>samit_hota
Back to security news
SN-2026-169HighOpen

Microsoft Warns of Global Surge in ACR Stealer Malware Attacks

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Enterprise customers targeted by ACR Stealer malware
#news#malware#acr

Overview

Microsoft has issued a critical warning to its enterprise customers about a notable surge in attacks employing the ACR Stealer malware. This sophisticated information stealer, believed to be a rebranded version of the Amatera Stealer, is designed to pilfer browser-stored passwords, authentication tokens, and sensitive documents. The ongoing campaign heavily utilizes the “ClickFix” social engineering method and is executed through multiple intrusion chains, posing a significant threat to organizational data security.

Technical Details

ACR Stealer is a “malware-as-a-service (MaaS) operation” that enables cybercriminals to rent or subscribe to its capabilities for their malicious campaigns. Its primary function is to exfiltrate sensitive data from compromised systems, specifically targeting:

  • Browser-stored Passwords: Credentials saved in web browsers, providing access to numerous online accounts.
  • Authentication Tokens: Session tokens and other authentication data that can bypass traditional login processes.
  • Sensitive Documents: Files that may contain proprietary information, personal data, or other valuable assets.

Microsoft has observed two distinct intrusion chains used by attackers deploying ACR Stealer:

  1. Malicious DLL via Remote WebDAV Share: One chain involves the execution of a command that runs a malicious Dynamic Link Library (DLL) file from a remote WebDAV (Web Distributed Authoring and Versioning) share. WebDAV is an extension of HTTP that allows clients to perform remote web content authoring operations. Attackers exploit this to host and execute their malicious payload.
  2. Microsoft HTML Application Host (mshta.exe) Exploitation: The second chain involves exploiting the Microsoft HTML Application Host (mshta.exe). This legitimate Windows utility is used to execute HTML applications (HTA files). Attackers can craft malicious HTA files that, when executed, bypass security controls and facilitate the deployment of ACR Stealer.

These intrusion chains are often initiated through “ClickFix” social engineering methods. While specifics of “ClickFix” aren’t detailed, it typically refers to deceptive tactics designed to trick users into performing an action (a “click”) that inadvertently launches the infection process, often by presenting a seemingly benign or urgent prompt.

Real-World Impact

The widespread deployment and efficacy of ACR Stealer pose a substantial threat to enterprise security. A successful infection can lead to:

  • Account Takeover: Stolen passwords and authentication tokens can be used to compromise employee accounts across various corporate services, including email, cloud applications, and internal platforms.
  • Data Breaches: Exfiltration of sensitive documents can result in the loss of intellectual property, trade secrets, financial data, and personally identifiable information (PII), leading to significant financial and reputational damage.
  • Lateral Movement: Compromised credentials can provide attackers with the ability to move laterally within an organization’s network, escalating privileges and accessing more critical systems.
  • Further Attacks: The stolen information can be leveraged for subsequent attacks, such as business email compromise (BEC) scams, ransomware deployment, or targeted phishing campaigns against an organization’s partners or customers.
  • Disruption of Operations: The diversion of IT and security resources to respond to and remediate infections can disrupt normal business operations.

Given that it’s a MaaS operation, its accessibility to a wider range of threat actors, including those with less technical sophistication, increases the likelihood of widespread attacks.

Threat Landscape

Information stealers like ACR Stealer represent a persistent and evolving threat in the cybercrime landscape. Their ability to quickly harvest credentials and sensitive data makes them valuable tools for initial access brokers and other malicious actors looking to monetize stolen information or facilitate more complex attacks. The rebranding from Amatera Stealer to ACR Stealer indicates continuous development and adaptation by malware authors to evade detection and expand capabilities.

The use of social engineering, particularly methods like “ClickFix,” highlights that human vulnerability remains a critical factor in successful cyberattacks. Even with advanced technical controls, a well-executed social engineering ploy can bypass many defenses. The reliance on legitimate system utilities like mshta.exe for execution (living-off-the-land techniques) further complicates detection, as these activities can blend in with normal system operations.

Remediation

Microsoft’s warning necessitates immediate and robust action from enterprise security teams to protect against ACR Stealer.

Key remediation and preventative measures include:

  • Enhanced Endpoint Security: Ensure all endpoint detection and response (EDR) and antivirus solutions are up-to-date and configured for maximum protection against known and emerging malware threats. Implement application control to restrict the execution of unauthorized software.
  • Multi-Factor Authentication (MFA): Implement and enforce MFA across all corporate accounts, especially for critical systems and external-facing services. MFA significantly reduces the impact of stolen passwords.
  • Security Awareness Training: Conduct regular and comprehensive security awareness training for all employees, focusing on identifying and avoiding social engineering tactics, phishing emails, and suspicious attachments or links. Emphasize the risks associated with clicking on untrusted “fix-it” prompts.
  • Patch Management: Keep operating systems, browsers, and all software up-to-date with the latest security patches to mitigate vulnerabilities that ACR Stealer or its delivery mechanisms might exploit.
  • Disable Unnecessary Features: Review and disable potentially vulnerable or unnecessary features, such as WebDAV client functionality if not required, to reduce the attack surface.
  • Network Segmentation: Implement network segmentation to limit the blast radius of a successful infection and prevent lateral movement of the malware.
  • Strong Password Policies: Enforce strong, unique password policies and consider deploying password managers to reduce reliance on browser-stored credentials.
  • Monitor for IoCs: Continuously monitor network traffic and endpoint logs for indicators of compromise (IoCs) associated with ACR Stealer, including unusual process execution, outbound connections to suspicious IP addresses, and file modifications.
  • Data Loss Prevention (DLP): Deploy DLP solutions to detect and prevent unauthorized exfiltration of sensitive documents.

By combining technical controls with robust employee education, organizations can significantly reduce their susceptibility to ACR Stealer and similar information-stealing malware campaigns.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call