ACR Stealer: Two observed intrusion chains amid increased threat activity

Reported 17 Jul 2026 by otx · Severity: medium

Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service,