Bottom line: ACR Stealer employs two technically distinct campaigns to circumvent security tools and fragment investigations without exploiting software vulnerabilities.
Microsoft warns of two new ACR Stealer campaigns from April through June 2026 using ClickFix social engineering to steal credentials and business documents. The campaigns leverage different techniques—WebDAV-based or MSHTA-based—to bypass security controls and confuse SOC teams.
Microsoft has documented two separate ACR Stealer campaigns observed between late April and mid-June 2026. The infection vector in both cases is ClickFix: attackers deceive users into executing commands to fix a fictional problem. After successful execution, the malware extracts credentials from browser storage, session tokens, and business documents—potential access vectors to cloud services and a foundation for identity theft in enterprise environments.
The two campaigns diverge significantly after initial execution. The first chain leverages WebDAV-hosted DLLs, PowerShell, Python loaders, Task Scheduler persistence, and the blockchain-backed “EtherHiding” technique to complicate detection and C2 reconnaissance. The second chain uses MSHTA with heavily obfuscated PowerShell, steganography, and predominantly file-less in-memory execution to minimize forensic traces. According to Microsoft, ACR Stealer is offered as malware-as-a-service (MaaS) and may be connected to Amatera Stealer.
For CISOs, the two-campaign strategy is critical: by employing different execution chains, related incidents appear unconnected, leading SOC teams to investigate incidents separately and identify the common malware family later. This delays incident response and stretches limited resources.
Microsoft has implemented protective measures in Microsoft Defender for Endpoint, including detections for suspicious WebDAV and MSHTA activity, obfuscated PowerShell, Task Scheduler persistence, in-memory payload execution, and browser credential theft. Neither campaign exploits software vulnerabilities—they operate solely through social engineering. Microsoft recommends: monitoring suspicious PowerShell activity, MSHTA execution, WebDAV connections, and browser credential store access; enabling Microsoft Defender SmartScreen and Attack Surface Reduction (ASR) Rules; correlating endpoint, identity, and network activity across XDR logic. Microsoft has provided C2 addresses and payload hosting domains for detection.
Source: www.csoonline.com · Published July 20, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.