INTEL_REPORT
The Hacker News · published 7/17/2026, 8:56:39 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the …
https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html
sha256:251b47a4c2bfc3e6fcfad7271591d90d7d76a4903649db2ac007f7589e59d6a2
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| enhanceblabber.cc |
| Open → |
| domain | creativecommunityinfo.art | Open → |
| domain | sites.google.com | Open → |
| domain | claude-desktop.gitlab.io | Open → |
| domain | sphere-api.dialectosphere.in.net | Open → |
| domain | ck-3d80df5d12cdfe6450a782fc87bf66b444.google | Open → |