Active Exploitation Alert: Surge in ACR Stealer Malware Targeting Microsoft 365, OneDrive, SharePoint, and Edge Users

Active Exploitation Alert: Surge in ACR Stealer Malware Targeting Microsoft 365, OneDrive, SharePoint, and Edge Users

Executive Summary

Microsoft has issued a critical warning regarding a surge in attacks leveraging the ACR Stealer malware, which is actively targeting its customer base. ACR Stealer is a sophisticated credential-stealing malware designed to extract sensitive information such as authentication tokens, cookies, and credentials from browsers and applications. The recent escalation in these attacks underscores the evolving tactics of cybercriminals and highlights the urgent need for organizations using Microsoft services to enhance their security posture. This advisory provides a comprehensive technical analysis of the threat, the tactics, techniques, and procedures (TTPs) employed by adversaries, observed exploitation in the wild, victimology, and actionable mitigation strategies.

Threat Actor Profile

The primary operators behind ACR Stealer are financially motivated cybercriminals, though there is growing evidence that some nation-state actors and advanced persistent threat (APT) groups have adopted similar credential-stealing techniques. These actors are opportunistic, leveraging Malware-as-a-Service (MaaS) models to distribute ACR Stealer widely. The malware’s accessibility on underground forums and its modular architecture have contributed to its rapid proliferation. While attribution remains fluid, the technical sophistication of recent campaigns—such as the use of blockchain-based command-and-control (C2) dead-drops and advanced evasion—suggests that both organized cybercrime groups and more advanced actors are involved.

Technical Analysis of Malware/TTPs

ACR Stealer is typically delivered through multi-stage attack chains that exploit both human and technical vulnerabilities. The most prevalent initial access vectors include phishing emails, malicious attachments, and compromised websites. Attackers employ social engineering techniques, such as the ClickFix lure, to trick users into executing malicious payloads.

Once executed, ACR Stealer employs several advanced techniques:

The malware is often delivered via malicious Microsoft Office documents, executable files, or compressed archives. It leverages rundll32.exe or mshta.exe to execute payloads, often from remote WebDAV shares or attacker-controlled servers. The use of PowerShell obfuscation, in-memory execution, and timestamp manipulation enables the malware to evade traditional endpoint detection and response (EDR) solutions.

ACR Stealer targets browser databases, including those of Chrome, Edge, and Firefox, as well as applications such as Discord and Telegram. It extracts stored credentials, session tokens, and cookies, decrypting browser data via the Windows Data Protection API (DPAPI). The malware also seeks out sensitive documents, including Microsoft 365 files and data stored in OneDrive and SharePoint directories.

For exfiltration, ACR Stealer archives the stolen data and transmits it to attacker-controlled infrastructure. Exfiltration channels include HTTP(S) and, in some variants, Telegram bots, which complicate detection and response. Notably, some campaigns utilize blockchain-based dead-drop resolvers (e.g., EtherHiding) to dynamically update C2 endpoints, further enhancing operational resilience.

The malware’s persistence mechanisms include the installation of a Python loader, creation of scheduled tasks disguised as legitimate software updates, and manipulation of system artifacts to avoid forensic detection.

Exploitation in the Wild

Recent months have seen a marked uptick in ACR Stealer campaigns, with Microsoft Threat Intelligence and independent security researchers documenting widespread exploitation. Attackers are distributing the malware via phishing emails containing malicious links or attachments, drive-by downloads from compromised websites, and social engineering lures that prompt users to execute commands under the guise of error resolution or verification.

Proof-of-concept (POC) demonstrations and incident reports on platforms such as LinkedIn and cybersecurity forums confirm the effectiveness of ACR Stealer in extracting credentials from popular browsers and applications. Notably, attackers have been observed leveraging ClickFix lures to induce user interaction, and employing steganography to conceal payloads within JPEG images hosted on public servers.

The use of blockchain-based C2 infrastructure has been reported in the wild, with adversaries leveraging public blockchain services to store and retrieve updated payload locations, thereby circumventing traditional domain-based blocking and takedown efforts.

Victimology and Targeting

The primary targets of ACR Stealer campaigns are organizations utilizing Microsoft products and services, particularly those with a large footprint of Microsoft 365, OneDrive, SharePoint, and Edge deployments. Both enterprise and small-to-medium businesses (SMBs) are at risk, with attackers focusing on environments where browser-based authentication and cloud-synced document storage are prevalent.

Victims span a range of sectors, including finance, healthcare, education, and government. The malware’s ability to extract credentials and session tokens enables attackers to conduct further compromise, lateral movement, and, in some cases, ransomware deployment. The targeting is opportunistic, but organizations with less mature security controls and user awareness programs are disproportionately affected.

Mitigation and Countermeasures

To defend against ACR Stealer and similar credential-stealing threats, organizations should implement a multi-layered security strategy. Key recommendations include:

Educate users about the risks of phishing and social engineering attacks, emphasizing the dangers of executing unsolicited commands or opening suspicious attachments. Implement multi-factor authentication (MFA) across all critical services to reduce the impact of credential theft. Regularly update and patch operating systems, browsers, and applications to mitigate exploitation of known vulnerabilities. Deploy advanced endpoint protection solutions capable of detecting and blocking credential-stealing malware, with behavioral analysis and memory scanning capabilities. Monitor network traffic for signs of data exfiltration, such as unusual outbound connections to low-reputation domains, WebDAV shares with GUID-based paths, or blockchain-based C2 resolvers. Restrict execution of rundll32.exe, mshta.exe, PowerShell, and Python from user-writeable paths using application control policies. Audit scheduled tasks for suspicious or disguised entries and investigate the presence of Python loader binaries in non-standard locations. Enforce least privilege principles and limit user access to sensitive data and administrative functions.

By combining technical controls with continuous user awareness training, organizations can significantly reduce their exposure to ACR Stealer and related threats.

References

Microsoft Security Blog: https://www.microsoft.com/security/blog/

BleepingComputer: https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/

MITRE ATT&CK Framework: https://attack.mitre.org/

LinkedIn: Search for "ACR Stealer" and "Microsoft warning" for recent incident reports and technical discussions.

NVD: https://nvd.nist.gov/ (Monitor for updates on vulnerabilities exploited by ACR Stealer)

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their supply chain and digital ecosystem. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify emerging threats and strengthen their overall security posture. For further details or tailored threat intelligence, please contact the Rescana team at info@rescana.com.