ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ID: e1acd551-d3fb-5a83-98df-3eaef56c6514
STIX ID: report--e1acd551-d3fb-5a83-98df-3eaef56c6514
Feed Name: The Hacker News
Microsoft and other telemetry sources describe active ACR Stealer campaigns (also linked to Amatera/AcridRain variants) that use a paste-and-run Run dialog vector to deploy two main chains — a fileless mshta→PowerShell→JPEG-embedded payload path and a disk-writing WebDAV/rundll32 path — to harvest browser credentials, authentication tokens, PDFs, and synced cloud documents; defenders are advised to revoke tokens, apply application control, block mshta/rundll32 behaviors, hunt for suspicious rundll32 network activity and remove the Run prompt to cut the vector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
