Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for ACR Stealer malware targeting Microsoft 365 browser-stored passwords and tokens

Microsoft warns of malware blitz targeting M365 passwords

Microsoft has flagged a sharp increase in attacks using a malware strain called ACR Stealer to harvest browser-stored passwords, session tokens, and documents from Microsoft 365 environments. The campaign is active, widespread, and specifically designed to raid the credentials your browser remembers for you.

ACR Stealer targets every password, cookie, and authentication token your browser has saved — including M365 sessions. One compromised workstation can expose your entire Microsoft 365 tenant.

How the Attack Works

It starts with social engineering. The most common lure is a fake error message — a technique called ClickFix — that tricks someone into copying and running a command. That single action downloads the malware, which then silently copies every password Chrome or Edge has saved, decrypts session cookies via the Windows Data Protection API, and trawls through OneDrive and SharePoint directories for sensitive files.

The payload runs entirely in memory and hides its command infrastructure behind public blockchain services, making it harder to detect with traditional network monitoring.

Here’s the pattern we see in Australian SMB environments: most staff save their M365 passwords in Chrome. Most businesses don’t enforce conditional access policies that limit what a stolen session token can reach. So when one browser is compromised, the attacker gets email, SharePoint, OneDrive, and Teams — often without triggering a single alert.

What to Do Now

  • Stop using browsers as your password vault. Deploy a managed password manager and disable Chrome’s built-in password saving via group policy.
  • Review your conditional access policies. Enforce device compliance checks and block legacy authentication protocols that bypass MFA.
  • Train your team on ClickFix lures. If a web page asks you to open a command prompt and paste something, that’s the attack. Awareness training is the fastest way to close this gap.
  • Check for signs of compromise. Look for unusual sign-in locations in your M365 audit logs and unexpected file access patterns in SharePoint and OneDrive.

Is Your M365 Environment Hardened?

All IT Services manages and secures Microsoft 365 environments for businesses across Australia. If you’re not sure whether your conditional access policies and endpoint protections are up to scratch, we can run a check.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →