Microsoft Warns of ACR Stealer Attacks on Enterprises
ACR Stealer attacks are increasing, with Microsoft observing new campaigns targeting enterprise customers between late April and mid-June.
The malware uses ClickFix lures, PowerShell scripts, legitimate Windows tools, and blockchain-based infrastructure to steal browser data, authentication tokens, and business files.
ACR Stealer Attacks Target Enterprise Customers
Microsoft says threat actors have increased their use of ACR Stealer against enterprise environments.
The campaigns use several delivery chains, including malicious websites, remote WebDAV servers, PowerShell scripts, and built-in Windows utilities.
ClickFix Lures Trick Users Into Running Commands
Attackers commonly distribute ACR Stealer through ClickFix social-engineering attacks.
These attacks display fake browser errors, verification prompts, or troubleshooting instructions. The page then tells users to copy and run a command through PowerShell, Command Prompt, or the Windows Run dialog.
One attack chain uses rundll32.exe to load a malicious DLL from a remote WebDAV server.
PowerShell Script Installs the Malware
After the infected device contacts the command-and-control server, it receives a heavily obfuscated PowerShell script.
The script launches a malware installer and creates persistence on the compromised system. Some versions install a bundled Python loader that helps execute additional components.
Attackers may create a scheduled task disguised as a legitimate software update. The malware can also modify file timestamps and clear PowerShell command history to conceal its activity.
The final ACR Stealer payload may be injected into a legitimate system process and executed directly in memory.
This method reduces the number of malicious files stored on disk and can make detection more difficult.
Second Attack Chain Uses MSHTA
Microsoft also documented another ACR Stealer attack chain that uses mshta.exe.
The ClickFix lure instructs the victim to launch a command that starts MSHTA. The Windows utility then downloads malicious content from an attacker-controlled server.
An obfuscated PowerShell downloader runs next and retrieves the final encrypted payload.
Attackers may hide the payload inside a publicly hosted JPEG image using steganography. The malware extracts the hidden data and executes it directly in memory.
Using a normal image file can help the malicious traffic avoid basic security filters.
What Data Does ACR Stealer Target?
ACR Stealer can collect browser, authentication, document, and cloud-synchronized data from infected devices, including stored passwords and cookies, authentication tokens and session information, Chrome and Microsoft Edge browser databases, and data protected by the Windows Data Protection API.
It can also target PDF files and Microsoft 365 documents, files stored in Desktop and Downloads folders, enterprise OneDrive directories, and SharePoint-synchronized files.
Access to cookies and session tokens may allow attackers to hijack active accounts without knowing the user’s password.
Enterprise OneDrive and SharePoint folders can also expose internal documents, financial records, customer information, and other sensitive business data.
Stolen Data Is Packaged for Exfiltration
After collecting the targeted information, ACR Stealer packages the stolen data into archive files.
The malware then prepares the archives for transmission to attacker-controlled infrastructure.
Microsoft says the two documented infection chains represent only some of the methods attackers use to distribute ACR Stealer.
Other affiliates may use different websites, scripts, loaders, and command-and-control systems.
How Users Can Avoid ClickFix Attacks
Users should never copy and execute commands from websites that claim the action will fix an error or complete a verification process.
Legitimate websites do not require visitors to launch PowerShell, Command Prompt, MSHTA, or the Windows Run dialog to prove they are human.
Users should close the page and report it to their security team when a website asks them to run commands manually.
Recommended Enterprise Defenses
Organizations should block newly registered and low-reputation domains whenever possible.
Security teams should also restrict access to unnecessary online services and remote resources that attackers could use to host malicious payloads.
Application-control policies can limit the use of tools commonly abused in attacks, including PowerShell, Python, mshta.exe, and rundll32.exe.
Organizations should especially prevent these tools from executing files stored in user-writable directories or remote network locations.
Security teams should also monitor suspicious scheduled tasks, WebDAV connections, PowerShell activity, browser database access, and unusual archive creation.
Microsoft has published additional mitigations and indicators of compromise to help organizations identify ACR Stealer activity.
The warning follows other recent security developments, including the release of a new LegacyHive Windows zero-day. Researchers have also reported that the Claude extension for Chrome remains vulnerable, while Zoom has released an emergency security patch.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages