ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

A highly sophisticated malware campaign is underway, using fake software updates to steal sensitive browser tokens and Microsoft 365 files from unsuspecting users. The threat, dubbed ACR Stealer, is being distributed via clickbait-style lures known as ClickFix, which promise to fix perceived issues with popular browsers like Google Chrome and Mozilla Firefox.

The malware works by exploiting the very trust that users place in software updates. When a user clicks on the ClickFix link, they are redirected to a malicious website that hosts the ACR Stealer payload. This executable file then injects itself into the browser’s process memory, allowing it to intercept sensitive data such as OAuth tokens and session cookies. These tokens can be used to gain unauthorized access to various online services, including Microsoft 365.

The most concerning aspect of this campaign is its ability to evade traditional security measures. ACR Stealer uses advanced anti-detection techniques, including code obfuscation and polymorphism, making it difficult for antivirus software to identify the malware. Furthermore, the use of ClickFix lures allows the attackers to blend in seamlessly with legitimate browser update notifications, further complicating the detection process.

The affected users are predominantly individuals who work remotely or have access to Microsoft 365 services. The scope of the campaign is significant, with reports suggesting that thousands of users have been compromised so far. It’s worth noting that this is not an isolated incident, as AI-powered malware has become increasingly sophisticated in recent times, capable of adapting and evolving at an alarming rate.

The ACR Stealer campaign serves as a stark reminder of the ongoing cat-and-mouse game between threat actors and cybersecurity professionals. As AI models continue to improve their ability to detect vulnerabilities, it’s essential for organizations to stay one step ahead by implementing robust security measures, such as regular software updates, employee education, and advanced threat detection tools.

To protect yourself from this type of attack, it’s crucial to exercise extreme caution when clicking on software update notifications. Only download updates directly from the official browser or application website, and be wary of lures that promise to “fix” perceived issues with your browser. Additionally, consider implementing a robust security solution that includes advanced threat detection capabilities, such as AI-powered intrusion prevention systems. By staying vigilant and taking proactive measures, you can significantly reduce the risk of falling victim to this type of attack.


Source: The Hacker News — 2026-07-17