Acreed is a Windows information-stealing malware family active since at least 2025. It harvests browser-resident data, including saved passwords, authentication cookies, active web-session artifacts, and locally stored application credentials. Stolen session cookies can be replayed to hijack authenticated accounts without repeating password, multifactor-authentication, or single-sign-on flows. Acreed has been associated with theft of authenticated Claude sessions from compromised Windows endpoints, enabling unauthorized use of victims’ accounts. It is part of the broader commodity-infostealer ecosystem, in which harvested credentials and session data can be selected from stealer-log collections and abused or resold by downstream threat actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
A bad actor was “using those login sessions to access Claude accounts and consume their usage.”
Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves.
...ainsi que sur la distribution de logiciels légitimes modifiés ou de versions piratées diffusées via des plateformes de téléchargement non officielles.
« Des sessions de connexion à la plateforme Claude ont été compromises à la suite d’infections par des malwares de type infostealer. »
The malware “steals locally stored data such as login cookies, app credentials, and browser passwords.”
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer identified in the campaign that compromised Claude-platform login sessions.
Voleur d’informations utilisé pour copier les cookies de session stockés dans les navigateurs ainsi que les mots de passe enregistrés, permettant le détournement de sessions et le contournement de l’authentification à deux facteurs.
Named as one of several infostealers identified on impacted systems that can collect login cookies, application credentials, and browser passwords, enabling theft of active Claude sessions.
An information stealer identified as capable of stealing active Claude session cookies from infected Windows computers, enabling account access without passwords and bypassing MFA and SSO.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.