CISOOnline

New ACR Stealer campaigns use WebDAV, MSHTA to evade detection

The second chain uses MSHTA, heavily obfuscated PowerShell, stenography, and predominantly fileless, in-memory execution to minimize forensic trails.

“The most troubling part of ACR Stealer is the flexibility surrounding the theft. One chain invests in persistence and layered infrastructure, while the other favors memory execution and fewer forensic traces,” Tausek said. “Those approaches look different to defenders, yet both turn a simple ClickFix lure into stolen credentials, tokens, and business documents.”

Microsoft researchers said protections against these campaigns have now been added to Defender. “Microsoft Defender for Endpoint can help surface both campaigns through behavioral coverage for living-off-the-land execution, suspicious WebDAV and MSHTA activity, obfuscated PowerShell, scheduled-task persistence, in-memory payload execution, and browser credential theft,” they said.



Source link