bleeping-computer · Crawled Jul 18, 2026
Microsoft warns of surge in ACR Stealer attacks on customers
1 IoCs 1 Malware
Read original article ↗
AI Summary
Microsoft has observed a significant increase in ACR Stealer malware attacks targeting enterprise customers. The malware is delivered via social engineering using the ClickFix lure, WebDAV servers, and MSHTA to execute malicious payloads. ACR Stealer steals browser passwords, authentication tokens, and sensitive documents, leveraging obfuscated PowerShell scripts, in-memory execution, and steganographic images. Some variants use blockchain services as dead-drop resolvers for C2 communication.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | google[.]ct | Details → |
MITRE ATT&CK TTPs 14 techniques
T1021.002 SMB/Windows Admin Shares · Lateral Movement T1036.005 Match Legitimate Name or Location · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1070.005 Network Share Connection Removal · Defense Evasion T1071.001 Web Protocols · Command And Control T1082 System Information Discovery · Discovery T1085 T1085 T1105 Ingress Tool Transfer · Command And Control T1112 Modify Registry · Defense Evasion T1482 Domain Trust Discovery · Discovery T1485 Data Destruction · Impact