Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-16 and was added to the RWP archive on 2026-09-07.
ACR Stealer showed two intrusion chains — same commodity, different front doors
Microsoft's 16 July 2026 ACR Stealer note is a reminder that infostealer telemetry is a delivery-diversity problem, not a new family every week.
Bottom line up front
CONFIRMED Microsoft 16 July 2026 documents ACR Stealer arriving through two observed intrusion chains rather than a single loader story. Commodity infostealers in 2026 are sold as a payload; affiliates pick SEO, malvertising, cracked-software, or loader services. Pair with Microsoft's late-June StealC/Amadey service write-up: the market is interchangeable families, not one masterpiece implant. OT: not applicable.
Historical backfill of 16 July 2026 reporting; added 7 September 2026.
What happened
Same stealer, two front doors. IR that keys only on one parent process will miss the twin.
Why it mattered
Credential theft is still how ransomware affiliates buy access. Detecting "ACR" is less important than detecting browser-db collection and unexpected archive staging.
Who / what was affected
Microsoft-observed endpoints. No named enterprise required.
Technical context
Hunt both chains' parents. Token/cookie theft follow-up. Isolate, reset IdP, assume mailbox-rule follow-on.
Exploitation / threat status at the time
CONFIRMED Microsoft dual-chain observation.
ASSESSED continues as MaaS.
What defenders should have done
- Behavior detections for stealer collection, not one hash.
- Rapid session revoke.
- Treat cracked-software and SEO download as equal initial access.
RWP assessment
Confidence: High on the "two doors" framing from Microsoft's title-level reporting.
Defensive actions
- Browser isolation for high-risk users.
- Alert on mass cookie-db reads.
- Do not wait for a ransomware note to hunt stealers.