{"id":799,"date":"2026-07-21T17:53:21","date_gmt":"2026-07-21T12:23:21","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=799"},"modified":"2026-08-18T17:56:25","modified_gmt":"2026-08-18T12:26:25","slug":"acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/","title":{"rendered":"ACR Stealer Surge Targets Enterprise Browsers, Tokens, and Microsoft 365 Data"},"content":{"rendered":"<p>Microsoft has warned enterprise customers about a surge in ACR Stealer campaigns that leverage ClickFix malware tactics to trick users into executing malicious commands. These lures typically instruct victims to copy and paste attacker-provided commands into the Windows Run dialog (Win + R) or Windows Terminal, allowing the malware to execute without exploiting a software vulnerability. Attackers then abuse trusted Windows utilities such as rundll32.exe, mshta.exe, and PowerShell to quietly deploy malware that steals credentials, browser session data, and sensitive business documents.<\/p>\n<p>The campaign highlights a growing trend in modern cyberattacks: compromising identities instead of merely stealing passwords. By targeting browser cookies, authentication tokens, and synchronized Microsoft 365 content, attackers can gain persistent access to enterprise resources even when organizations enforce strong password policies and multi-factor authentication.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Endpoint Security with Hexnode UEM<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the ACR Stealer attack works<\/h2>\n<p>Microsoft observed increased ACR Stealer activity between late April and mid-June 2026. The malware, believed to be a rebranding of Amatera Stealer, is offered through a Malware-as-a-Service (MaaS) model, enabling affiliates to distribute it through multiple delivery chains that begin with ClickFix social engineering.<\/p>\n<p>Instead of exploiting a software vulnerability, attackers display a fake browser error or verification prompt instructing users to copy and execute a command. Once the victim follows the instructions, the attack proceeds using legitimate Windows components that often blend into normal system activity.<\/p>\n<p>Microsoft documented two primary attack chains.<\/p>\n<h3>Attack chain 1: WebDAV, rundll32, and PowerShell<\/h3>\n<p>The first campaign begins with a ClickFix lure that launches a malicious DLL from a remote WebDAV share through rundll32.exe.<\/p>\n<p>The attack then:<\/p>\n<ul>\n<li>Executes heavily obfuscated PowerShell commands.<\/li>\n<li>Downloads a bundled Python loader.<\/li>\n<li>Creates scheduled tasks disguised as software updates for persistence.<\/li>\n<li>Manipulates file timestamps to hinder investigations.<\/li>\n<li>Injects the final payload directly into memory to reduce forensic artifacts.<\/li>\n<\/ul>\n<p>Some observed variants also use EtherHiding, a blockchain-based dead-drop resolver technique that stores attacker infrastructure within Binance Smart Chain contract data, to retrieve updated command-and-control infrastructure while making it more difficult to block or disrupt.<\/p>\n<h3>Attack chain 2: MSHTA and steganography<\/h3>\n<p>A second campaign uses the same ClickFix technique but launches mshta.exe instead.<\/p>\n<p>The attacker retrieves malicious content from a remote server, executes an obfuscated PowerShell downloader, and extracts an encrypted payload hidden inside a seemingly harmless JPEG image using steganography. The malware then executes entirely in memory, making detection more difficult.<\/p>\n<p>Although the delivery methods differ, both chains ultimately deploy the same infostealer capabilities.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            This resource kit will help your company adopt the right cybersecurity strategy to secure your business.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>What data does ACR Stealer steal?<\/h2>\n<p>Unlike traditional password stealers, ACR Stealer focuses on collecting information that enables immediate access to enterprise resources.<\/p>\n<p>Microsoft reported that the malware targets:<\/p>\n<table>\n<thead>\n<tr>\n<th>Target<\/th>\n<th>Why attackers want it<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Browser passwords<\/td>\n<td>Access saved credentials<\/td>\n<\/tr>\n<tr>\n<td>Cookies and session data<\/td>\n<td>Hijack authenticated sessions<\/td>\n<\/tr>\n<tr>\n<td>Authentication tokens<\/td>\n<td>Bypass password-based defenses<\/td>\n<\/tr>\n<tr>\n<td>Chrome and Edge browser databases<\/td>\n<td>Recover stored enterprise credentials<\/td>\n<\/tr>\n<tr>\n<td>PDF files<\/td>\n<td>Steal confidential business information<\/td>\n<\/tr>\n<tr>\n<td>Microsoft 365 documents<\/td>\n<td>Exfiltrate corporate data<\/td>\n<\/tr>\n<tr>\n<td>Desktop and Downloads folders<\/td>\n<td>Collect sensitive local files<\/td>\n<\/tr>\n<tr>\n<td>OneDrive and SharePoint synchronized directories<\/td>\n<td>Access cloud-synced enterprise documents<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The malware archives the collected information before exfiltrating it to attacker-controlled infrastructure.