Microsoft Defender Experts have identified a surge in ACR Stealer malware campaigns using ClickFix social engineering to compromise enterprise browser credentials, authentication tokens, and sensitive corporate data.
Key Points
- ACR Stealer, a malware-as-a-service family formerly known as Amatera Stealer, targets enterprise environments to exfiltrate browser-stored credentials and sensitive documents.
- Attackers utilize ClickFix lures via malvertising or SEO-manipulated search results to trick users into executing malicious commands.
- One campaign variant employs WebDAV-delivered payloads and blockchain-backed dead-drop command-and-control resolution to evade traditional detection.
- A second campaign utilizes fileless, in-memory execution through MSHTA and steganography, hiding malicious payloads within image pixels.
- Microsoft Defender for Endpoint provides behavioral coverage for these techniques, including suspicious WebDAV activity, obfuscated PowerShell execution, and unauthorized browser credential access.