logo

ACR Stealer Uses ClickFix, WebDAV, and Steganography to Steal Browser Credentials and Tokens

ID: 3178cdd9-91f7-56f9-96c7-d9caf3bc4513

STIX ID: report--3178cdd9-91f7-56f9-96c7-d9caf3bc4513

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-17

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

A surge in ACR Stealer activity (late April–mid June 2026) details two intrusion chains: one delivered via malvertising/SEO-poisoning that uses WebDAV-hosted DLLs (invoked via rundll32/pushd/conhost --headless) to drop an obfuscated Python runtime that reconstructs and executes shellcode in memory, and a second fileless chain using mshta→HTA→VBScript→PowerShell which extracts and executes payloads hidden in JPEGs. Both campaigns target Chromium browser databases and DPAPI-protected secrets, establish persistence with hidden scheduled tasks, minimize disk artifacts via in-memory execution and Fiber/VirtualAlloc techniques, and exfiltrate archived credentials and business documents; the report lists multiple C2 and hosting domains as IOCs and recommends monitoring for ClickFix prompts, WebDAV access, mshta activity, obfuscated PowerShell, unusual scheduled tasks, and browser-database access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.