
Microsoft Warns of Surge in ACR Stealer Malware Attacks Targeting Enterprise Customers
Microsoft has detected a significant increase in attacks utilizing the ACR Stealer malware, targeting its enterprise customers to exfiltrate browser-stored passwords, authentication tokens, and sensitive documents. The campaign focuses on compromising credentials and data stored within web browsers, though no specific timeline, affected regions, or technical indicators such as CVE IDs were disclosed. The malware’s primary impact involves unauthorized access to confidential information, posing risks to organizational security. No exact figures on the number of compromised entities or attack vectors were provided in the report. The threat was identified and reported by Microsoft’s security teams without additional attribution to specific threat actors.