Acreed is an information-stealing malware family that emerged in early 2025 and rapidly became one of the most prevalent infostealer services in the cybercrime ecosystem. It is commonly discussed alongside major MaaS-style stealers such as Lumma, Rhadamanthys, Vidar, and StealC, and has been assessed as a private project advertised in Russian-speaking criminal markets. By 2025 it was widely observed in stealer-log ecosystems and was reported among the top infostealers by infected hosts and market prevalence.
Acreed is associated with the core behaviors typical of modern infostealers: theft of browser-saved credentials, autofill data, active session cookies, authentication tokens, local configuration material, and other sensitive data present on compromised endpoints. Such theft enables downstream account compromise, including abuse of developer, cloud, and AI-platform identities, and can facilitate bypass of multifactor authentication when valid session material is captured. The malware’s output is monetized through structured stealer logs traded in underground markets, where buyers can later select victims by service, geography, or credential type.
Observed infections appear to be broadly opportunistic rather than tightly pre-targeted. Reported infection vectors for the infostealer ecosystem in which Acreed operates include trojanized software, malvertising, and fraudulent CAPTCHA or verification-style lures used to induce execution. Acreed has been linked in reporting to the broader rise of credential theft affecting developer tooling and AI-related platforms, increasing software supply-chain risk because compromised endpoints may expose access to source-code repositories, CI/CD systems, cloud infrastructure, and collaboration services.
Windows is the dominant platform in the observed infostealer landscape in which Acreed operates, accounting for the overwhelming majority of infected hosts, although limited activity across other operating systems has also been noted at ecosystem level. Acreed’s rapid adoption and prominence in 2025 indicate that it became a significant component of the credential-theft economy and a notable successor or complement to other leading infostealer families during periods of disruption affecting competitors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
“...test stolen credentials across multiple services, and adjust tactics based on failed attempts without human input.” / “stolen credentials could be tested against thousands of endpoints simultaneously, including corporate VPNs, SaaS providers, and cloud services…”
Le vol de données de navigateurs web (cookies, mots de passe enregistrés, historiques)
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newer infostealer family mentioned as helping fill the gap in credential theft activity after disruption to Lumma infrastructure.
An active infostealer service cited as one of the more prevalent offerings in 2025.
Acreed is identified as an active infostealer service and one of the most prevalent infostealers in 2025.
An infostealer listed among the most active by infected hosts in 2025.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.