SANS ISC: Documented ACR Stealer Infection via Claude Impersonation
SANS ISC handler Brad Duncan documented an ACR Stealer infection traced to a page impersonating Claude AI, reached through malicious Google ads.
SANS ISC handler Brad Duncan documented an ACR Stealer infection traced to a page impersonating Claude AI, reached through malicious Google ads.
ACR Stealer, an infostealer active since 2024, is targeting enterprise networks by stealing saved browser passwords, live session tokens, PDFs, Microsoft 365…