Microsoft warns of malware blitz targeting M365 passwords
Microsoft has flagged a sharp increase in attacks using a malware strain called ACR Stealer to harvest browser-stored passwords, session tokens, and documents from Microsoft 365 environments. The campaign is active, widespread, and specifically designed to raid the credentials your browser remembers for you.
How the Attack Works
It starts with social engineering. The most common lure is a fake error message — a technique called ClickFix — that tricks someone into copying and running a command. That single action downloads the malware, which then silently copies every password Chrome or Edge has saved, decrypts session cookies via the Windows Data Protection API, and trawls through OneDrive and SharePoint directories for sensitive files.
The payload runs entirely in memory and hides its command infrastructure behind public blockchain services, making it harder to detect with traditional network monitoring.
What to Do Now
- Stop using browsers as your password vault. Deploy a managed password manager and disable Chrome’s built-in password saving via group policy.
- Review your conditional access policies. Enforce device compliance checks and block legacy authentication protocols that bypass MFA.
- Train your team on ClickFix lures. If a web page asks you to open a command prompt and paste something, that’s the attack. Awareness training is the fastest way to close this gap.
- Check for signs of compromise. Look for unusual sign-in locations in your M365 audit logs and unexpected file access patterns in SharePoint and OneDrive.
Is Your M365 Environment Hardened?
All IT Services manages and secures Microsoft 365 environments for businesses across Australia. If you’re not sure whether your conditional access policies and endpoint protections are up to scratch, we can run a check.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
