Microsoft warns of surge in ACR Stealer attacks on customers
ID: 220ee02d-dad3-52db-9244-3757d18b101c
STIX ID: report--220ee02d-dad3-52db-9244-3757d18b101c
Feed Name: Bleeping Computer
Microsoft observed a surge in ACR Stealer (an Amatera Stealer rebrand) attacks against enterprise customers between late April and mid‑June, delivered primarily via ClickFix social engineering using WebDAV-hosted DLLs with rundll32.exe and MSHTA-based PowerShell downloaders that extract steganographic payloads; the malware steals browser credentials, tokens, documents (including OneDrive/SharePoint synchronized files), and exfiltrates collected data, while using obfuscation, scheduled tasks, in-memory execution, and blockchain-based dead-drop resolvers for C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
