Acreed
Acreed is a Windows-focused infostealer that emerged in early 2025 and rapidly became one of the most prevalent stealer services in the cybercrime ecosystem.
Profile source: Mallory opens in a new tabAcreed
Family profile
Acreed is a Windows-focused infostealer that emerged in early 2025 and rapidly became one of the most prevalent stealer services in the cybercrime ecosystem. It is commonly discussed alongside major malware-as-a-service infostealers such as Lumma, Rhadamanthys, Vidar, and StealC, and has been assessed as a private project advertised in Russian-speaking criminal markets. By 2025 it had risen to the top tier of active infostealer operations by infected hosts and stolen-log volume.
Acreed’s core function is credential and data theft from compromised endpoints. Infostealers in this class are used to harvest browser-saved credentials, autofill data, active session cookies, authentication tokens, SSH keys, local configuration data, and cryptocurrency wallet information, packaging the results into structured stealer logs for resale and follow-on intrusion activity. The operational value of such malware extends beyond password theft because stolen session material can enable account takeover and downstream compromise of cloud services, developer platforms, source-code repositories, CI/CD environments, and other enterprise resources.
Observed infection patterns indicate broad, opportunistic victimization rather than tightly preselected targeting. Common delivery mechanisms associated with contemporary infostealer activity include trojanized software, malvertising, and fraudulent CAPTCHA or ClickFix-style social-engineering pages that induce users to execute malicious commands or payloads. Acreed has also been linked in reporting to Vidar, but the precise nature of that relationship is not currently available at high confidence.
Acreed has been observed in the wider criminal market for stealer logs, where harvested data is traded and filtered for later exploitation by other actors, including initial access brokers. Its rise after disruptions to competing services underscores the resilience and substitutability of the infostealer ecosystem. The malware represents a significant supply-chain and identity risk because infections on developer and knowledge-worker systems can expose both personal and corporate credentials, active sessions, and connected service tokens from a single compromised device.
Capabilities
- Credential Theft
- Exfiltration
- Session Hijacking
MITRE ATT&CK
Acreed in ATT&CK
5 distinct techniquesReporting
Research mentioning Acreed
The AI Agent Credential Crisis: From Stealer Log to Source Code
By late 2025, Lumma operators had reconstituted their networks, and newer families like Acreed and MacSync were filling the gap.
Infostealers StealC and Amadey Disrupted in Police Crackdown
Among the more than 30 active infostealer services currently on offer, the most prevalent in 2025 was Lumma, followed by Acreed, Rhadamanthys, Vidar and StealC, reported threat intelligence firm Flashpoint.
Infostealers StealC and Amadey Disrupted in Police Crackdown
Among the more than 30 active infostealer services currently on offer, the most prevalent in 2025 was Lumma, followed by Acreed, Rhadamanthys, Vidar and StealC, reported threat intelligence firm Flashpoint.
Agentic attack chains advance as infostealers flood criminal markets - Help Net Security
The top five most active infostealers by infected hosts were Lumma, Acreed, Rhadamanthys, Vidar, and StealC.
What'd I Miss? InfoSec Weekend News Roundup for October 31 - November 2, 2025
maCERT, the Moroccan national cybersecurity agency, has released a critical warning about the newly discovered spyware toolkit, Acreed, which spreads at a high rate over the internet.
⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More
The most common types of infostealers being used by sellers in Russian Market over the years have been Raccoon, Vidar, Lumma, RedLine, and Stealc, with Rhadamanthys and Acreed gaining popularity in the first half of 2025.
Rhadamanthys Stealer Evolves: Adds Device Fingerprinting, PNG Steganography Payloads
First advertised by a threat actor named kingcrete2022, Rhadamanthys has emerged as one of the most popular information stealers available under a malware-as-a-service (MaaS) model alongside Lumma, Vidar, StealC, and, more recently, Acreed.
ThreatsDay Bulletin: CarPlay Exploit, BYOVD Tactics, SQL C2 Attacks, iCloud Backdoor Demand & More
An information stealer known as Acreed is gaining traction among threat actors, with a steady rise in Acreed logs in Russian-speaking forums. The stealer was first advertised on the Russian Market in February 2025 by a user named "Nu####ez" and is assessed to be a private project.