🚨 ACTIVE EXPLOITATION
- Microsoft Reports Surge in ACR Stealer Attacks Targeting Enterprise Customers — BleepingComputer
Microsoft has observed a significant increase in attacks using the ACR Stealer malware, which steals browser-stored passwords, authentication tokens, and sensitive documents from enterprise customers. The malware is delivered mainly via two methods involving ClickFix lures, WebDAV servers, and the MSHTA utility, with payloads executed in-memory to evade detection. Organizations should enforce domain filtering, restrict execution of remote content, and avoid running untrusted commands to mitigate these attacks.