Bottom line: ACR Stealer exfiltrates browser credentials and Microsoft 365 content from enterprise environments via ClickFix lures by manipulating users to execute PowerShell commands directly.
The infostealer ACR Stealer steals browser passwords, active session tokens, PDFs, and Microsoft 365 documents stored in enterprise networks. Compromise occurs through ClickFix lures that trick users into entering commands in the Windows Run box.
The infostealer ACR Stealer has been in circulation since 2024 and specializes in a specific attack method: it exfiltrates stored browser passwords, active session tokens, PDFs, Microsoft 365 documents, and files from synchronized OneDrive and SharePoint folders. Microsoft documented two infection chains on Thursday that the Defender Experts team identified.
The attack vector is based on social engineering: attackers use ClickFix lures (fake error messages or support pages) to trick users into manually entering command-line commands into the Windows Run dialog. This bypasses typical defensive measures since command execution is performed directly by the user.
For CISOs, this represents a significant risk in the area of credential theft and data loss. Browser session tokens allow attackers to access web accounts without a password. At the same time, ACR Stealer gains access to Microsoft 365 environments and synchronized cloud storage, exposing intellectual property, customer data, and business correspondence. The attack does not require exploitation of software vulnerabilities but relies on successful user deception.
Countermeasures should address both technical and organizational levels: endpoint protection with behavioral detection, disabling the Run box in restrictive environments, enforcement of conditional access in Microsoft 365, and regular training on identifying ClickFix lures and social engineering techniques.
Source: thehackernews.com · Published 17 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.