ClickFix Trick Spreads ACR Stealer via Paste-Run

The Hacker News · Medium sophistication
Last updated July 30, 2026

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning password changes alone may not be enough and token revocation is required.

How the Attack Worked

Microsoft documented two separate intrusion chains that both rely on the same core trick, known as ClickFix. Victims land on a fake page, often after clicking a malicious ad or a search result manipulated through SEO tactics, and are told to copy a command and paste it into the Windows Run box to resolve a supposed issue. One documented case involved a page impersonating Anthropic's Claude AI assistant, reached through malicious Google ads.

Once the victim pastes the command and presses Enter, the infection begins. One chain is largely fileless and can hide payload data inside a JPEG downloaded from an image-hosting service. The other pulls a DLL from a remote WebDAV share using a disguised filename, then persists through a hidden scheduled task made to look like a routine software update.

Why It Succeeded

The attack does not rely on any software vulnerability. As the reporting notes, neither chain exploits a vulnerability; it only runs because a person read a prompt and pressed Enter. This makes the technique effective against well-patched systems, since the weak point is human trust rather than a technical flaw. Malvertising and SEO manipulation also help the lure reach users who are actively searching for legitimate tools, making the fake page feel like a normal result rather than an unsolicited message.

What to Watch For

  • Any prompt asking you to open Windows Run (Win+R) and paste a command, regardless of the stated reason
  • Landing pages reached through search ads or top search results rather than a bookmarked or known URL
  • Commands referencing rundll32.exe or a remote network path, including WebDAV-style addresses
  • Scheduled tasks that appear to be software updates but were not initiated through normal update channels
  • Brand impersonation pages, such as one mimicking an AI assistant's support flow

How to Build Resistance

Organizations and individuals can reduce risk from this style of attack with a few consistent habits:

  • Treat any instruction to paste a command into Windows Run or a terminal as a likely scam and verify through official support channels first
  • Use bookmarks or known URLs for services like Microsoft 365 and AI tools instead of relying on search results or ads
  • If compromise is suspected, revoke session tokens rather than only changing passwords, since the malware can steal live session tokens
  • Train staff, including IT helpdesk and general employees, to recognize that legitimate fixes rarely require manually pasting and running commands

Because the malware targets Microsoft 365 documents and synced OneDrive and SharePoint files in addition to browser credentials, security teams should pair user awareness training with monitoring for unusual scheduled tasks and token activity across cross-industry Microsoft 365 environments.

Key findings

  • Microsoft observed two ACR Stealer intrusion chains that rely on ClickFix-style prompts to get users to paste commands into Windows Run.
  • The campaigns steal “saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.”
  • Initial access is tied to malvertising/SEO manipulation and impersonation lures (e.g., a page impersonating Anthropic’s Claude).
  • One chain is largely fileless and can hide payload data inside a JPEG downloaded from an image-hosting service.
  • The other chain uses a WebDAV share to pull a DLL and establishes persistence via a hidden scheduled task that looks like a software update.
  • Microsoft advises revoking tokens, not only rotating passwords.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT helpdesk/support, Microsoft 365 users, Security operations (SOC).
  • Affected industries: Cross-industry enterprises using Microsoft 365.
  • Attack channels: website.
  • Impersonated: Claude (Anthropic) / AI assistant support page, Generic “security/verification” or “software update” prompt (ClickFix lure).

Red flags to watch for

  • Any website asking you to paste a command into Windows Run is highly suspicious
  • Reached via “malicious Google ads”/SEO results rather than a known bookmarked site
  • Brand impersonation (a page “impersonating Claude”)
  • Command uses rundll32.exe and a remote path (\\server\GUID\...)
  • Filename made to look legitimate (e.g., “google.ct”)
  • Instructions rely on manual copy/paste execution rather than normal installer/update process
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a ClickFix attack?

A ClickFix attack is a social engineering trick where a fake webpage or prompt instructs a user to copy a command and paste it into Windows Run to fix a supposed problem, which instead executes malware.

What does ACR Stealer take from infected systems?

According to Microsoft's findings, ACR Stealer collects saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.

Why isn't changing my password enough after this attack?

Because the malware can steal live session tokens in addition to passwords, Microsoft advises revoking tokens rather than only rotating passwords.

How do victims typically encounter these ClickFix prompts?

The prompts arrive through malvertising or SEO-manipulated search results, including a page impersonating Anthropic's Claude reached through malicious Google ads.

Read the video transcript

You search for Claude, click a top Google result, and a "ClickFix" box pops up: copy this command into Windows Run to continue. The moment you paste and hit Enter, ACR Stealer installs. It quietly grabs saved browser passwords, live Microsoft 365 tokens, and files from OneDrive and SharePoint, no exploit, just you following that prompt. Big red flag: real sites like Claude or Microsoft 365 never tell you to open Win+R and paste a mystery command. That ClickFix box is just social engineering dressed up as tech support. If any website tells you to paste a command into Windows Run or Terminal, stop. Close it, and report it to security immediately before you press Enter.

Similar attacks

Fake CAPTCHA Tricks Users Into Running TerminalFix

Fake CAPTCHA Tricks Users Into Running TerminalFix

Attackers used a fake Cloudflare “verify you are human” overlay to copy a command to victims’ clipboards and trick them into pasting it into Windows Terminal/PowerShell. The command kicked off a multi-stage infection chain, including downloading payloads hidden inside PNG images, establishing…

August 31, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Fake Teams Update Drops Remote-Access Tools

Fake Teams Update Drops Remote-Access Tools

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store page that claims Microsoft Teams must be updated. The download installs legitimate remote access tools (Level RMM and ScreenConnect) so…

July 27, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
BlueMoon Phishing Uses Browser Zero-Days to Spy

BlueMoon Phishing Uses Browser Zero-Days to Spy

Multiple suspected China-linked espionage groups used a new exploit kit (“BlueMoon”) that starts with phishing emails and a malicious link to break into organizations in the US and Southeast Asia. Clicking the link can trigger browser and Windows vulnerabilities to install surveillance tools,…

September 9, 2026
Copy-Paste Lures Spread New macOS & Windows RATs

Copy-Paste Lures Spread New macOS & Windows RATs

This report describes real-world social engineering where victims are tricked into copying and pasting commands that install malware on macOS and Windows. It also highlights device code phishing activity targeting Microsoft Entra ID/Microsoft 365 tokens, enabling attackers to access accounts and…

August 20, 2026