Microsoft has warned businesses about a noticeable increase in cyber attacks recently, using malware called “ACR stealer.”

From late April to mid-June of this year, Microsoft Defender Experts noticed that several attacks were targeting company computers (increased ACR stealer activity across customer environments). The main goal is to steal saved passwords, login tokens, and important company documents. Microsoft published a blog explaining the observed intrusions further.

Microsoft blog.

Basically, ACR Stealer is an information-stealing malware, which is sold as a service. It’s a rebranded version of an earlier malware known as Amatera Stealer. During this period, Microsoft identified two main attacks that stood out. Others may exist as well.

The attacks typically begin with a common trick called “ClickFix.” Victims see a fake message on a website, from suspicious advertisements, or search results. It tells people to copy and paste a command to “fix an error,” or for human verification. However, this prompt asking people to copy/paste or verify themselves is entirely fake. It’s a clever phishing trick.

If someone falls for it, the malware installs itself on the system with clever techniques. In one of the identified methods, the malware downloads files from remote servers and continues to run on the system. Some versions may use blockchain technology to hide their control servers as well.

In the second identified method, the malware runs almost entirely in memory and doesn’t leave any files behind. This is much harder to detect. While both methods differ in their approach, the end goal of obtaining data is the same.

Flowchart.

It aggressively steals information from web browsers, including passwords, login tokens, and cookies. It can also grab PDF files, Microsoft 365 documents, and files stored in the Desktop folder, Downloads, OneDrive, and more. All of this collected data is sent back to the attackers.

The reason why it’s a serious issue is that a successful attack can theoretically give hackers access to accounts and cloud services, making it possible to launch further intrusions.

To stay safe from such cyber attacks, Microsoft has strongly advised people not to copy and paste commands from websites, no matter what they claim. Companies must also use strong security tools (Microsoft Defender, for example) to monitor suspicious activity.

Additionally, Microsoft also recommended educating users to recognize ClickFix-style prompts/fake verification checks, reducing exposure to these fake advertisements, limiting access to remote content that’s not required for business, monitoring for suspicious activity, and more.

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Sudhanshu K
158 Posts

I have been a consumer technology enthusiast for over 5 years. Thanks to my experience in software beta testing and product reviews, I've understood and learnt a lot about what bugs and issues bother people, and I spend time trying to simplify their solutions. I cover smartphones, software, social media, apps, AI, and most consumer tech gadgets. Actively pursuing a Computer Science bachelor’s degree. I'm mostly active on Twitter/X (@TechWhirlUlt), drop a DM or tag me if you want to share info or connect!