HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer is distributed via ClickFix lure pages that trick users into running a malicious command from the Windows Run dialog, harvesting browser passwords, live tokens, and Microsoft 365 documents. The episode highlights gaps in access‑control and security‑awareness that SOC 2 audits require organizations to remediate and evidence.

LiveThreat™ Intelligence · 📅 July 17, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

ACR Stealer Leverages ClickFix Lures to Harvest Browser Tokens and Microsoft 365 Files

What Happened — ACR Stealer, an infostealer active since 2024, is being distributed via “ClickFix” lure pages. Victims inadvertently execute a malicious command from the Windows Run dialog, allowing the stealer to exfiltrate saved browser credentials, live session tokens, PDFs, and files from synced OneDrive and SharePoint folders.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a failure of access‑control and credential‑management safeguards that SOC 2 CC6 (Logical Access) is designed to protect.
  • Continuous evidence of security‑awareness training and command‑line monitoring provides audit‑ready proof that the organization mitigates social‑engineering vectors.
  • Verisq’s Security Awareness Training capability supplies the documentation and ongoing assessment needed to demonstrate control effectiveness in a SOC 2 audit.

Who Is Affected — Enterprises that rely on Microsoft 365 (OneDrive, SharePoint) across technology, SaaS, and financial services sectors.

Recommended Actions

  • Map the incident to SOC 2 CC6 controls; verify that least‑privilege and MFA are enforced for all privileged accounts.
  • Deploy endpoint monitoring to detect anomalous Run‑box commands and block execution of unknown binaries.
  • Conduct targeted security‑awareness sessions on “Run‑box” and lure‑based attacks, and retain training completion records as audit evidence.

Source: The Hacker News

Technical Notes

  • Attack vector: social‑engineering lure → Run‑box command execution → credential and token theft.
  • No specific CVE; the threat relies on user interaction rather than a software flaw.
  • Data types exfiltrated include browser passwords, OAuth tokens, PDFs, and Microsoft 365 documents.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →