New ACR Stealer campaigns use WebDAV, MSHTA to evade detection

Summary

Microsoft has reported a rise in ACR Stealer campaigns that employ social engineering tactics, specifically fake issue resolution prompts, to trick users into executing malicious commands. These campaigns utilize distinct execution chains involving WebDAV or MSHTA to steal credentials, browser data, and sensitive documents, potentially leading to unauthorized access to cloud services and further intrusions.

IFF Assessment

FOE

This article details a new surge in ACR Stealer activity and its advanced evasion techniques, representing a significant threat to defenders.

Defender Context

Defenders should be aware of the evolving tactics used by ACR Stealer, particularly its use of social engineering lures and the divergent execution chains employing WebDAV and MSHTA. Organizations should strengthen their endpoint detection and response capabilities and train users to identify and report suspicious prompts to mitigate the risk of credential theft and subsequent breaches.

Read Full Story →