1mo ago · hacker-news
ACR Stealer, an infostealer active since 2024, is being distributed through social engineering lures such as fake Claude AI assistant pages and malvertising. The malware uses fileless techniques and WebDAV shares to steal browser credentials, session tokens, and sensitive files from Microsoft 365, OneDrive, and SharePoint. It relies on user execution via pasted commands and does not exploit software vulnerabilities, making detection dependent on behavioral analysis and proactive controls.