ACR Stealer browser credential and document theft activity
Malware Activity
Summary
Hide ▲
Show ▼
ACR Stealer is driving a surge of browser credential and document theft against enterprise customers. Microsoft said activity climbed from late April to mid-June 2026, with attackers using ClickFix, WebDAV, and MSHTA delivery chains to steal passwords, authentication tokens, cookies, session data, and Microsoft 365 documents. The malware archives collected data for exfiltration and can also target OneDrive and SharePoint content. Microsoft says the observed chains do not exploit a vulnerability and recommends blocking the loader paths and rotating exposed credentials and tokens.
Related Happenings
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware Activity
H score15
First: 20.07.2026 15:30
Last: 20.07.2026 15:30
Sources 1
About this happening:
HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware ActivityAbout this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
ACR Stealer enterprise infostealer surge
Malware Activity
H score29
First: 18.07.2026 17:17
Last: 18.07.2026 17:17
Sources 1
How related:
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
About this happening:
ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ACR Stealer enterprise infostealer surge
Malware ActivityHow related: Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
About this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
StealC and Amadey infostealer infrastructure disruption
Malware Activity
H score69
First: 24.06.2026 18:25
Last: 24.06.2026 18:25
Sources 1
About this happening:
StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
StealC and Amadey infostealer infrastructure disruption
Malware ActivityAbout this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
USB-spreading clipboard-stealing malware targeting cryptocurrency wallets
Malware Activity
H score27
First: 18.06.2026 19:20
Last: 18.06.2026 19:20
Sources 1
About this happening:
A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...
USB-spreading clipboard-stealing malware targeting cryptocurrency wallets
Malware ActivityAbout this happening: A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...
Timeline
-
17.07.2026 11:56 3 articles · 13d ago
Microsoft details ACR Stealer ClickFix theft chains targeting browser credentials and Microsoft 365 files
Technical Analysis UpdateMicrosoft said Defender Experts observed ACR Stealer activity climb across customer environments from late April to mid-June 2026, with campaigns using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents. The report described a fileless chain that spawns mshta.exe, uses an embedded VBScript loader and PowerShell to run payloads in memory, and can extract code from a JPEG, plus a disk-based chain that pulls a DLL from a WebDAV share, hides execution with conhost.exe --headless, and drops a ZIP and pythonw.exe loader. Microsoft also said neither chain exploits a vulnerability and advised victims to revoke tokens and rotate credentials.
Show sources
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files — thehackernews.com — 17.07.2026 11:56
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files — thehackernews.com — 17.07.2026 11:56
- Microsoft warns of surge in ACR Stealer attacks on customers — www.bleepingcomputer.com — 18.07.2026 17:17