Cyber Companies SANS ISC: Documented ACR Stealer Infection via Claude Impersonation July 17, 2026 ♡Follow0 SANS ISC handler Brad Duncan documented an ACR Stealer infection traced to a page impersonating Claude AI, reached through malicious Google ads. Discovered from: ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ClaudemalvertisingSANS Internet Storm Centerthreat intelligence