Malware · 58 days ago
ACR Stealer now breaks the old cleanup playbook. A single pasted Run command can hand an attacker browser tokens and synced Microsoft 365 data, so changing passwords does not end the compromise if those sessions stay valid.
Microsoft says activity rose across customer environments from late April to mid-June. It documented two delivery chains that use ClickFix lures, JPEG steganography, and WebDAV to steal browser credentials, authentication tokens, PDFs, and files from synced OneDrive and SharePoint folders.
The steal works because the malware rides the browser’s own saved sessions and the logged-in device’s sync access. That makes revoked passwords only part of the fix; the stolen tokens are the real persistence point.
3 sources covering this story
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer campaigns use ClickFix lures, JPEG steganography, and WebDAV to steal browser tokens, passwords, PDFs, and synced Microsoft 365 files.
ACR Stealer: Two observed intrusion chains amid increased threat activity | Microsoft Security Blog
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments.
Part of the PlainSec briefing for 2026-07-19