logo

ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains

ID: ddd3eb23-9aac-5595-bc51-36fd3b528e15

STIX ID: report--ddd3eb23-9aac-5595-bc51-36fd3b528e15

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Do Son

...
...

## Executive summary Microsoft Defender Experts observed a rise in ACR Stealer activity from late April to mid‑June 2026: attackers lure victims with ClickFix malvertising or poisoned search results that prompt users to paste commands, then deploy one of two chains (a disk‑based WebDAV/Python/PowerShell chain or a fileless MSHTA/HTA+VBScript chain that extracts a payload from a JPEG) to steal browser credentials, authentication tokens, and sensitive documents for exfiltration; operators use techniques like DPAPI harvesting and EtherHiding for C2 resilience. Recommended defenses include blocking malicious run‑box commands, monitoring rundll32/MSHTA/WebDAV activity, revoking tokens, enabling cloud‑delivered protection, and training users not to paste commands from web prompts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.