In today's cybersecurity landscape, malicious activity continues to evolve, and information theft campaigns have become a constant threat to businesses of all sizes. Recently, a significant increase in the activity of the stealer known as ACR Stealer has been detected, a malware that has been observed in two clearly differentiated but equally dangerous intrusion campaigns. This article takes an in-depth look at both campaigns, their attack vectors, the evasion techniques employed, and most importantly, how organizations can protect themselves against this growing threat. In an environment where digital transformation is advancing rapidly, having specialized cybersecurity services is no longer an option, but a necessity.
The first campaign is characterized by the use of WebDAV as an initial vector, combined with the ClickFix social engineering technique. Attackers trick users into executing commands that, through cmd.exe and rundll32.exe, load a DLL from a remote resource hosted on WebDAV. This approach allows adversaries to deliver payloads directly from controlled servers, bypassing traditional perimeter defenses. Once the DLL is executed, an infection chain is deployed that includes highly obfuscated PowerShell scripts, loaders written in Python, and, in some cases, a blockchain-based C2 resolution mechanism, known as EtherHiding. This technique uses public blockchain RPC services to retrieve addresses from command-and-control servers, making it extremely difficult to detect and block malicious infrastructure. Persistence is achieved through hidden scheduled tasks that are disguised as legitimate software updates, and attackers employ timestomping and erasing PowerShell history to remove forensic fingerprints. Credential theft focuses on Chromium-based browsers, using Windows' DPAPI APIs to crack locally stored passwords, cookies, and authentication tokens.
The second campaign, in contrast, opts for an almost completely fileless approach. The starting point is also a ClickFix, but instead of WebDAV, mshta.exe is used to run remote HTA content. The embedded VBScript uses COM objects to decode and run PowerShell in memory, avoiding writing files to disk. The most striking feature of this campaign is the use of steganography to hide the final payload within JPEG images hosted by public imaging services. The PowerShell script extracts the embedded data from the image pixels, decrypts it, and executes it directly in memory using dynamic resolution from APIs such as VirtualAlloc and CreateThread. This minimizes disk artifacts and complicates forensics. As in the first campaign, the ultimate goal is the theft of browser credentials and the collection of sensitive documents, especially PDFs and Office files, for later exfiltration. The combination of steganography and in-memory execution represents a quantum leap in the sophistication of today's stealers.
Both campaigns share the same goal: to obtain credentials stored in browsers, session tokens, and corporate documents that allow access to cloud resources, business applications, and internal systems. Exposure of this data can lead to account compromise, unauthorized access to services such as Microsoft 365 or SharePoint, and lateral movement within the network. For businesses, this poses a critical risk that can translate into financial loss, reputational damage, and sensitive data breaches. Early detection of these attack chains requires thorough monitoring of anomalous behavior, such as running obfuscated PowerShell, using living-off-the-land (LOLBins) tools such as mshta or rundll32, and unusual access to browser database files.
From a protection perspective, organizations must take a multi-layered approach. Educating users is critical to recognizing social engineering tactics like ClickFix prompts, which are often presented as fake CAPTCHA checks or urgent updates. In addition, it is crucial to restrict the use of tools such as PowerShell, Python or mshta in end-user environments, allowing their execution only when strictly necessary and under controlled application policies. Attack Surface Reduction (ASR) rules and application control can block scripts downloaded from the Internet or from user directories such as Temp or Downloads from executing. Monitoring for the creation of suspicious scheduled tasks, timestomping, and history deletion are indicators that should not be overlooked.
Artificial intelligence applied to cybersecurity plays an increasingly important role in the detection of these threats. AI-based solutions for companies can analyze behavior patterns in real time, identify deviations from the baseline, and generate early warnings of attack chains that combine multiple techniques. For example, an endpoint running PowerShell after downloading a JPEG image from a public host, followed by calls to VirtualAlloc, may be automatically flagged as suspicious. The integration of AI agents into detection and response (EDR) systems allows incident investigation and containment to be automated, reducing response time and minimizing impact.
From an infrastructure perspective, companies that use cloud services such as AWS or Azure must take extreme precautions. Attackers can leverage stolen credentials to access management consoles, storage buckets, or cloud-hosted databases. Deploying AWS and Azure cloud services securely, with Conditional Access policies, multi-factor authentication, and regular review of roles and permissions, is essential to prevent information leaks. Likewise, business intelligence tools such as Power BI can be used to centralize and visualize security logs, making it easier for cybersecurity teams to identify anomalous patterns.
Another key aspect is credential management. Reducing reliance on passwords stored in browsers, implementing corporate password managers, and encouraging the use of single sign-on (SSO) with multi-factor authentication are all measures that hinder the success of these types of stealers. In addition, monitoring for suspicious DPAPI activity can alert on credential decryption attempts. Business intelligence services tools can help correlate security events with other data sources, providing a holistic view of risk.
For companies looking to strengthen their security posture, custom application development can be an effective solution. Rather than relying on off-the-shelf software that may contain vulnerabilities or insecure configurations, applications developed specifically for business needs allow security controls to be integrated by design. Custom applications developed by specialized teams can include encryption mechanisms, strong authentication, and audit logging, reducing the attack surface. Similarly, process automation, when implemented correctly, can eliminate error-prone manual tasks and ensure that security policies are applied consistently.
In conclusion, ACR Stealer campaigns represent an evolution in information theft tactics, combining social engineering, advanced evasion techniques, and the use of decentralized infrastructure. Organizations cannot afford to be reactive; They must take a proactive approach that includes ongoing training, endpoint hardening, behavior-based monitoring, and collaboration with cybersecurity experts. Q2BSTUDIO, as a software and technology development company, offers expertise in implementing custom security solutions, AI integration for threat detection, and managed cloud services. Protecting digital assets is a constant race against increasingly sophisticated adversaries, but with the right tools and knowledge, it's possible to maintain a defensive edge.





