Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:microsoft_mstic, report:secureworks, report:the_hacker_news
tags: report:microsoft_mstic, report:secureworks, report:the_hacker_news
tags: report:microsoft_mstic, report:secureworks, report:the_hacker_news
tags: report:microsoft_mstic, report:secureworks, report:the_hacker_news
tags: report:secureworks, report:the_hacker_news
tags: report:microsoft_mstic, report:the_hacker_news
tags: report:the_hacker_news
tags: report:the_hacker_news
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
ClickFix campaign abuses Deno runtime for infostealer delivery Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealer Categories: Threat Research Tags: clickfix, Deno, WordPress ClickFix campaign abuses Deno runtime for infostealer deliv
ACR Stealer: Two observed intrusion chains amid increased threat activity From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browse
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced On
Deduped connector weight from graph context.