Act
archived
ACR Stealer ClickFix Campaign Targets M365 Sessions and Browser Credentials
- Engineer — Plan: ClickFix is a social-engineering delivery vector, not a patchable vuln — review AppLocker/WDAC policies to restrict arbitrary Run-dialog execution, and audit M365 Conditional Access token-lifetime and revocation settings to limit stolen-session utility.
- SOC/IR — Act: Microsoft Defender Experts documented two active delivery chains; hunt for PowerShell or cmd.exe spawned via user-initiated Run dialog (explorer.exe lineage), and sweep M365 Unified Audit Log for anomalous OAuth grants, bulk file access, or SharePoint/OneDrive exfiltration events since the campaign is live.
- Leader — Plan: Session-token theft bypasses MFA and directly targets M365 documents — worth a leadership brief this quarter on lure-based infostealer risk, and a review of whether security-awareness training covers ClickFix-style social engineering.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.