Acreed Stealer is an infostealer malware family observed in 2025 cybercrime activity affecting Latin America and the Caribbean (LAC). In the provided reporting, Acreed Stealer is identified as one of the malware families associated with exposed credential logs on Russian Market, with most such records tied to LummaC2 and Acreed Stealer. This places it among the infostealer threats used to collect and monetize stolen credentials and other sensitive data from compromised systems. The content directly associates Acreed Stealer with credential exposure affecting major healthcare, government, and financial organizations in the region’s five largest economies. No additional high-confidence technical details on its infection vector, platform specificity, or operator attribution are provided in the source content beyond its role as an infostealer and its presence in stolen-log ecosystems targeting or impacting LAC entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer observed in credential logs affecting LAC-related organizations.
Infostealer observado en registros de credenciales expuestas relacionados con organizaciones de LAC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.