Skip to content
Malware family Windows

Acreed

Acreed is a Windows-focused infostealer that emerged in early 2025 and rapidly became one of the most prevalent stealer services in the cybercrime ecosystem.

Profile source: Mallory opens in a new tab

Acreed

Family profile

Acreed is a Windows-focused infostealer that emerged in early 2025 and rapidly became one of the most prevalent stealer services in the cybercrime ecosystem. It is commonly discussed alongside major malware-as-a-service infostealers such as Lumma, Rhadamanthys, Vidar, and StealC, and has been assessed as a private project advertised in Russian-speaking criminal markets. By 2025 it had risen to the top tier of active infostealer operations by infected hosts and stolen-log volume.

Acreed’s core function is credential and data theft from compromised endpoints. Infostealers in this class are used to harvest browser-saved credentials, autofill data, active session cookies, authentication tokens, SSH keys, local configuration data, and cryptocurrency wallet information, packaging the results into structured stealer logs for resale and follow-on intrusion activity. The operational value of such malware extends beyond password theft because stolen session material can enable account takeover and downstream compromise of cloud services, developer platforms, source-code repositories, CI/CD environments, and other enterprise resources.

Observed infection patterns indicate broad, opportunistic victimization rather than tightly preselected targeting. Common delivery mechanisms associated with contemporary infostealer activity include trojanized software, malvertising, and fraudulent CAPTCHA or ClickFix-style social-engineering pages that induce users to execute malicious commands or payloads. Acreed has also been linked in reporting to Vidar, but the precise nature of that relationship is not currently available at high confidence.

Acreed has been observed in the wider criminal market for stealer logs, where harvested data is traded and filtered for later exploitation by other actors, including initial access brokers. Its rise after disruptions to competing services underscores the resilience and substitutability of the infostealer ecosystem. The malware represents a significant supply-chain and identity risk because infections on developer and knowledge-worker systems can expose both personal and corporate credentials, active sessions, and connected service tokens from a single compromised device.

Capabilities

  • Credential Theft
  • Exfiltration
  • Session Hijacking

MITRE ATT&CK

Acreed in ATT&CK

5 distinct techniques

Reporting

Research mentioning Acreed

Jul 9
Socradar

The AI Agent Credential Crisis: From Stealer Log to Source Code

By late 2025, Lumma operators had reconstituted their networks, and newer families like Acreed and MacSync were filling the gap.

Jun 24
Bank Info Security

Infostealers StealC and Amadey Disrupted in Police Crackdown

Among the more than 30 active infostealer services currently on offer, the most prevalent in 2025 was Lumma, followed by Acreed, Rhadamanthys, Vidar and StealC, reported threat intelligence firm Flashpoint.

Jun 24
Govinfosecurity

Infostealers StealC and Amadey Disrupted in Police Crackdown

Among the more than 30 active infostealer services currently on offer, the most prevalent in 2025 was Lumma, followed by Acreed, Rhadamanthys, Vidar and StealC, reported threat intelligence firm Flashpoint.

Mar 12
Help Net Security

Agentic attack chains advance as infostealers flood criminal markets - Help Net Security

The top five most active infostealers by infected hosts were Lumma, Acreed, Rhadamanthys, Vidar, and StealC.

Nov 3
Sherpa Intelligence

What'd I Miss? InfoSec Weekend News Roundup for October 31 - November 2, 2025

maCERT, the Moroccan national cybersecurity agency, has released a critical warning about the newly discovered spyware toolkit, Acreed, which spreads at a high rate over the internet.

Oct 13
The Hacker News

⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More

The most common types of infostealers being used by sellers in Russian Market over the years have been Raccoon, Vidar, Lumma, RedLine, and Stealc, with Rhadamanthys and Acreed gaining popularity in the first half of 2025.

Oct 3
The Hacker News

Rhadamanthys Stealer Evolves: Adds Device Fingerprinting, PNG Steganography Payloads

First advertised by a threat actor named kingcrete2022, Rhadamanthys has emerged as one of the most popular information stealers available under a malware-as-a-service (MaaS) model alongside Lumma, Vidar, StealC, and, more recently, Acreed.

Oct 2
The Hacker News

ThreatsDay Bulletin: CarPlay Exploit, BYOVD Tactics, SQL C2 Attacks, iCloud Backdoor Demand & More

An information stealer known as Acreed is gaining traction among threat actors, with a steady rise in Acreed logs in Russian-speaking forums. The stealer was first advertised on the Russian Market in February 2025 by a user named "Nu####ez" and is assessed to be a private project.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.