highMalware

ACR Stealer Malware Campaign

First seen Jul 19, 2026 · Updated Jul 19, 2026

infostealercredential-theftagent-relevantbrowser-securitydata-exfiltration

Microsoft has identified a significant surge in attacks deploying ACR Stealer, an information-stealing malware targeting enterprise customers. The malware harvests browser-stored passwords, authentication tokens, and sensitive documents, posing a serious risk to organizational credential security and downstream account compromise.

Technical Analysis

ACR Stealer is designed to extract credentials from browser password stores, session/authentication tokens, cookies, and locally stored documents, typically delivered via phishing lures, malicious downloads, or trojanized installers. Once executed, the stealer exfiltrates harvested data to attacker-controlled infrastructure, often using dead-drop resolver techniques (e.g., abusing legitimate services like Steam or Telegram profiles to obtain C2 addresses) to evade detection. The malware likely employs obfuscation and anti-analysis techniques common to modern stealer families to bypass endpoint defenses. Given that stolen authentication tokens and stored credentials frequently include API keys, OAuth tokens, and service account secrets used by LLM tool integrations and agent frameworks, compromised hosts running AI agents or RAG pipelines could expose these credentials, enabling attackers to hijack agent-to-API sessions, exfiltrate proprietary data, or pivot into connected cloud and SaaS environments.

Affected Systems

Windows endpoints running Chromium-based and Gecko-based browsers (Chrome, Edge, Firefox) with stored credentials; enterprise workstations and servers lacking updated endpoint detection; systems with locally cached API keys, tokens, or credential files used by automation/agent tooling

Indicators of Compromise

  • Specific hashes, IPs, and domains not disclosed in source reporting; organizations should monitor Microsoft Defender/Threat Intelligence feeds for updated ACR Stealer IOC releases

Remediation Steps

  1. 1

    Deploy Endpoint Detection

    Ensure Microsoft Defender for Endpoint or equivalent EDR is updated with latest ACR Stealer signatures and behavioral detection rules enabled.

  2. 2

    Rotate Exposed Credentials

    Immediately rotate browser-stored passwords, session tokens, API keys, and service account credentials on any potentially compromised host, including those used by AI agent or automation pipelines.

  3. 3

    Enforce MFA and Token Hardening

    Enable multi-factor authentication and short-lived, scoped tokens to reduce the impact of stolen credentials and session hijacking.

  4. 4

    Restrict Credential Storage

    Disable browser-based password storage in enterprise environments and enforce use of managed secrets/credential vaults for agent and application authentication.

  5. 5

    User Awareness Training

    Educate employees on phishing and malicious download vectors commonly used to deliver stealer malware.

  6. 6

    Network Monitoring

    Monitor for anomalous outbound connections and C2 dead-drop resolver patterns associated with stealer malware families.

Industries Most Exposed

Enterprise/Corporate ITFinancial ServicesTechnologyRetailHealthcareGovernment

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.