bleeping-computer · Crawled Jul 18, 2026

Microsoft warns of surge in ACR Stealer attacks on customers

1 IoCs 1 Malware
Read original article ↗

AI Summary

Microsoft has observed a significant increase in ACR Stealer malware attacks targeting enterprise customers. The malware is delivered via social engineering using the ClickFix lure, WebDAV servers, and MSHTA to execute malicious payloads. ACR Stealer steals browser passwords, authentication tokens, and sensitive documents, leveraging obfuscated PowerShell scripts, in-memory execution, and steganographic images. Some variants use blockchain services as dead-drop resolvers for C2 communication.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Domain google[.]ct Details →

MITRE ATT&CK TTPs 14 techniques