AUTO-UPDATED

ACR Stealer: Two observed intrusion chains amid increased threat activity

Microsoft Defender Experts have identified a surge in ACR Stealer malware campaigns using ClickFix social engineering to compromise enterprise browser credentials, authentication tokens, and sensitive corporate data.

Key Points

  • ACR Stealer, a malware-as-a-service family formerly known as Amatera Stealer, targets enterprise environments to exfiltrate browser-stored credentials and sensitive documents.
  • Attackers utilize ClickFix lures via malvertising or SEO-manipulated search results to trick users into executing malicious commands.
  • One campaign variant employs WebDAV-delivered payloads and blockchain-backed dead-drop command-and-control resolution to evade traditional detection.
  • A second campaign utilizes fileless, in-memory execution through MSHTA and steganography, hiding malicious payloads within image pixels.
  • Microsoft Defender for Endpoint provides behavioral coverage for these techniques, including suspicious WebDAV activity, obfuscated PowerShell execution, and unauthorized browser credential access.

Why it Matters

These campaigns demonstrate how sophisticated information-stealing malware can bypass traditional security by blending into legitimate network traffic and utilizing fileless execution methods. Organizations face significant risks of account takeover and unauthorized access to cloud resources, necessitating proactive monitoring of script-based execution and browser credential stores.
Microsoft.com Published by Microsoft Security Research and Balaji Venkatesh S
Read original