logo

ACR Stealer: Two observed intrusion chains amid increased threat activity

ID: 0c8cd850-98c8-56e2-a0e5-f47d4912c29e

STIX ID: report--0c8cd850-98c8-56e2-a0e5-f47d4912c29e

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

Author: Microsoft Security Research and Balaji Venkatesh S

...
...

Microsoft Defender Experts observed increased ACR Stealer activity using ClickFix lures from April to June 2026; two prevalent campaigns were analyzed — a WebDAV-delivered chain with staged PowerShell and Python loaders (including a blockchain-backed dead-drop C2) and a fileless MSHTA/PowerShell chain using steganography for in-memory execution — both focused on stealing browser credentials, authentication tokens, and sensitive enterprise documents, with IOCs, MITRE mappings, hunting queries, and mitigation recommendations provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.