Microsoft’s warning about a surge in ACR Stealer activity is a reminder that modern intrusions often begin with stolen browser state, not a dramatic breach of the network perimeter.
A user-driven lure can turn a single Windows command into credential theft, session replay, and local document harvesting from synced cloud workspaces.
A reported PureLogs campaign blends phishing attachments, a legitimate Microsoft build tool, and memory-injection tradecraft to target credentials and wallet data.