Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using ACR Stealer, which targets browser passwords, authentication tokens, and sensitive business documents. The malware is delivered through ClickFix lures, WebDAV servers, and MSHTA, and is believed to be a rebranding of Amatera Stealer. #ACRStealer #AmateraStealer #ClickFix #WebDAV #MSHTA

Keypoints

  • Microsoft saw a rise in ACR Stealer attacks against enterprise customers.
  • The malware steals browser credentials, tokens, cookies, and sensitive files.
  • Attackers used ClickFix, WebDAV, and MSHTA to deliver the payload.
  • ACR Stealer is believed to be a rebranded version of Amatera Stealer.
  • Microsoft recommends blocking risky domains and restricting remote script execution tools.

Read More: https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/