
ClickFix Trick Spreads ACR Stealer via Paste-Run
Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…
Microsoft reports a surge in real-world ACR Stealer activity where attackers use a “ClickFix” trick to get employees to run malicious commands that steal passwords, session tokens, and business documents. Two separate campaigns used different execution methods (WebDAV-hosted payloads vs. MSHTA/fileless execution) to make related incidents harder for defenders to connect.
Microsoft observed two separate ACR Stealer campaigns running from late April to mid-June 2026, both built around the same core trick known as ClickFix. A prompt, typically encountered on a website, tells the user there is a problem and instructs them to run a command, often PowerShell, to fix it. Once the victim copies and pastes that command, the infection chain begins.
What made these campaigns notable is that the two waves used different post-execution methods. One relied on WebDAV-hosted DLLs combined with PowerShell and Python loaders and scheduled tasks to maintain persistence. The other used MSHTA and fileless, in-memory execution to reduce the forensic trail left behind. Despite these technical differences, both chains depended entirely on getting a user to execute a malicious command themselves.
The core reason this lure works is that it mimics normal troubleshooting behavior. Users are accustomed to being told by a website or application that something needs to be fixed, and copy-pasting a suggested command feels like a reasonable, low-effort response. Because the attack does not exploit any software vulnerability, and depends solely on social engineering, traditional patching and vulnerability management offer no protection here.
The varying execution methods also help the campaigns evade detection tuned to a single known chain, and can make related incidents appear disconnected from each other even though they share the same lure and objective.
Once executed, the malware extracts browser-stored credentials, session tokens, and documents, which can allow attackers to access cloud services, impersonate users, and conduct follow-on intrusions across enterprise environments.
Organizations should train employees, IT helpdesk staff, and finance teams to never run copy-paste “fix” commands from pop-ups or unfamiliar websites, and instead contact IT through established, known channels. Because attackers can change delivery and execution patterns (T1204.001, T1059.001, T1218.005, T1053.005) while keeping the same lure, awareness training should focus on the underlying behavior, being asked to execute commands, rather than the exact appearance of any single message. Security operations teams should also monitor for PowerShell, MSHTA, and WebDAV activity alongside attempts to access browser credential stores, since these are the operational signals tied to this lure regardless of which execution chain follows it.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a fake prompt claiming there is a problem on the user's system, instructing them to copy and paste a command to fix it. Running that command triggers the malware chain.
No. Microsoft reported that neither campaign exploits any software vulnerability, relying solely on ClickFix-based social engineering to get users to execute commands.
Once executed, the malware extracts browser-stored credentials, session tokens, and documents, which can allow attackers to access cloud services, impersonate users, and conduct follow-on intrusions.
One chain used WebDAV-hosted DLLs with PowerShell and Python loaders and scheduled tasks, while the other used MSHTA and fileless, in-memory execution, so the differing delivery and execution patterns make related incidents look disconnected.
You’re browsing, a page breaks, and this pops up: “Please run the following command to fix this issue.” That’s the ClickFix trick behind recent ACR Stealer attacks. Microsoft saw sites like this getting people to copy a PowerShell command that quietly pulls in malware and starts grabbing browser passwords, session tokens, and business documents. Here’s the sneaky part: the lure never changes, just the plumbing behind it. One campaign used WebDAV-hosted DLLs and scheduled tasks; another used MSHTA and in‑memory code. To you, it always looks like the same ‘helpful’ fix asking you to run a command. Aha rule: if any website or pop‑up tells you to copy and run a command to ‘fix’ something, stop. Don’t run it, screenshot it and contact our IT support through the usual helpdesk channel instead.

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software…