The record
Written from the 1 report below. Nothing here is unsourced.
- Microsoft reports that ACR Stealer, an infostealer circulating since 2024, is increasingly targeting enterprise networks through ClickFix social engineering lures that trick users into pasting commands into a Run box.
- The malware steals saved browser passwords, session tokens, PDFs, and Microsoft 365 and OneDrive documents, with some variants using stealthy techniques like hiding payloads in JPEG images or pulling commands from blockchain ledgers.
- The intrusions exploit no software vulnerability, so patching alone cannot stop them; Microsoft advises revoking tokens, not just rotating passwords.
- Neither Microsoft nor researchers have attributed the activity to a specific threat actor, and Microsoft has not quantified the scale of infections.
What to watch next
- Whether Microsoft or researchers quantify the number of victims or affected customers.
- Further documentation of the EtherHiding technique using blockchain infrastructure for payload delivery.
- Attribution of the campaigns to a specific threat actor behind ACR Stealer.
Coverage1
1 report
English national1
All filed from India
Named United States · Russia
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
