Could the software you already trust be helping an attacker compromise your business?

That is exactly the kind of risk we discussed in our August 5 podcast, Why MSPs Need Prevention Before Detection.

And now Microsoft has provided another real-world example of why that conversation matters.

In a July 16 threat report, Microsoft documented increased activity involving ACR Stealer, an information-stealing malware designed to capture credentials, authentication tokens, browser data, and sensitive business documents.

What makes these attacks especially relevant is that the attacker does not rely only on obviously malicious software. The attack chain abuses trusted Windows components and legitimate system capabilities after the victim is tricked into starting the process.

So what exactly happened?

Microsoft observed two major ACR Stealer attack chains between late April and mid-June 2026.

Both began with a social engineering technique called ClickFix. A victim encounters what appears to be a legitimate verification or troubleshooting instruction and is persuaded to run a command.

From there, attackers use trusted Windows technologies such as PowerShell, rundll32, MSHTA, scheduled tasks, WebDAV, and other legitimate system capabilities to continue the attack.

One campaign even executed malicious code almost entirely in memory, reducing the files available for traditional security tools to inspect.

The ultimate objective was straightforward: steal browser passwords, cookies, authentication tokens, Microsoft 365 documents, PDFs, and other valuable information.

Why does this reinforce the point from the podcast?

The August 5 podcast focused on a growing weakness in modern endpoint security:

Detection is being asked to recognize malicious behavior that increasingly occurs inside legitimate software and trusted operating system processes.

That is exactly what Microsoft documented here.

Traditional security assumes there will be something suspicious enough to identify, classify, and respond to.

But what happens when the attacker uses PowerShell?

Or rundll32?

Or a browser?

Or another process the business legitimately needs?

Those tools cannot simply be blocked outright. The real security question becomes:

Once a trusted application is running, what should it actually be allowed to do?

That is where a prevention-first model becomes important.

Why should business leaders care about stolen tokens?

A stolen password is bad. A stolen authenticated session can be worse.

Authentication tokens can potentially allow criminals to operate using an identity that has already logged in. That can lead to unauthorized access to cloud services, email, Microsoft 365 resources, sensitive documents, and additional systems.

The result can include financial loss, operational downtime, legal and compliance exposure, reputational damage, incident-response costs, and lost employee productivity.

IBM's 2025 Cost of a Data Breach research placed the global average breach cost at $4.44 million, while the average U.S. breach cost reached $10.22 million.

The 2026 Verizon Data Breach Investigations Report also found that credential abuse remained a major path into organizations.

But shouldn't EDR catch this?

Sometimes.

But that is not the same as preventing the activity from happening.

Microsoft describes attackers using obfuscation, fileless execution, in-memory payloads, legitimate Windows components, process masquerading, and techniques designed to complicate detection and analysis.

This is another reason Detect and Respond cannot be the only security strategy.

The security team may eventually recognize malicious PowerShell activity, suspicious credential access, or an unusual process.

The more important business question is what the attacker was able to accomplish before that detection occurred.

Modern attacks increasingly involve:

  • Legitimate administrative tools
  • Stolen credentials and authentication tokens
  • Living-off-the-land techniques
  • Fileless and in-memory execution
  • Obfuscated commands
  • Security-tool tampering
  • Rapidly changing malware

That is the exact problem prevention-first security is designed to address.

So what needs to change?

Organizations should assume that eventually something malicious will get past a detection layer.

That means adding Isolation and Containment to the security model.

Instead of simply asking whether an application looks malicious, prevention-first security asks:

What should this application actually be allowed to do?

Microsoft itself recommends restricting PowerShell, Python, MSHTA, rundll32, and similar tools from launching untrusted or internet-delivered content as part of its mitigation guidance.

Isolation and containment can reduce the freedom available to an attacker after initial access by restricting unauthorized execution, controlling how applications interact with protected resources, limiting attacker movement, and reducing the potential blast radius.

The objective is to prevent damaging actions before credential theft, lateral movement, or ransomware encryption can begin.

AppGuard is a proven endpoint protection solution with more than 12 years in production, focused on prevention through Isolation and Containment.

It is designed to complement existing antivirus, EDR, MDR, and XDR investments by adding controls that restrict what trusted applications and processes are allowed to do.

What Should Businesses Do Next?

Assume detection will sometimes fail.

Review whether your endpoint strategy can prevent harmful actions even when the application or Windows process being used is legitimate.

Reduce unnecessary endpoint execution freedom, particularly around scripting engines and administrative tools.

Review browser-stored credentials and authentication-token exposure.

Segment critical systems so one compromised endpoint cannot easily become an enterprise-wide incident.

Review third-party and privileged access.

Test what happens when EDR does not recognize an attack immediately.

Most importantly, make sure your incident response strategy is not your only strategy.

Response happens after something has already occurred. Prevention should reduce how much can happen in the first place.

Microsoft’s ACR Stealer research is another real-world example of the exact issue we discussed in the August 5 podcast.

Attackers are increasingly operating through tools businesses already trust.

The answer is not simply detecting them faster.

It is limiting what they are allowed to do in the first place.

Business owners who want to better understand how prevention-first security can stop attacks before damage occurs should talk with CHIPS about how AppGuard can help prevent incidents like this through Isolation and Containment.

Tony Chiappetta
Post by Tony Chiappetta
August 11, 2026