Skip to content

Microsoft Warns of ACR Stealer Campaigns Targeting Enterprise Customers

The Bottom Line: ACR Stealer infects enterprise customers through fake error messages with manipulated commands and steals browser data, credentials, and cloud content.

Microsoft has registered an intensified wave of attacks using the infostealer malware ACR Stealer, which between late April and mid-June 2026 specifically infected enterprise customers via manipulated system commands. The threat targets browser data, cloud storage, and login credentials.

Microsoft documents a significant increase in cyberattacks leveraging ACR Stealer, a malware-as-a-service offering considered an evolution of the Amatera malware. The attacks concentrated primarily between late April and mid-June 2026 on enterprise customers. Attackers use the ClickFix method: victims receive fake error messages instructing them to execute malicious commands in Windows Command Prompt to fix alleged system errors.

Defender experts identified two primary infection chains. The first leverages the Windows utility rundll32.exe to load a malicious DLL from a WebDAV server that mimics legitimate web addresses. An obfuscated PowerShell script then launches an installer that executes the payload in memory. Some variants also use public blockchains to locate their command-and-control servers. The second infection path abuses mshta.exe to launch a PowerShell downloader via manipulated HTML applications, which extracts the malware using steganography from encrypted JPEG images. Microsoft emphasizes that these two mechanisms do not represent ACR Stealer’s complete arsenal of distribution methods.

ACR Stealer focuses on stealing sensitive enterprise data: passwords, cookies, and session data stored in web browsers; credentials decrypted via the Data Protection API (DPAPI); databases from Chromium-based browsers such as Chrome and Edge; local PDF documents and Microsoft 365 files from Desktop and Download directories; and data from synchronized OneDrive and SharePoint folders. The collected information is locally compressed and transmitted to the attackers.

To defend against the threat, Microsoft recommends organizational measures first: training to prevent users from copying commands from external sources into administrative tools. On the technical side, web filters should be implemented to block access to unknown or newly registered domains. Additionally, application control rules should restrictively limit the execution of PowerShell, Python, mshta.exe, and rundll32.exe from user-writable directories.


Source: www.it-daily.net · Published 20 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: