New ACR Stealer campaigns use WebDAV, MSHTA to evade detection
Summary
Microsoft has reported a rise in ACR Stealer campaigns that employ social engineering tactics, specifically fake issue resolution prompts, to trick users into executing malicious commands. These campaigns utilize distinct execution chains involving WebDAV or MSHTA to steal credentials, browser data, and sensitive documents, potentially leading to unauthorized access to cloud services and further intrusions.
IFF Assessment
This article details a new surge in ACR Stealer activity and its advanced evasion techniques, representing a significant threat to defenders.
Defender Context
Defenders should be aware of the evolving tactics used by ACR Stealer, particularly its use of social engineering lures and the divergent execution chains employing WebDAV and MSHTA. Organizations should strengthen their endpoint detection and response capabilities and train users to identify and report suspicious prompts to mitigate the risk of credential theft and subsequent breaches.