Find notable cyber news and cases, enriched with sources, timelines, and signals.

ACR Stealer browser credential and document theft activity

Malware Activity
First reported
Last updated
Happening score
H score 29
2 unique sources, 2 articles

Summary

Hide ▲

ACR Stealer is driving a surge of browser credential and document theft against enterprise customers. Microsoft said activity climbed from late April to mid-June 2026, with attackers using ClickFix, WebDAV, and MSHTA delivery chains to steal passwords, authentication tokens, cookies, session data, and Microsoft 365 documents. The malware archives collected data for exfiltration and can also target OneDrive and SharePoint content. Microsoft says the observed chains do not exploit a vulnerability and recommends blocking the loader paths and rotating exposed credentials and tokens.

Related Happenings

HollowGraph Windows malware uses Microsoft 365 calendars for covert C2

Malware Activity
H score15 First: 20.07.2026 15:30 Last: 20.07.2026 15:30 Sources 1

About this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...

ACR Stealer enterprise infostealer surge

Malware Activity
H score29 First: 18.07.2026 17:17 Last: 18.07.2026 17:17 Sources 1

How related: Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.

About this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

StealC and Amadey infostealer infrastructure disruption

Malware Activity
H score69 First: 24.06.2026 18:25 Last: 24.06.2026 18:25 Sources 1

About this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...

USB-spreading clipboard-stealing malware targeting cryptocurrency wallets

Malware Activity
H score27 First: 18.06.2026 19:20 Last: 18.06.2026 19:20 Sources 1

About this happening: A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...

Timeline

  1. 17.07.2026 11:56 3 articles · 13d ago

    Microsoft details ACR Stealer ClickFix theft chains targeting browser credentials and Microsoft 365 files

    Technical Analysis Update

    Microsoft said Defender Experts observed ACR Stealer activity climb across customer environments from late April to mid-June 2026, with campaigns using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents. The report described a fileless chain that spawns mshta.exe, uses an embedded VBScript loader and PowerShell to run payloads in memory, and can extract code from a JPEG, plus a disk-based chain that pulls a DLL from a WebDAV share, hides execution with conhost.exe --headless, and drops a ZIP and pythonw.exe loader. Microsoft also said neither chain exploits a vulnerability and advised victims to revoke tokens and rotate credentials.

    Show sources