Microsoft this week issued a public warning about a sharp rise in attacks using ACR Stealer, a Windows malware that empties saved browser passwords, session cookies, and cloud documents — and it gets in only after the user is tricked into pasting a command into the Windows Run box. The technique, called "ClickFix," is being pushed through fake CAPTCHA pages, phony "fix this error" prompts, and poisoned search results, and it works on fully patched Windows 11 PCs because no software vulnerability is being exploited — the user is.
What Microsoft actually said
In a security advisory posted July 16 and picked up widely on July 18, Microsoft said it has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers . The company's Defender Experts team observed increased ACR Stealer activity across customer environments from late April 2026 to mid-June 2026, with campaigns successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents .
ACR Stealer is a malware-as-a-service (MaaS) operation believed to be a rebranding of the Amatera Stealer malware , meaning it is rented out to anyone willing to pay. That is a big part of why it is showing up in so many different attack campaigns at once.
How the ClickFix trick works
The attack is almost embarrassingly simple. A user hits a webpage — often through malvertising or SEO-manipulated search results — that shows a fake CAPTCHA, a phony "your browser needs to be fixed" prompt, or a bogus verification screen. The page tells the visitor to press Windows key + R, paste a command it has quietly copied to their clipboard, and hit Enter. That single action installs the malware.
Microsoft documented two main variations. The first campaign starts with a ClickFix lure that executes a command to run a malicious DLL from a remote WebDAV share using rundll32.exe. The second is stealthier: it uses ClickFix to trigger MSHTA, which fetches malicious content from the attacker's server and executes an obfuscated PowerShell script, then extracts an encrypted payload hidden within a steganographic JPEG image and executes it directly in memory. The second chain leaves almost nothing on the hard drive, which makes it harder for traditional antivirus to catch.
Because the user manually launches the payload, no Windows patch will block this. Keeping the OS updated still matters, but the front line here is user behavior — and if you think you may have already clicked through one of these prompts, our malware and spyware cleanup service can check the machine for the loaders and scheduled tasks these attacks leave behind.
What ACR Stealer actually takes
Once it runs, ACR Stealer goes straight for the browser. The malware aggressively harvests information from browser credential stores, invokes Windows Data Protection API (DPAPI) routines to decrypt locally stored browser passwords, cookies, and authentication tokens, and also enumerates files across the system, targeting PDFs, Microsoft 365 documents, and data stored in enterprise-synchronized directories such as OneDrive and SharePoint.
The session-token piece is the part most people underestimate. Stolen cookies let an attacker sign into your email, bank, or Microsoft 365 account without your password and without triggering multi-factor authentication, because the session already appears "trusted." That is why Microsoft's remediation guidance tells victims to revoke tokens, not just rotate passwords.
How to protect yourself
Three simple rules cover most of the risk:
1. Never paste a command into the Run box (Windows key + R), PowerShell, or Terminal because a website told you to. No legitimate website — not Google, not Microsoft, not your bank — will ever ask you to do that.
2. Treat any "verify you are human" page that wants keyboard input as hostile. Real CAPTCHAs use clicks and image puzzles, not command-line typing.
3. If you did paste something, assume the browser is compromised. From a clean device, change passwords and revoke sessions — start with your primary email, password manager, work identity, banking, crypto, and social accounts, and use each service's sign-out-all-sessions or device-removal control because changing a password alone may not invalidate every stolen cookie or token.
If a PC is behaving oddly after one of these prompts — new browser extensions, unfamiliar scheduled tasks, or antivirus alerts that keep coming back — bring it to our York shop before you sign back into any important accounts on it.
What This Means for York, PA
We're already seeing York-area customers walk in with PCs infected through fake CAPTCHA and "fix this error" pop-ups, and the damage almost always extends beyond the computer to email, banking, and Microsoft 365 accounts. If you or an employee pasted anything from a suspicious webpage, stop using the PC for logins and bring it to York Computer Repair at 2069 Carlisle Rd for a full malware sweep before you change any passwords.
Sources
- Microsoft warns of surge in ACR Stealer attacks on customers
- ACR Stealer: Two observed intrusion chains amid increased threat activity
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
- Microsoft Urges Caution as ACR Stealer Attacks Surge Against Customers
- ACR Stealer ClickFix: Check Passwords, Tokens, Tasks