top of page
ALL POSTS
ClickFix Campaign Distributes ACR Stealer to Harvest Browser Tokens and Microsoft 365 Credentials
Key Findings ACR Stealer, active since 2024, steals browser passwords, session tokens, PDFs, and Microsoft 365 documents through ClickFix social engineering lures Two distinct delivery chains identified: one leaves disk artifacts, the other operates entirely in memory using steganography and pixel-embedded payloads No vulnerabilities exploited; both chains rely entirely on victims pasting commands into Run boxes or PowerShell Microsoft recommends revoking tokens rather than r
Jul 174 min read
WordPress Malware Hides C2 Instructions in Steam Profile Comments
Key Findings New malware campaign discovered on approximately 1,980 WordPress sites using Steam Community profile comments to store encoded command-and-control instructions Malware uses invisible Unicode characters hidden within visible Steam profile comments to deliver payloads, making detection difficult Infected sites load external malicious JavaScript and contain a server-side backdoor capable of modifying PHP files for persistent access Campaign first detected in July 20
Jun 23 min read
bottom of page
