Run-Box Lures Steal Cloud Sessions Too

ACR Stealer now breaks the old cleanup playbook. A single pasted Run command can hand an attacker browser tokens and synced Microsoft 365 data, so changing passwords does not end the compromise if those sessions stay valid. Microsoft says activity rose across customer environments from late April to mid-June. It documented two delivery chains that use ClickFix lures, JPEG steganography, and WebDAV to steal browser credentials, authentication tokens, PDFs, and files from synced OneDrive and SharePoint folders. The steal works because the malware rides the browser’s own saved sessions and the logged-in device’s sync access. That makes revoked passwords only part of the fix; the stolen tokens are the real persistence point.

Part of the PlainSec briefing for 2026-07-19

Sources