{"id":8819,"date":"2026-07-20T12:00:24","date_gmt":"2026-07-20T12:00:24","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8819"},"modified":"2026-07-20T12:00:24","modified_gmt":"2026-07-20T12:00:24","slug":"new-acr-stealer-campaigns-use-webdav-mshta-to-evade-detection","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8819","title":{"rendered":"New ACR Stealer campaigns use WebDAV, MSHTA to evade detection"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents.<\/p>\n<p class=\"wp-block-paragraph\">In a new report, Microsoft researchers detailed two separate campaigns observed between late April and mid-June 2026 that use different execution techniques for the same theft.<\/p>\n<p class=\"wp-block-paragraph\">The campaign was seen tricking users into executing malicious commands to resolve a fake issue. Once the malware is executed, it extracts browser-stored credentials, session tokens, and documents, which can potentially allow attackers to access cloud services, impersonate users, and conduct follow-on intrusions across enterprise environments.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/nicholas-tausek-6ab41611\/\" target=\"_blank\" rel=\"noopener\">Nick Tausek<\/a>, lead security automation architect at Swimlane, thinks attackers could be using two distinct chains to trick defense tuned on individual indicators.\u00a0 \u201cBy changing the delivery and execution patterns, attackers can evade defenses tuned to one known chain and make related incidents appear disconnected,\u201c he said. \u201cSecurity teams may split the activity across separate investigations, delaying recognition of the shared malware and objective.\u201d<\/p>\n<p class=\"wp-block-paragraph\">ACR Stealer is an information-stealing malware family Microsoft believes is offered through a malware-as-a-service (<a href=\"https:\/\/www.csoonline.com\/article\/4148601\/chrome-abe-bypass-discovered-new-voidstealer-malware-steals-passwords-and-cookies.html\">MaaS<\/a>) model, with possible links to the Amatera Stealer.<\/p>\n<h2 class=\"wp-block-heading\">WebDAV and MSHTA-based chains<\/h2>\n<p class=\"wp-block-paragraph\">Although both campaigns begin with ClickFix lures, Microsoft\u2019s analysis shows they diverge after initial execution. One attack chain uses <a href=\"https:\/\/www.csoonline.com\/article\/530692\/data-protection-webdav-is-bad-says-security-researcher.html\">WebDAV<\/a>-hosted DLLs, PowerShell, Python loaders, scheduled-task persistence, and even blockchain-based infrastructure called the \u201cEtherHiding\u201d technique, to complicate detection and command and control (C2) discovery.<\/p>\n<p class=\"wp-block-paragraph\">The second chain uses <a href=\"https:\/\/www.csoonline.com\/article\/4173096\/internet-explorer-may-be-dead-but-its-ghost-still-runs-malware.html\">MSHTA<\/a>, heavily obfuscated PowerShell, stenography, and predominantly fileless, in-memory execution to minimize forensic trails.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe most troubling part of ACR Stealer is the flexibility surrounding the theft. One chain invests in persistence and layered infrastructure, while the other favors memory execution and fewer forensic traces,\u201d Tausek said. \u201cThose approaches look different to defenders, yet both turn a simple ClickFix lure into stolen credentials, tokens, and business documents.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Microsoft researchers said protections against these campaigns have now been added to Defender. \u201cMicrosoft Defender for Endpoint can help surface both campaigns through behavioral coverage for living-off-the-land execution, suspicious WebDAV and MSHTA activity, obfuscated PowerShell, scheduled-task persistence, in-memory payload execution, and browser credential theft,\u201d they <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/07\/16\/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity\/\" target=\"_blank\" rel=\"noopener\">said<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Mitigations include ClickFix-targeted detections<\/h2>\n<p class=\"wp-block-paragraph\">The report highlighted that neither of the campaigns exploits any software vulnerability, depending solely on ClickFix-based social engineering.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft warned its Defender customers that ClickFix attacks <a href=\"https:\/\/www.csoonline.com\/article\/4016208\/sixfold-surge-of-clickfix-attacks-threatens-corporate-defenses.html\">are on the rise<\/a> and shared XDR queries to identify suspicious commands executed through ClickFix-based activity observed while delivering the ACR Stealer.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft also recommended, as general defense, monitoring for suspicious PowerShell activity, MSHTA execution, WebDAV connections, and attempts to access browser credential stores, while also enabling Microsoft Defender SmartScreen and Attack Surface Reduction (ASR) rules to block common malware delivery techniques.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe campaigns do not need to directly aid one another to be effective. Together, they create ambiguity and stretch limited SOC resources,\u201d Tausek explained. Security teams need enough visibility to correlate endpoint, identity, and network activity as one evolving intrusion, he added.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft also shared a list of C2 addresses and payload hosting domains for defenders to add to their detection.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents. In a new report, Microsoft researchers detailed two separate campaigns observed between late April and mid-June 2026 that use different execution techniques for the same theft. The campaign [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8820,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8819","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8819"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8819"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8819\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8820"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}