As cited
Copy frozen at (site build).
threat intel
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer, an infostealer active since 2024, infiltrates networks through ClickFix social engineering tactics that trick users into executing commands via the Windows Run dialog. Once inside, the malware harvests browser passwords, session tokens, PDFs, Microsoft 365 documents, and files from OneDrive and SharePoint folders.
Why it matters: Enterprise security teams need to detect and block ClickFix lures immediately, as ACR Stealer can exfiltrate authentication tokens and sensitive cloud documents that grant attackers persistent access to email, collaboration platforms, and file repositories.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer, an infostealer active since 2024, infiltrates networks through ClickFix social engineering tactics that trick users into executing commands via the Windows Run dialog. Once inside, the malware harvests browser passwords, session tokens, PDFs, Microsoft 365 documents, and files from OneDrive and SharePoint folders.
Why it matters: Enterprise security teams need to detect and block ClickFix lures immediately, as ACR Stealer can exfiltrate authentication tokens and sensitive cloud documents that grant attackers persistent access to email, collaboration platforms, and file repositories.
- Source published
- First seen by Cybersecurity Tracker