Affected Systems

Microsoft 365 enterprise users and organizations. ACR Stealer targets browser credentials, session tokens, and M365 documents. Active since 2024 with two documented delivery chains using ClickFix social engineering lures.

Exploitation Status

Active campaign. ACR Stealer is being actively deployed via ClickFix lures that trick users into manually executing malicious commands. Microsoft Defender Experts has documented ongoing attacks with two distinct delivery chains.

Business Impact

High risk to enterprise environments using Microsoft 365. Successful compromise enables theft of browser-stored credentials, active session tokens (allowing account takeover without passwords), and exfiltration of M365 documents. User interaction is required but ClickFix social engineering has proven effective at bypassing technical controls by manipulating users into executing commands themselves. Credential and session token theft can lead to lateral movement and persistent access.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Deploy email filtering rules to block ClickFix-style lures that instruct users to run PowerShell or command-line instructions
  • Enable Microsoft Defender for Endpoint attack surface reduction rules, specifically blocking execution of potentially obfuscated scripts and untrusted processes
  • Enforce conditional access policies requiring phishing-resistant MFA for M365 access to mitigate session token replay attacks
  • Monitor for suspicious PowerShell execution and clipboard manipulation activity via EDR telemetry, particularly commands launched from browser contexts
  • Conduct targeted user awareness training on ClickFix and similar social engineering tactics that instruct users to paste and execute commands