ACR Stealer Malware Campaign
First seen Jul 19, 2026 · Updated Jul 19, 2026
Microsoft has identified a significant surge in attacks deploying ACR Stealer, an information-stealing malware targeting enterprise customers. The malware harvests browser-stored passwords, authentication tokens, and sensitive documents, posing a serious risk to organizational credential security and downstream account compromise.
Technical Analysis
ACR Stealer is designed to extract credentials from browser password stores, session/authentication tokens, cookies, and locally stored documents, typically delivered via phishing lures, malicious downloads, or trojanized installers. Once executed, the stealer exfiltrates harvested data to attacker-controlled infrastructure, often using dead-drop resolver techniques (e.g., abusing legitimate services like Steam or Telegram profiles to obtain C2 addresses) to evade detection. The malware likely employs obfuscation and anti-analysis techniques common to modern stealer families to bypass endpoint defenses. Given that stolen authentication tokens and stored credentials frequently include API keys, OAuth tokens, and service account secrets used by LLM tool integrations and agent frameworks, compromised hosts running AI agents or RAG pipelines could expose these credentials, enabling attackers to hijack agent-to-API sessions, exfiltrate proprietary data, or pivot into connected cloud and SaaS environments.
Affected Systems
Windows endpoints running Chromium-based and Gecko-based browsers (Chrome, Edge, Firefox) with stored credentials; enterprise workstations and servers lacking updated endpoint detection; systems with locally cached API keys, tokens, or credential files used by automation/agent tooling
Indicators of Compromise
- Specific hashes, IPs, and domains not disclosed in source reporting; organizations should monitor Microsoft Defender/Threat Intelligence feeds for updated ACR Stealer IOC releases
Remediation Steps
- 1
Deploy Endpoint Detection
Ensure Microsoft Defender for Endpoint or equivalent EDR is updated with latest ACR Stealer signatures and behavioral detection rules enabled.
- 2
Rotate Exposed Credentials
Immediately rotate browser-stored passwords, session tokens, API keys, and service account credentials on any potentially compromised host, including those used by AI agent or automation pipelines.
- 3
Enforce MFA and Token Hardening
Enable multi-factor authentication and short-lived, scoped tokens to reduce the impact of stolen credentials and session hijacking.
- 4
Restrict Credential Storage
Disable browser-based password storage in enterprise environments and enforce use of managed secrets/credential vaults for agent and application authentication.
- 5
User Awareness Training
Educate employees on phishing and malicious download vectors commonly used to deliver stealer malware.
- 6
Network Monitoring
Monitor for anomalous outbound connections and C2 dead-drop resolver patterns associated with stealer malware families.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.