Skip to content

Microsoft Warns of Increased ACR Stealer Attacks

The bottom line: ACR Stealer is increasingly being deployed against Microsoft enterprise customers to steal login credentials and sensitive files.

Microsoft has detected a surge in attacks using the ACR Stealer malware, which targets enterprise customers. The trojan steals passwords stored in browsers, authentication tokens, and sensitive documents.

Microsoft has observed a significant increase in attacks using the ACR Stealer malware. The malware deliberately targets enterprise customers and focuses on exfiltrating passwords stored in web browsers, authentication tokens, and sensitive documents.

For CISOs, this trend represents a concrete threat to the organization’s access controls. ACR Stealer enables attackers to log into enterprise environments using stolen credentials and thereby circumvent traditional perimeter security controls. The threat targets not systems, but the authentication means that grant access to them.

Protective measures should be implemented on multiple levels: in addition to endpoint detection and response and advanced malware detection tools, multi-factor authentication and continuous monitoring of suspicious logins should be prioritized. Monitoring of unusual token usage and browser profile access is also essential.


Source: www.bleepingcomputer.com · Published 18 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: