Microsoft Warns of Surge in ACR Stealer Attacks Targeting Enterprise Customers

Microsoft has observed a significant increase in attacks using the ACR Stealer malware, which targets enterprise customers by stealing browser-stored passwords, authentication tokens, and sensitive documents. The warning comes from Microsofts security research team, which tracks emerging threats targeting corporate networks.

The ACR Stealer is designed to extract credentials from web browsers, including login information for corporate applications and cloud services. Once installed on a compromised machine, the malware can also harvest authentication tokens that allow attackers to maintain persistent access to compromised accounts even after passwords are changed.

Microsofts threat intelligence team said the malware has been distributed through multiple vectors, including phishing campaigns and compromised software downloads. The attacks have been observed across various industry verticals, with no specific sector being exclusively targeted.

The company recommends that organizations implement multi-factor authentication across all user accounts, enforce least-privilege access policies, and deploy endpoint detection and response solutions capable of identifying credential theft behavior. Regular security awareness training to help employees identify phishing attempts is also advised.

Microsoft has released detection signatures for Defender Antivirus and Microsoft Defender for Endpoint to identify and block ACR Stealer infections. The company encourages security teams to review their Microsoft 365 sign-in logs for unusual authentication patterns that may indicate token theft.