ACR Stealer ClickFix Attack Targets M365 & OneDrive
🟠 High | Source: The Hacker News ACR Stealer is an infostealer that tricks users into running malicious commands via ClickFix social engineering lures, harvesting saved browser credentials, live session tokens, and Microsoft 365 documents including files synced via OneDrive and SharePoint. Once a user pastes and executes the delivered command, the malware silently exfiltrates sensitive data without requiring any elevated privileges. This is particularly dangerous in enterprise environments where browser-stored credentials and active sessions provide direct access to cloud resources. ...