Protect.Computer
NEWS

Fake CAPTCHAs Are Stealing Your Browser Passwords

· 0 min read · Digital scams Identity theft
Fake CAPTCHAs Are Stealing Your Browser Passwords

Microsoft is warning about a sharp rise in attacks using a malware called ACR Stealer that specifically targets passwords, cookies, and session tokens saved in your web browser. The attacks use a trick called “ClickFix” — a fake CAPTCHA or browser security popup that tells you to press Windows+R, paste a command, and hit Enter to “verify you’re human” or “fix a security issue.” Running that command secretly installs the stealer on your computer.

Once installed, ACR Stealer can pull every password saved in Chrome, Edge, or other Chromium-based browsers, along with authentication cookies that let attackers log into your accounts without even needing your password. It also hunts for synced Microsoft 365 files and documents on your device. The malware is sold as a subscription service to cybercriminals, and active campaigns have been running since at least late April. Victims often have no idea anything happened because the stealer runs silently in the background.

Sources

Related reading