Trust as the Attack Surface: Inside the ClickFix Campaigns Powering ACR Stealer- 258
July 19, 2026
No vulnerability was patched, no exploit chain engineered, in the campaigns Microsoft disclosed distributing ACR Stealer through the first half of 2026. The entire attack surface was a single dialog box and a user persuaded to paste a command into it — a technique known as ClickFix that has emerged as one of the more consequential shifts in mass-market credential theft, precisely because it asks nothing of the operating system's defenses and everything of the operator's judgment.
The campaigns Microsoft's Defender Experts team traced between late April and mid-June followed two distinct paths from that same initial prompt. One route ran almost entirely in memory: a chain of scripting layers ultimately retrieved a payload concealed inside the pixel data of an ordinary-looking JPEG image, decoded and executed without ever writing the malicious code to disk. The other route left more forensic residue, mounting a remote WebDAV share disguised as a local drive and using naming conventions designed to blend into legitimate software updates — in one case impersonating a hidden scheduled task to establish persistence while erasing its own command history behind it. A subset of these intrusions went further still, using the EtherHiding technique to store command-and-control addresses on a public blockchain, eliminating any single domain or server that defenders could seize to disrupt the operation.
The lure itself points to a deliberate exploitation of a specific moment of institutional trust. Independent researchers at SANS and Red Canary separately documented the same campaigns using pages impersonating Anthropic's Claude assistant — reached through malicious search advertising and convincingly hosted on legitimate platforms such as Google Sites and GitLab — to persuade victims that the command they were pasting was a normal AI tool installation step rather than a malware loader. That the criminal ecosystem behind ACR Stealer has itself rebranded at least once, reportedly reemerging as Amatera Stealer after its original operator ceased sales in 2024, illustrates the resilience of the underlying business model even as its outward identity shifts. What ties the whole campaign together is not a software flaw but a social one: the abuse of a widely trusted brand to lower a user's guard at precisely the moment their guard matters most.
