logo

Microsoft warns of surge in ACR Stealer attacks on customers

ID: 220ee02d-dad3-52db-9244-3757d18b101c

STIX ID: report--220ee02d-dad3-52db-9244-3757d18b101c

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Microsoft observed a surge in ACR Stealer (an Amatera Stealer rebrand) attacks against enterprise customers between late April and mid‑June, delivered primarily via ClickFix social engineering using WebDAV-hosted DLLs with rundll32.exe and MSHTA-based PowerShell downloaders that extract steganographic payloads; the malware steals browser credentials, tokens, documents (including OneDrive/SharePoint synchronized files), and exfiltrates collected data, while using obfuscation, scheduled tasks, in-memory execution, and blockchain-based dead-drop resolvers for C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.