Technology

Data theft as a service: Microsoft warns about ACR stealer campaigns

Microsoft warns of an increased wave of attacks with the ACR Stealer malware. Accordingly, attackers are currently increasingly trying to steal passwords, authentication tokens and confidential documents stored in web browsers.

Two variants of the same malware

The campaigns observed ran between late April and mid-June and relied on sophisticated methods to bypass security mechanisms, shared Microsoft with. The focus of the attacks is a social engineering technique called ClickFix. Users are tricked into carrying out supposed problem solutions or security checks themselves. In the cases analyzed by Microsoft, malware was then reloaded via WebDAV servers or the Windows tool MSHTA. ACR Stealer is considered a so-called malware-as-a-service and is intended to be a further development or renaming of the already known Amatera Stealer malware.

Microsoft describes two particularly frequently observed attack sequences. In the first scenario, clicking on the crafted content results in a malicious program library being loaded from a remote WebDAV server. To make network traffic appear inconspicuous, perpetrators use directory and file names that impersonate legitimate resources. After connecting to the control infrastructure, the malware installs additional components, sets up a scheduled task disguised as a software update and conceals its tracks by, among other things, deleting the PowerShell history. The actual malicious code is then executed directly in the main memory. In a second chain of attacks, perpetrators abuse MSHTA to retrieve malicious content from a server. The encrypted malicious code is hidden in a publicly accessible JPEG image using steganography. Some variants also rely on public blockchain services to obtain updated addresses of their command and control servers, a technique known as EtherHiding.

Data extraction on a large scale

The main aim of the attacks is to steal sensitive company data. This includes saved passwords, cookies, session data and authentication tokens from browsers such as Chrome or Edge. The malware also searches PDF files, Microsoft 365 documents, and content on the desktop, in the Downloads folder, and in synchronized OneDrive or SharePoint directories. The collected data is archived and then transmitted to the attackers. Microsoft emphasizes that the two attack methods described represent only a portion of the techniques actually used. Among other things, the group recommends that companies consistently block unknown or untrustworthy Internet sources, restrict the execution of scripts and programs from external sources and make employees aware not to copy and execute commands from unknown instructions into the Windows command line or PowerShell.

Recent Posts

Top Brands Delivering Quality Cell Lines for Research

High-quality cell lines are fundamental to modern biomedical research. They enable scientists to investigate disease…

5 minutes ago

AI-driven Last Mile Carrier Tracking: What’s Next for 2026 and Beyond

AI is changing delivery operations from a monitoring function into a decision engine. For years,…

3 hours ago

Why Programmable AC Sources Matter in the Era of Bidirectional Energy

Power electronics used to be easier to test because the power environment was relatively predictable.…

3 hours ago

Using Technology to Manage the Financial Side of College Life

Being in college can be very expensive. Not only do you have to pay for…

6 hours ago

Trump is now imposing 100 percent tariffs on drone imports

The US government under Donald Trump is imposing massive tariffs on the import of drones.…

4 days ago

Neagley: New trailer for the Reacher spin-off released

After a first teaser video at the end of July, Amazon Prime Video is now…

4 days ago