logo

Microsoft Warns of Surge in ACR Stealer Attacks on Enterprise Customers

ID: 6e61d452-4f2b-5a94-a61a-92dc600270da

STIX ID: report--6e61d452-4f2b-5a94-a61a-92dc600270da

Feed Name: CosmicBytez Labs

Threat Score
72/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

...
...

Microsoft warns of a notable surge in ACR Stealer campaigns targeting enterprises; the MaaS infostealer harvests browser-stored credentials, session tokens, cryptocurrency wallet data, and sensitive files via malvertising, phishing, and trojanized installers, then exfiltrates data to attacker-controlled C2/Telegram and self-deletes. The report highlights enterprise risk (M365/GitHub/cloud tokens enabling lateral movement), monetization on IAB markets or for ransomware follow-on, and recommends mitigations including Credential Guard, conditional access, Defender for Endpoint behavioral rules, enterprise password managers, token monitoring, and blocking known C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.