Tag
high
threat
ACR Stealer Campaigns Use ClickFix Lures, WebDAV, and Steganography for Credential Theft
2 rules 18 TTPsMicrosoft Defender Experts observed increased ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering lures in two distinct campaigns to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments via WebDAV-based Python loaders or MSHTA-initiated PowerShell with steganography.
Windows
ACR Stealer
infostealer
malware-as-a-service
social-engineering
webdav
powershell
steganography
credential-theft
data-exfiltration
2r
18t
medium
advisory
PureLogs Infostealer Delivered via PawsRunner Steganography
2 rules 1 TTPA steganography-based malware campaign uses PawsRunner to deliver the PureLogs infostealer, highlighting evolving delivery methods.
PureLogs
steganography
infostealer
malware
2r
1t
critical
threat
TeamPCP Backdoors Telnyx PyPI Package with Steganographic Malware
2 rules 5 TTPsThe TeamPCP threat actor compromised the Telnyx PyPI package, injecting credential-stealing malware hidden within WAV audio files to target Linux, macOS, and Windows systems.
TeamPCP
supply chain attack
pypi
credential theft
steganography
2r
5t