable aspect of this malware is its use of a technique called dead drop resolver to extract the actual command and control (C2) server. It relies on legitimate services such as Steam, Telegram’s Telegraph, Google Forms, and Google Slides.
See also: Beware! New malware campaign distributes Skuld info-stealer
“ The threat actors enter the real C2 domain by Base64 encoding it on a specific page ,” ASEC said . “ The malware accesses that page, parses the string, and obtains the real C2 domain address to perform malicious behavior .”
The info-stealer malware ACR Stealer collects a wide range of information from compromised systems: files, browser data , and cryptocurrency wallet extensions.
As for Lumma Stealer, it is another powerful data theft tool. It is sold to hackers who distribute it through various methods. It can collect, among other things, passwords stored in web browsers and session tokens that can be used to compromise accounts.
See also: Fake AI video generator infects Windows and macOS with info-stealer
Protection from info-stealer malware
Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities.

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers (e.g. Lumma Stealer).
See also: WordPress sites hacked: Fake plugins promote info-stealer malware
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
