Microsoft Warns of Surge in ACR Stealer Attacks Targeting Passwords and Sensitive Data

Views: 83 views

396/69 Monday, July 20, 2026

Microsoft has observed a surge in attacks involving ACR Stealer, a malware strain designed to steal passwords, cookies, session data, authentication tokens, and important documents stored on users’ devices. Microsoft detected the campaign from late April to mid-June 2026 and believes that ACR Stealer is a Malware-as-a-Service (MaaS) offering linked to Amatera Stealer.

Reports indicate that attackers use the ClickFix technique to trick victims into executing malicious commands before downloading and installing the malware through built-in system tools, such as MSHTA, rundll32.exe, and WebDAV servers. The malware then uses obfuscated PowerShell to evade detection and leverages payloads embedded in JPEG image files to execute code in memory. It also runs a Python-based loader, creates scheduled tasks for persistence, removes traces of its activity, and injects payloads into system processes to avoid detection. Some samples use blockchain services to locate command-and-control (C2) servers through a technique known as EtherHiding. The malware can also extract data from browsers, PDF documents, Microsoft 365, and files in synced OneDrive and SharePoint folders before collecting and exfiltrating the information to the attackers.

Microsoft recommends that organizations increase awareness of ClickFix attacks and avoid copying or running commands from untrusted websites or messages, even if they claim to be part of a troubleshooting or verification process. Organizations should also restrict the use of tools such as PowerShell, MSHTA, Python, and rundll32.exe for executing files from external sources, block access to low-reputation or newly registered domains, monitor access to sensitive data, and inspect systems using the indicators of compromise (IOCs) published by Microsoft to help reduce the risk of data theft within the organization.

Source: https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/