Microsoft has observed a surge in attacks using ACR Stealer, which targets browser passwords, authentication tokens, and sensitive business documents. The malware is delivered through ClickFix lures, WebDAV servers, and MSHTA, and is believed to be a rebranding of Amatera Stealer. #ACRStealer #AmateraStealer #ClickFix #WebDAV #MSHTA
Keypoints
- Microsoft saw a rise in ACR Stealer attacks against enterprise customers.
- The malware steals browser credentials, tokens, cookies, and sensitive files.
- Attackers used ClickFix, WebDAV, and MSHTA to deliver the payload.
- ACR Stealer is believed to be a rebranded version of Amatera Stealer.
- Microsoft recommends blocking risky domains and restricting remote script execution tools.