Technology

Data theft as a service: Microsoft warns about ACR stealer campaigns

Microsoft warns of an increased wave of attacks with the ACR Stealer malware. Accordingly, attackers are currently increasingly trying to steal passwords, authentication tokens and confidential documents stored in web browsers.

Two variants of the same malware

The campaigns observed ran between late April and mid-June and relied on sophisticated methods to bypass security mechanisms, shared Microsoft with. The focus of the attacks is a social engineering technique called ClickFix. Users are tricked into carrying out supposed problem solutions or security checks themselves. In the cases analyzed by Microsoft, malware was then reloaded via WebDAV servers or the Windows tool MSHTA. ACR Stealer is considered a so-called malware-as-a-service and is intended to be a further development or renaming of the already known Amatera Stealer malware.

Microsoft describes two particularly frequently observed attack sequences. In the first scenario, clicking on the crafted content results in a malicious program library being loaded from a remote WebDAV server. To make network traffic appear inconspicuous, perpetrators use directory and file names that impersonate legitimate resources. After connecting to the control infrastructure, the malware installs additional components, sets up a scheduled task disguised as a software update and conceals its tracks by, among other things, deleting the PowerShell history. The actual malicious code is then executed directly in the main memory. In a second chain of attacks, perpetrators abuse MSHTA to retrieve malicious content from a server. The encrypted malicious code is hidden in a publicly accessible JPEG image using steganography. Some variants also rely on public blockchain services to obtain updated addresses of their command and control servers, a technique known as EtherHiding.

Data extraction on a large scale

The main aim of the attacks is to steal sensitive company data. This includes saved passwords, cookies, session data and authentication tokens from browsers such as Chrome or Edge. The malware also searches PDF files, Microsoft 365 documents, and content on the desktop, in the Downloads folder, and in synchronized OneDrive or SharePoint directories. The collected data is archived and then transmitted to the attackers. Microsoft emphasizes that the two attack methods described represent only a portion of the techniques actually used. Among other things, the group recommends that companies consistently block unknown or untrustworthy Internet sources, restrict the execution of scripts and programs from external sources and make employees aware not to copy and execute commands from unknown instructions into the Windows command line or PowerShell.

Recent Posts

Updates for Android Auto: From new quick settings to the raccoon

Google is planning a practical innovation for Android Auto in the form of Quick Settings.…

3 hours ago

Dell 14S: Another alternative to the MacBook Air, this time for school

With the new XPS 13, Dell already offers a premium alternative to the extremely successful…

3 hours ago

China is said to be using civilian cargo ships for global espionage

Chinese logistics giant Cosco moves harmless cargo around the world every day, but US officials…

3 hours ago

Managing DTF Transfer Orders Across Multiple Cincinnati Apparel Projects

Cincinnati’s official September 2026 special-events calendar places very different projects within the same few weeks:…

3 hours ago

AI finds previously unknown structures on Earth in earthquake data

An AI system has discovered previously overlooked structures at the boundary between the Earth's mantle…

4 hours ago

US Army installs nuclear microreactors on bases

The US armed forces plan to build over 20 nuclear microreactors on domestic military bases.…

4 hours ago