<\/p>\n<h2>Why ACR Stealer is especially dangerous<\/h2>\n<p>Modern enterprises increasingly rely on browser-based authentication and cloud productivity platforms.<\/p>\n<p>Because ACR Stealer steals active authentication tokens alongside passwords, attackers may not need to know a user&#8217;s credentials to access cloud applications. Stolen browser sessions can enable account takeover even after passwords are changed until organizations revoke existing sessions and invalidate compromised tokens.<\/p>\n<p>The malware also targets synchronized OneDrive and SharePoint folders, expanding the impact beyond a single endpoint to sensitive business documents stored in Microsoft 365.<\/p>\n<p>For security teams, this means every successful infostealer infection should be treated as a potential identity compromise rather than simply a malware incident.<\/p>\n<h2>How Hexnode helps reduce the risk<\/h2>\n<p>Attacks like ACR Stealer combine suspicious endpoint behavior with identity theft, making layered defenses essential.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> provides correlated endpoint telemetry, <a href=\"https:\/\/www.hexnode.com\/blogs\/mitre-attack-framework\/\">MITRE ATT&amp;CK<\/a> insights, process analysis through a Visual Process Tree, and threat hunting across seven days of historical process and endpoint-event data. Security teams can respond using documented actions such as isolating devices, terminating processes, and quarantining files.<\/p>\n<p>Hexnode UEM complements detection by enforcing security policies across managed Windows devices. Administrators can control application deployment, configure application <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-allowlist\/\">allowlists<\/a> and blocklists, and use Application Compliance to identify devices running unauthorized or unapproved software without automatically blocking those applications.<\/p>\n<p>Organizations can integrate Hexnode UEM compliance data with Microsoft Entra Conditional Access for supported Android, iOS, and macOS 11 or later devices. Hexnode does not currently provide Windows compliance data for this integration, so it should not be positioned as a direct access-control measure for Windows endpoints affected by ACR Stealer.<\/p>\n<h2>Conclusion<\/h2>\n<p>Microsoft&#8217;s findings demonstrate that ClickFix malware and the growing availability of Malware-as-a-Service (MaaS) infostealers like ACR Stealer are making identity-focused attacks easier to launch. These campaigns abuse trusted Windows tools while stealing identities instead of just passwords.<\/p>\n<p>Organizations should respond to any suspected ACR Stealer infection as an identity breach. In addition to isolating affected endpoints, security teams should revoke active sessions, invalidate authentication tokens, rotate credentials, review Microsoft 365 access, and strengthen controls around PowerShell, mshta.exe, rundll32.exe, and other living-off-the-land binaries. Combining user awareness with endpoint security, application control, and identity-based access policies provides stronger protection against this growing class of infostealer attacks.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Protect Enterprise Browser Data<\/h5><p>Detect credential theft, secure endpoints, and reduce browser-based risks with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is ACR Stealer?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>ACR Stealer is an infostealer malware family that targets browser-stored credentials, cookies, authentication tokens, and enterprise documents. It uses social engineering and trusted Windows utilities to compromise endpoints and steal data without relying on traditional software exploits.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How can organizations defend against ClickFix-based ACR Stealer attacks?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Organizations should educate users about ClickFix scams, restrict the execution of tools like PowerShell, mshta.exe, and rundll32.exe, monitor for suspicious endpoint activity, revoke compromised sessions and tokens after an infection, and enforce application control and device compliance policies.