Microsoft has noticed a spike in assaults utilizing the ACR Stealer malware to steal passwords, authentication tokens, and delicate paperwork saved in browsers from enterprise clients.
From late April to mid-June, attackers used ClickFix social engineering methods, WebDAV servers, and the Microsoft HTML Utility Host (MSHTA) utility to ship information-stealing payloads.
ACR Stealer is a malware-as-a-service (MaaS) operation that’s believed to be a rebrand of the Amatera Stealer malware.
ACR stealer assault
Though there are a number of supply strategies for this malware, Microsoft highlights the 2 most prevalent compromise chains for ACR Stealer.
The primary marketing campaign begins with a ClickFix lure that executes a command that makes use of rundll32.exe to execute a malicious DLL from a distant WebDAV share.
Attackers exploiting WebDAV is a standard tactic and has been seen in previous assaults delivering Bumblebee and Voldemort malware.
Microsoft mentioned in a report this week that attackers sometimes use GUID-based listing constructions and filenames in WebDAV paths to imitate legit assets (akin to google.ct) and blend their exercise with anticipated community site visitors.
After establishing communication with the command and management (C2) infrastructure, a “extremely obfuscated PowerShell script” is executed to launch the malware installer and set up persistence.
This routine installs the bundled Python loader, creates a scheduled job masked as a software program replace, manipulates timestamps, clears PowerShell historical past, and injects the ultimate payload into the system course of for execution in reminiscence.
Some variants use public blockchain providers as useless drop resolvers to acquire up to date payload places or C2 addresses. This can be a widespread method often known as “EtherHiding”.
Within the second supply chain, risk actors use ClickFix to launch MSHTA. This retrieves malicious content material from the attacker’s server and executes an obfuscated PowerShell downloader.
The malware then extracts an encrypted payload hidden inside a publicly hosted steganographic JPEG picture and executes it straight in reminiscence.
Regardless of the variations, the objective continues to be to steal delicate information.
- Steal passwords, cookies, session information, and authentication tokens saved in internet browsers.
- Decrypt browser information through Home windows Knowledge Safety API DPAPI
- Entry the Chromium browser database in Chrome and Edge
- Search PDF and Microsoft 365 paperwork
- Gather information from Desktop and Downloads folders
- Goal OneDrive and SharePoint directories for enterprise sync
All information is collected and archived in case it’s launched to an attacker.

Supply: Microsoft
“These two campaigns signify a few of the commonest ACR Stealer supply campaigns noticed by Defender Skilled. Nonetheless, they don’t signify all supply strategies utilized by this malware household,” Microsoft warns, noting that further execution chains are very doubtless current.
As a normal rule of protection towards ClickFix assaults, customers ought to keep away from copying and executing directions in a command interpreter, particularly in the event that they declare to repair errors or confirm human id.
Microsoft recommends that organizations cut back their publicity to web-based supply chains by making use of filters, blocking disreputable or new domains, and limiting entry to on-line assets not wanted for enterprise operations.
Utility management guidelines can prohibit launching content material from distant assets utilizing instruments akin to PowerShell, Python, mshta.exe, and rundll32.exe, particularly from user-writable paths.
Microsoft’s report supplies an in depth record of advisable mitigations and a set of indicators of compromise particular to the noticed ACR Stealer exercise.
Safety groups doc 54% of profitable assaults and difficulty a warning on solely 14%. The remainder strikes invisibly by way of the atmosphere.
Picus’ whitepaper exhibits check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
