ACR Stealer Malware Uses ClickFix Lures to Steal Browser Credentials and Cryptocurrency Wallets

Microsoft has detailed two primary intrusion chains used by the ACR Stealer malware, which has been increasingly targeting enterprise environments through sophisticated ClickFix social engineering lures. The malware is designed to steal browser credentials, authentication tokens, and cryptocurrency wallet data from infected systems.

According to Microsofts Defender Experts team, the ACR Stealer campaigns have been active since late April 2026 and have successfully compromised systems across multiple customer environments. The attackers use ClickFix lures, which present fake error messages or update prompts that trick users into running malicious PowerShell commands or downloading trojanized files.

Once executed, the ACR Stealer harvests stored credentials from web browsers, extracts authentication tokens for various online services, and targets cryptocurrency wallet applications for their private keys and seed phrases. The stolen data is then exfiltrated to command-and-control servers operated by the threat actors.

The malware employs several evasion techniques to avoid detection, including delayed execution, anti-analysis checks, and the use of legitimate Windows tools for malicious purposes. Microsoft noted that the campaigns have shown increased sophistication in their social engineering approaches, making them more likely to succeed against unsuspecting users.

Microsoft recommends that organizations implement multi-factor authentication, restrict PowerShell execution policies, and educate users about the risks of running commands from untrusted sources. Security teams should also monitor for unusual PowerShell activity and unexpected file downloads as potential indicators of ACR Stealer compromise.