Microsoft warns of a surge in ACR Stealer attacks against its enterprise customers
Microsoft's own telemetry now shows a surge in ACR Stealer hits against enterprise customers — the same infostealer this watch flagged yesterday riding ClickFix lures to lift session tokens and OneDrive/SharePoint documents. The jump from a researcher writeup to a vendor-issued customer warning means the campaign's hit rate is high enough to move the needle at scale, not a handful of isolated ClickFix victims; re-ranked from context to high on that basis. Guidance is unchanged: gate or block Win+R paste flows, and treat any live session token from a possibly-affected host as burned, not just the password.