A significant uptick in ACR Stealer malware campaigns is targeting enterprise environments, with Microsoft highlighting the threat's focus on hijacking active session tokens to bypass security controls. The advisory, first reported by BleepingComputer, details how attackers use this tactic to gain persistent access to corporate networks.

ACR Stealer is engineered to extract sensitive data from web browsers and cloud platforms, including passwords, session cookies, and authentication tokens. Its most critical capability is capturing live session tokens, enabling threat actors to impersonate authenticated users and circumvent multi-factor authentication (MFA) without direct credentials.

The attack lifecycle typically commences with phishing emails luring victims into downloading malicious payloads. Once executed, the malware systematically siphons credentials and documents from local systems, with operators continually refining their tactics to evade detection.

In response, Microsoft emphasizes a layered defense approach. Organizations are advised to enforce strict credential hygiene by avoiding browser-based password storage, deploying robust MFA across all accounts, and enhancing email security to intercept phishing attempts. Continuous monitoring for anomalous activities, such as logins from unfamiliar devices or locations, is also crucial.

The surge underscores cybercriminals' persistent focus on enterprise credentials, particularly session tokens that grant access to critical cloud resources and corporate systems. This threat reinforces the universal need for proactive security postures and vigilant monitoring to protect digital identities and business operations.


針對企業環境的 ACR Stealer 惡意軟件攻擊活動出現顯著增加。Microsoft 強調,該威脅的重點在於劫持有效的工作階段代號(session tokens),以繞過安全控制措施。Microsoft 首次透過 BleepingComputer 發布的安全通告詳細說明,攻擊者如何運用此策略獲取企業網絡的持續存取權限。

ACR Stealer 被設計用於從網頁瀏覽器及雲端平台提取敏感資料,包括密碼、工作階段 cookies 及認證代號。其最關鍵的能力是擷取即時工作階段代號,使攻擊者能冒充已認證的使用者,並在不需直接憑證的情況下規避多重認證(MFA)機制。

此類攻擊週期通常始於釣魚電郵,引誘受害者下載惡意載荷。一旦執行,惡意軟件會系統性地從本地系統竊取憑證及文件,而攻擊者亦持續調整其策略以逃避偵測。

作為回應,Microsoft 強調採用多層防禦方法。建議企業透過避免使用瀏覽器儲存密碼、為所有帳戶部署強健的多重認證機制、並加強電郵安全以攔截釣魚嘗試,來實施嚴格的憑證衛生措施。持續監測異常活動(例如來自不熟悉設備或地點的登入)亦至關重要。

此次攻擊活動的激增,凸顯了網絡犯罪份子對企業憑證的持續關注,特別是那些可用於存取關鍵雲端資源及企業系統的工作階段代號。此威脅再次強調了採取主動安全措施及保持警惕監控以保護數碼身份及業務運作的普遍必要性。

新聞來源 / Original News Source