SECURITY·중요도 8·2026. 07. 17.·The Hacker News
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
── KO ──────────────────
ACR Stealer가 Microsoft 365 파일과 브라우저 토큰을 훔치는 방법을 설명합니다.
ACR Stealer는 2024년부터 유포되고 있는 정보 탈취 프로그램으로, 브라우저 비밀번호, 세션 토큰 및 Microsoft 365 문서를 훔칩니다. 이 악성코드는 사용자가 Run 박스에 명령을 붙여넣고 Enter 키를 누름으로써 네트워크에 침투합니다. Microsoft는 두 가지 배달 체인을 발표했습니다.
── EN ──────────────────
ACR Stealer steals browser tokens and Microsoft 365 files using ClickFix lures.
ACR Stealer is an infostealer that has been circulating since 2024, stealing saved browser passwords, session tokens, and Microsoft 365 documents. It gains access when users paste a command into the Run box and hit Enter. Microsoft has outlined two of the delivery chains related to this threat.