Executive Summary
Between late April and mid-June 2026, Microsoft observed a significant increase in attacks utilizing the ACR Stealer malware, targeting enterprise customers to exfiltrate browser-stored passwords, authentication tokens, and sensitive documents. The attackers employed social engineering tactics, notably the 'ClickFix' method, to deceive users into executing malicious commands. These campaigns leveraged WebDAV servers and the MSHTA utility to deliver the info-stealing payloads, with some variants utilizing blockchain services for command-and-control communication. The impact includes unauthorized access to confidential information and potential compromise of enterprise systems.
This surge underscores the evolving sophistication of cyber threats, particularly the use of social engineering combined with advanced delivery mechanisms. Organizations must enhance their security posture by implementing robust user education programs, restricting the execution of untrusted scripts, and monitoring for unusual network activities to mitigate such risks.
Why This Matters Now
The recent escalation in ACR Stealer attacks highlights the urgent need for organizations to bolster defenses against sophisticated social engineering tactics and malware delivery methods that exploit user trust and system vulnerabilities.
Attack Path Analysis
The attack began with users being deceived by ClickFix lures to execute malicious commands, leading to the download and execution of ACR Stealer malware. The malware then escalated privileges by exploiting the user's existing permissions to access sensitive data. Subsequently, it moved laterally within the system to gather additional information. The malware established command and control channels using obfuscated PowerShell scripts and blockchain-based dead-drop resolvers. It exfiltrated stolen credentials, authentication tokens, and sensitive documents to attacker-controlled servers. Finally, the impact included unauthorized access to confidential information and potential further exploitation of compromised accounts.
Kill Chain Progression
Initial Compromise
Description
Users were deceived by ClickFix lures to execute malicious commands, leading to the download and execution of ACR Stealer malware.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
PowerShell
Web Protocols
LSASS Memory
Email Forwarding Rule
Archive via Utility
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
ACR Stealer targets browser authentication tokens and OneDrive documents, posing severe risks to financial data and compliance with banking regulations.
Information Technology/IT
IT enterprises face critical exposure as ACR Stealer exploits WebDAV, PowerShell, and cloud services while targeting enterprise-synchronized SharePoint directories.
Health Care / Life Sciences
Healthcare organizations risk HIPAA violations as the infostealer targets Microsoft 365 documents and authentication tokens containing sensitive patient information.
Government Administration
Government agencies face significant threats from ACR Stealer's ability to steal authentication credentials and access classified documents through OneDrive exploitation.
Sources
- Microsoft warns of surge in ACR Stealer attacks on customershttps://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/Verified
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Fileshttps://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html?m=1Verified
- ACR Stealer malware leverages Dead Drop Resolver (DDR) techniquehttps://www.broadcom.com/support/security-center/protection-bulletin/acr-stealer-malware-leverages-dead-drop-resolver-ddr-techniqueVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial execution of malicious commands, it would likely limit the malware's ability to communicate with other workloads, reducing the potential for further compromise.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the malware's access to sensitive data by enforcing strict, identity-based access controls, reducing the scope of data exposure.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the malware's ability to move laterally by enforcing strict segmentation between workloads, reducing the attacker's reach within the network.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely detect and limit unauthorized command and control communications by providing comprehensive monitoring and policy enforcement across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic, reducing the risk of unauthorized data transfer.
While Aviatrix CNSF may not prevent initial unauthorized access, it would likely limit the extent of data exposure and further exploitation by enforcing strict segmentation and access controls.
Impact at a Glance
Affected Business Functions
- User Authentication
- Document Management
- Cloud Storage Services
Estimated downtime: 3 days
Estimated loss: $50,000
Exposure of browser-stored passwords, authentication tokens, and sensitive documents including PDFs and Microsoft 365 files.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit access to sensitive data.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Deploy Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
- • Utilize Threat Detection & Anomaly Response mechanisms to identify and mitigate suspicious behaviors promptly.
- • Educate users on recognizing and avoiding social engineering tactics, such as ClickFix lures, to prevent initial compromise.