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has warned enterprise customers about a surge in ACR Stealer campaigns that leverage ClickFix&#8230;<\/p>\n","protected":false},"author":6,"featured_media":800,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,16],"class_list":["post-799","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-windows","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ACR Stealer Attacks: Protect Enterprise Credentials<\/title>\n<meta name=\"description\" content=\"Learn how ACR Stealer uses ClickFix malware to steal enterprise credentials, tokens, and Microsoft 365 data, and how to reduce the risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ACR Stealer Attacks: Protect Enterprise Credentials\" \/>\n<meta property=\"og:description\" content=\"Learn how ACR Stealer uses ClickFix malware to steal enterprise credentials, tokens, and Microsoft 365 data, and how to reduce the risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-21T12:23:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T12:26:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"ACR Stealer Surge Targets Enterprise Browsers, Tokens, and Microsoft 365 Data\",\"datePublished\":\"2026-07-21T12:23:21+00:00\",\"dateModified\":\"2026-08-18T12:26:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/\"},\"wordCount\":1025,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/\",\"name\":\"ACR Stealer Attacks: Protect Enterprise Credentials\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp\",\"datePublished\":\"2026-07-21T12:23:21+00:00\",\"dateModified\":\"2026-08-18T12:26:25+00:00\",\"description\":\"Learn how ACR Stealer uses ClickFix malware to steal enterprise credentials, tokens, and Microsoft 365 data, and how to reduce the risk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"ACR Stealer Surge Targets Enterprise Browsers, Tokens, and Microsoft 365 Data\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ACR Stealer Surge Targets Enterprise Browsers, Tokens, and Microsoft 365 Data\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ACR Stealer Attacks: Protect Enterprise Credentials","description":"Learn how ACR Stealer uses ClickFix malware to steal enterprise credentials, tokens, and Microsoft 365 data, and how to reduce the risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/","og_locale":"en_US","og_type":"article","og_title":"ACR Stealer Attacks: Protect Enterprise Credentials","og_description":"Learn how ACR Stealer uses ClickFix malware to steal enterprise credentials, tokens, and Microsoft 365 data, and how to reduce the risk.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-21T12:23:21+00:00","article_modified_time":"2026-08-18T12:26:25+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"ACR Stealer Surge Targets Enterprise Browsers, Tokens, and Microsoft 365 Data","datePublished":"2026-07-21T12:23:21+00:00","dateModified":"2026-08-18T12:26:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/"},"wordCount":1025,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp","articleSection":["Identity Abuse","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/","url":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/","name":"ACR Stealer Attacks: Protect Enterprise Credentials","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp","datePublished":"2026-07-21T12:23:21+00:00","dateModified":"2026-08-18T12:26:25+00:00","description":"Learn how ACR Stealer uses ClickFix malware to steal enterprise credentials, tokens, and Microsoft 365 data, and how to reduce the risk.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ACR-Stealer-Surge-Targets-Enterprise-Browsers-Tokens-and-Microsoft-365-Data.png?format=webp","width":1340,"height":700,"caption":"ACR Stealer Surge Targets Enterprise Browsers, Tokens, and Microsoft 365 Data"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/acr-stealer-surge-targets-enterprise-browsers-tokens-and-microsoft-365-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"ACR Stealer Surge Targets Enterprise Browsers, Tokens, and Microsoft 365 Data"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/799","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=799"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/799\/revisions"}],"predecessor-version":[{"id":802,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/799\/revisions\/802"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/800"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}