Acreed is an information-stealing malware family that emerged in 2025 and rapidly gained adoption among cybercriminals, particularly in Russian-speaking underground communities. It has been advertised on a major Russian-language criminal marketplace and is assessed to be a privately developed project rather than a broadly open malware-as-a-service offering. Reporting indicates Acreed quickly became one of the more prevalent infostealers in circulation during 2025. Acreed is associated with credential theft and data exfiltration typical of the infostealer ecosystem. Infrastructure analysis has linked it to an ecosystem overlapping with Vidar, suggesting operational or technical relationships within established stealer tradecraft. High-confidence reporting supports Acreed’s role as a financially motivated criminal tool used to harvest victim data for downstream fraud and account compromise. Publicly available information in this context does not establish specific victim countries or industry verticals with sufficient confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.