New ACR Stealer campaigns use WebDAV, MSHTA to evade detection

Tags:

Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents.

In a new report, Microsoft researchers detailed two separate campaigns observed between late April and mid-June 2026 that use different execution techniques for the same theft.

The campaign was seen tricking users into executing malicious commands to resolve a fake issue. Once the malware is executed, it extracts browser-stored credentials, session tokens, and documents, which can potentially allow attackers to access cloud services, impersonate users, and conduct follow-on intrusions across enterprise environments.

Nick Tausek, lead security automation architect at Swimlane, thinks attackers could be using two distinct chains to trick defense tuned on individual indicators.  “By changing the delivery and execution patterns, attackers can evade defenses tuned to one known chain and make related incidents appear disconnected,“ he said. “Security teams may split the activity across separate investigations, delaying recognition of the shared malware and objective.”

ACR Stealer is an information-stealing malware family Microsoft believes is offered through a malware-as-a-service (MaaS) model, with possible links to the Amatera Stealer.

WebDAV and MSHTA-based chains

Although both campaigns begin with ClickFix lures, Microsoft’s analysis shows they diverge after initial execution. One attack chain uses WebDAV-hosted DLLs, PowerShell, Python loaders, scheduled-task persistence, and even blockchain-based infrastructure called the “EtherHiding” technique, to complicate detection and command and control (C2) discovery.

The second chain uses MSHTA, heavily obfuscated PowerShell, stenography, and predominantly fileless, in-memory execution to minimize forensic trails.

“The most troubling part of ACR Stealer is the flexibility surrounding the theft. One chain invests in persistence and layered infrastructure, while the other favors memory execution and fewer forensic traces,” Tausek said. “Those approaches look different to defenders, yet both turn a simple ClickFix lure into stolen credentials, tokens, and business documents.”

Microsoft researchers said protections against these campaigns have now been added to Defender. “Microsoft Defender for Endpoint can help surface both campaigns through behavioral coverage for living-off-the-land execution, suspicious WebDAV and MSHTA activity, obfuscated PowerShell, scheduled-task persistence, in-memory payload execution, and browser credential theft,” they said.

Mitigations include ClickFix-targeted detections

The report highlighted that neither of the campaigns exploits any software vulnerability, depending solely on ClickFix-based social engineering.

Microsoft warned its Defender customers that ClickFix attacks are on the rise and shared XDR queries to identify suspicious commands executed through ClickFix-based activity observed while delivering the ACR Stealer.

Microsoft also recommended, as general defense, monitoring for suspicious PowerShell activity, MSHTA execution, WebDAV connections, and attempts to access browser credential stores, while also enabling Microsoft Defender SmartScreen and Attack Surface Reduction (ASR) rules to block common malware delivery techniques.

“The campaigns do not need to directly aid one another to be effective. Together, they create ambiguity and stretch limited SOC resources,” Tausek explained. Security teams need enough visibility to correlate endpoint, identity, and network activity as one evolving intrusion, he added.

Microsoft also shared a list of C2 addresses and payload hosting domains for defenders to add to their detection.

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *