THREAT OPS › Threat News › ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer: Two observed intrusion chains amid increased threat activity
<aside class="table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents" id="accordion-7067dae4-d33a-4b35-adf8-b97bbba2141c"> <button class="btn btn-collapse" type="button"> <span class="table-of-contents-block__label">In this article</span> <span class="table-of-contents-block__current"></span>
<svg class="table-of-contents-block__arrow" fill="none" height="11" viewBox
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- SharepointT1213.002
- MalvertisingT1583.008
- Scheduled Task/JobT1053
- Clear Command HistoryT1070.003
- Data from Local SystemT1005
- Social EngineeringT1684
- MasqueradingT1036
- Process InjectionT1055
- System Binary Proxy ExecutionT1218
- Reflective Code LoadingT1620
- Credentials from Web BrowsersT1555.003
- Command and Scripting InterpreterT1059
- Indicator RemovalT1070
- Data StagedT1074
- Web ServiceT1102
- PowerShellT1059.001
- Process HollowingT1055.012
- Obfuscated Files or InformationT1027
- Social MediaT1593.001
- CredentialsT1589.001
- SteganographyT1027.003
- Windows Command ShellT1059.003
- Drive-by CompromiseT1189
- SEO PoisoningT1608.006
- Dynamic API ResolutionT1027.007
- SteganographyT1001.002
- Dead Drop ResolverT1102.001
- CompressionT1027.015
- Data from Local SystemAML.T0037
- Command and Scripting InterpreterAML.T0050
- MasqueradingAML.T0074
- Drive-by CompromiseAML.T0078
Indicators of compromise
- https://redcanary.com/blog/threat-intelligence/intelligence-insights-may-2026/url
- https://isc.sans.edu/diary/Possible+ACR+Stealer+From+Page+Impersonating+Claude/33018/url
- https://microsoft.github.io/zerotrustassessment/url
- enhanceblabber.ccdomain
- deep-harborio.comdomain
- auramatrixa.comdomain
- zealpraxis.comdomain
- prism-vertex.comdomain
- prism-matrixs.comdomain
- proton-network.comdomain