ACR Stealer: Two observed intrusion chains amid increased threat activity
ID: 0c8cd850-98c8-56e2-a0e5-f47d4912c29e
STIX ID: report--0c8cd850-98c8-56e2-a0e5-f47d4912c29e
Feed Name: Microsoft Security
Date Published: 2026-07-16
Date Updated: 2026-07-17
Author: Microsoft Security Research and Balaji Venkatesh S
Microsoft Defender Experts observed increased ACR Stealer activity using ClickFix lures from April to June 2026; two prevalent campaigns were analyzed — a WebDAV-delivered chain with staged PowerShell and Python loaders (including a blockchain-backed dead-drop C2) and a fileless MSHTA/PowerShell chain using steganography for in-memory execution — both focused on stealing browser credentials, authentication tokens, and sensitive enterprise documents, with IOCs, MITRE mappings, hunting queries, and mitigation recommendations provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
