ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
AI Analysis
Technical Summary
ACR Stealer is an information-stealing malware associated with the Amatera Stealer rebranding and distributed as malware-as-a-service. Microsoft observed two distinct intrusion chains between late April and mid-June 2026 targeting enterprise environments using ClickFix social engineering lures. The first campaign delivered payloads via WebDAV with Python loaders and used blockchain-based command-and-control resolution. The second campaign used a fileless approach involving MSHTA and payloads concealed via steganography in images. Both campaigns focused on harvesting browser credentials, authentication tokens, and sensitive documents including PDFs and Microsoft 365 files. The threat actors used obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution to avoid detection. They also masqueraded as legitimate software updates and exploited Windows DPAPI to decrypt credentials. The blockchain dead-drop technique enabled dynamic infrastructure for command-and-control.
Potential Impact
The malware campaigns resulted in the theft of browser credentials, authentication tokens, and sensitive documents from compromised enterprise systems. This could lead to unauthorized access to user accounts and sensitive corporate data. The use of obfuscation, fileless techniques, and in-memory execution increases the difficulty of detection and remediation. The targeting of PDF and Microsoft 365 documents may expose confidential business information. The dynamic blockchain-based command-and-control infrastructure complicates traditional network defense measures.
Mitigation Recommendations
No official patch or fix is available as this is malware activity rather than a software vulnerability. Organizations should refer to the Microsoft advisory for detailed detection and mitigation guidance. Mitigation should focus on identifying and blocking the associated domains and indicators of compromise, monitoring for suspicious PowerShell activity and scheduled tasks, and educating users to recognize and avoid ClickFix social engineering lures. Because the malware uses sophisticated evasion techniques including fileless execution and steganography, endpoint detection and response solutions with behavioral analysis capabilities are recommended. Regular credential resets and multi-factor authentication can reduce impact from stolen credentials.
Indicators of Compromise
- domain: proton-network.com
- domain: ux.strainedeasily.icu
- domain: looksta.icu
- domain: fast.raidher.icu
- domain: apigrokcloud.icu
- domain: deep-harborio.com
- domain: zealpraxis.com
- domain: prism-vertex.com
- domain: auramatrixa.com
- domain: cpppemwjewjoiwejow.sale
- domain: creativecommunityinfo.art
- domain: enhanceblabber.cc
- domain: prism-matrixs.com
- domain: breaksd.wifihot.icu
- domain: contrite.quirksturdy.icu
- domain: walter.filloco.icu
ACR Stealer: Two observed intrusion chains amid increased threat activity
Description
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ACR Stealer is an information-stealing malware associated with the Amatera Stealer rebranding and distributed as malware-as-a-service. Microsoft observed two distinct intrusion chains between late April and mid-June 2026 targeting enterprise environments using ClickFix social engineering lures. The first campaign delivered payloads via WebDAV with Python loaders and used blockchain-based command-and-control resolution. The second campaign used a fileless approach involving MSHTA and payloads concealed via steganography in images. Both campaigns focused on harvesting browser credentials, authentication tokens, and sensitive documents including PDFs and Microsoft 365 files. The threat actors used obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution to avoid detection. They also masqueraded as legitimate software updates and exploited Windows DPAPI to decrypt credentials. The blockchain dead-drop technique enabled dynamic infrastructure for command-and-control.
Potential Impact
The malware campaigns resulted in the theft of browser credentials, authentication tokens, and sensitive documents from compromised enterprise systems. This could lead to unauthorized access to user accounts and sensitive corporate data. The use of obfuscation, fileless techniques, and in-memory execution increases the difficulty of detection and remediation. The targeting of PDF and Microsoft 365 documents may expose confidential business information. The dynamic blockchain-based command-and-control infrastructure complicates traditional network defense measures.
Defensive Guidance
No official patch or fix is available as this is malware activity rather than a software vulnerability. Organizations should refer to the Microsoft advisory for detailed detection and mitigation guidance. Mitigation should focus on identifying and blocking the associated domains and indicators of compromise, monitoring for suspicious PowerShell activity and scheduled tasks, and educating users to recognize and avoid ClickFix social engineering lures. Because the malware uses sophisticated evasion techniques including fileless execution and steganography, endpoint detection and response solutions with behavioral analysis capabilities are recommended. Regular credential resets and multi-factor authentication can reduce impact from stolen credentials.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/"]
- Adversary
- null
- Pulse Id
- 6a59832ac2ebd9e525a462b9
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainproton-network.com | — | |
domainux.strainedeasily.icu | — | |
domainlooksta.icu | — | |
domainfast.raidher.icu | — | |
domainapigrokcloud.icu | — | |
domaindeep-harborio.com | — | |
domainzealpraxis.com | — | |
domainprism-vertex.com | — | |
domainauramatrixa.com | — | |
domaincpppemwjewjoiwejow.sale | — | |
domaincreativecommunityinfo.art | — | |
domainenhanceblabber.cc | — | |
domainprism-matrixs.com | — | |
domainbreaksd.wifihot.icu | — | |
domaincontrite.quirksturdy.icu | — | |
domainwalter.filloco.icu | — |
Threat ID: 6a5b3f7634329bf928c66aa6
Added to database: 07/18/2026, 08:55:18 UTC
Last enriched: 07/18/2026, 11:11:42 UTC
Last updated: 08/16/2026, 14:48:15 UTC
Views: 93
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.