HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Surge in ACR Stealer Malware Campaign Targets Enterprise Customers, Stealing Browser Credentials and Documents

Microsoft observed a sharp rise in ACR Stealer attacks that use ClickFix lures, WebDAV shares, and MSHTA to exfiltrate browser passwords, tokens, and corporate files. The activity underscores the need for robust SOC 2 access‑control policies, continuous monitoring, and security‑awareness training.

LiveThreat™ Intelligence · 📅 July 19, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Surge in ACR Stealer Malware Campaign Targets Enterprise Customers, Stealing Browser Credentials and Documents

What Happened — Microsoft’s Defender experts observed a sharp increase in attacks leveraging the ACR Stealer malware‑as‑a‑service. Between late April and mid‑June 2026 the actors delivered the info‑stealer via “ClickFix” social‑engineering lures, WebDAV shares, and the MSHTA utility, exfiltrating browser‑stored passwords, authentication tokens, and sensitive files from enterprise endpoints.

Why It Matters for Compliance & Audit Readiness

  • The campaign directly attacks the very access‑control safeguards SOC 2 CC6.1 (Logical Access) expects you to enforce and monitor.
  • Persistent use of obfuscated PowerShell, scheduled‑task masquerading, and DPAPI decryption highlights the need for continuous evidence of privileged‑access reviews and secure configuration baselines.
  • Demonstrates why security‑awareness training and documented credential‑handling policies are essential audit artifacts for the SOC 2 Security principle.

Who Is Affected – Large‑scale enterprise customers across technology, finance, professional services, and other sectors that rely on Microsoft 365, Chrome/Edge browsers, and OneDrive/SharePoint for collaboration.

Recommended Actions

  • Verify that all privileged‑access policies (SOC 2 CC6.1) require MFA, least‑privilege, and regular review of browser credential stores.
  • Deploy endpoint detection that flags rundll32/WebDAV/MSHTA execution chains and logs PowerShell activity for continuous monitoring.
  • Refresh security‑awareness curricula to cover “ClickFix” lures, WebDAV abuse, and the risks of executing unknown HTML applications.

Technical Notes – The attackers chain ClickFix lures to run a malicious DLL via rundll32.exe from a WebDAV share, then launch heavily obfuscated PowerShell that installs a Python loader, creates a disguised scheduled task, and injects the payload in‑memory. A second chain uses MSHTA to fetch a steganographically‑hidden payload from a public JPEG. Data exfiltrated includes decrypted DPAPI browser secrets, Chromium databases, PDFs, Office 365 documents, and files from OneDrive/SharePoint. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →