Microsoft warns of an increased wave of attacks with the ACR Stealer malware. Accordingly, attackers are currently increasingly trying to steal passwords, authentication tokens and confidential documents stored in web browsers.
The campaigns observed ran between late April and mid-June and relied on sophisticated methods to bypass security mechanisms, shared Microsoft with. The focus of the attacks is a social engineering technique called ClickFix. Users are tricked into carrying out supposed problem solutions or security checks themselves. In the cases analyzed by Microsoft, malware was then reloaded via WebDAV servers or the Windows tool MSHTA. ACR Stealer is considered a so-called malware-as-a-service and is intended to be a further development or renaming of the already known Amatera Stealer malware.
Microsoft describes two particularly frequently observed attack sequences. In the first scenario, clicking on the crafted content results in a malicious program library being loaded from a remote WebDAV server. To make network traffic appear inconspicuous, perpetrators use directory and file names that impersonate legitimate resources. After connecting to the control infrastructure, the malware installs additional components, sets up a scheduled task disguised as a software update and conceals its tracks by, among other things, deleting the PowerShell history. The actual malicious code is then executed directly in the main memory. In a second chain of attacks, perpetrators abuse MSHTA to retrieve malicious content from a server. The encrypted malicious code is hidden in a publicly accessible JPEG image using steganography. Some variants also rely on public blockchain services to obtain updated addresses of their command and control servers, a technique known as EtherHiding.
The main aim of the attacks is to steal sensitive company data. This includes saved passwords, cookies, session data and authentication tokens from browsers such as Chrome or Edge. The malware also searches PDF files, Microsoft 365 documents, and content on the desktop, in the Downloads folder, and in synchronized OneDrive or SharePoint directories. The collected data is archived and then transmitted to the attackers. Microsoft emphasizes that the two attack methods described represent only a portion of the techniques actually used. Among other things, the group recommends that companies consistently block unknown or untrustworthy Internet sources, restrict the execution of scripts and programs from external sources and make employees aware not to copy and execute commands from unknown instructions into the Windows command line or PowerShell.
Google is officially ending software support for the Pixel 6 and Pixel 6 Pro. With…
A hacker attack has completely paralyzed the Romanian real estate market. After a failed ransom…
Millions of websites are currently at risk of a successful attack. An error became known…
Stripe and Advent are offering a massive $53 billion for PayPal, but the payment service…
A newly emerged North Korean clone of the Google Pixel 8 Pro not only looks…
LibreOffice once again sharply criticizes Microsoft Office file formats. The accusation is that users are…