Microsoft has warned of a surge in ACR Stealer attacks that use ClickFix malware and legitimate Windows tools to steal browser credentials, authentication tokens, and Microsoft 365 data. Organizations should treat infections as identity breaches, revoke compromised sessions, and strengthen endpoint, application, and identity security to reduce enterprise risk.
Microsoft has warned enterprise customers about a surge in ACR Stealer campaigns that leverage ClickFix malware tactics to trick users into executing malicious commands. These lures typically instruct victims to copy and paste attacker-provided commands into the Windows Run dialog (Win + R) or Windows Terminal, allowing the malware to execute without exploiting a software vulnerability. Attackers then abuse trusted Windows utilities such as rundll32.exe, mshta.exe, and PowerShell to quietly deploy malware that steals credentials, browser session data, and sensitive business documents.
The campaign highlights a growing trend in modern cyberattacks: compromising identities instead of merely stealing passwords. By targeting browser cookies, authentication tokens, and synchronized Microsoft 365 content, attackers can gain persistent access to enterprise resources even when organizations enforce strong password policies and multi-factor authentication.
Microsoft observed increased ACR Stealer activity between late April and mid-June 2026. The malware, believed to be a rebranding of Amatera Stealer, is offered through a Malware-as-a-Service (MaaS) model, enabling affiliates to distribute it through multiple delivery chains that begin with ClickFix social engineering.
Instead of exploiting a software vulnerability, attackers display a fake browser error or verification prompt instructing users to copy and execute a command. Once the victim follows the instructions, the attack proceeds using legitimate Windows components that often blend into normal system activity.
Microsoft documented two primary attack chains.
Attack chain 1: WebDAV, rundll32, and PowerShell
The first campaign begins with a ClickFix lure that launches a malicious DLL from a remote WebDAV share through rundll32.exe.
The attack then:
Executes heavily obfuscated PowerShell commands.
Downloads a bundled Python loader.
Creates scheduled tasks disguised as software updates for persistence.
Manipulates file timestamps to hinder investigations.
Injects the final payload directly into memory to reduce forensic artifacts.
Some observed variants also use EtherHiding, a blockchain-based dead-drop resolver technique that stores attacker infrastructure within Binance Smart Chain contract data, to retrieve updated command-and-control infrastructure while making it more difficult to block or disrupt.
Attack chain 2: MSHTA and steganography
A second campaign uses the same ClickFix technique but launches mshta.exe instead.
The attacker retrieves malicious content from a remote server, executes an obfuscated PowerShell downloader, and extracts an encrypted payload hidden inside a seemingly harmless JPEG image using steganography. The malware then executes entirely in memory, making detection more difficult.
Although the delivery methods differ, both chains ultimately deploy the same infostealer capabilities.
Featured Resource
Cybersecurity kit
This resource kit will help your company adopt the right cybersecurity strategy to secure your business.
Unlike traditional password stealers, ACR Stealer focuses on collecting information that enables immediate access to enterprise resources.
Microsoft reported that the malware targets:
Target
Why attackers want it
Browser passwords
Access saved credentials
Cookies and session data
Hijack authenticated sessions
Authentication tokens
Bypass password-based defenses
Chrome and Edge browser databases
Recover stored enterprise credentials
PDF files
Steal confidential business information
Microsoft 365 documents
Exfiltrate corporate data
Desktop and Downloads folders
Collect sensitive local files
OneDrive and SharePoint synchronized directories
Access cloud-synced enterprise documents
The malware archives the collected information before exfiltrating it to attacker-controlled infrastructure.
Why ACR Stealer is especially dangerous
Modern enterprises increasingly rely on browser-based authentication and cloud productivity platforms.
Because ACR Stealer steals active authentication tokens alongside passwords, attackers may not need to know a user’s credentials to access cloud applications. Stolen browser sessions can enable account takeover even after passwords are changed until organizations revoke existing sessions and invalidate compromised tokens.
The malware also targets synchronized OneDrive and SharePoint folders, expanding the impact beyond a single endpoint to sensitive business documents stored in Microsoft 365.
For security teams, this means every successful infostealer infection should be treated as a potential identity compromise rather than simply a malware incident.
How Hexnode helps reduce the risk
Attacks like ACR Stealer combine suspicious endpoint behavior with identity theft, making layered defenses essential.
Hexnode XDR provides correlated endpoint telemetry, MITRE ATT&CK insights, process analysis through a Visual Process Tree, and threat hunting across seven days of historical process and endpoint-event data. Security teams can respond using documented actions such as isolating devices, terminating processes, and quarantining files.
Hexnode UEM complements detection by enforcing security policies across managed Windows devices. Administrators can control application deployment, configure application allowlists and blocklists, and use Application Compliance to identify devices running unauthorized or unapproved software without automatically blocking those applications.
Organizations can integrate Hexnode UEM compliance data with Microsoft Entra Conditional Access for supported Android, iOS, and macOS 11 or later devices. Hexnode does not currently provide Windows compliance data for this integration, so it should not be positioned as a direct access-control measure for Windows endpoints affected by ACR Stealer.
Conclusion
Microsoft’s findings demonstrate that ClickFix malware and the growing availability of Malware-as-a-Service (MaaS) infostealers like ACR Stealer are making identity-focused attacks easier to launch. These campaigns abuse trusted Windows tools while stealing identities instead of just passwords.
Organizations should respond to any suspected ACR Stealer infection as an identity breach. In addition to isolating affected endpoints, security teams should revoke active sessions, invalidate authentication tokens, rotate credentials, review Microsoft 365 access, and strengthen controls around PowerShell, mshta.exe, rundll32.exe, and other living-off-the-land binaries. Combining user awareness with endpoint security, application control, and identity-based access policies provides stronger protection against this growing class of infostealer attacks.
Protect Enterprise Browser Data
Detect credential theft, secure endpoints, and reduce browser-based risks with Hexnode UEM and XDR.
ACR Stealer is an infostealer malware family that targets browser-stored credentials, cookies, authentication tokens, and enterprise documents. It uses social engineering and trusted Windows utilities to compromise endpoints and steal data without relying on traditional software exploits.
How can organizations defend against ClickFix-based ACR Stealer attacks?
Organizations should educate users about ClickFix scams, restrict the execution of tools like PowerShell, mshta.exe, and rundll32.exe, monitor for suspicious endpoint activity, revoke compromised sessions and tokens after an infection, and enforce application control and device compliance policies.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.