The cybercriminal underground is witnessing a dramatic shift with the emergence of Acreed, a new infostealer that is rapidly gaining traction in Russian-speaking forums. According to Intrinsecβs latest report, βwe see the rise of Acreed logs in Russian-speaking forums. Some of our clients are already victims of this new infostealer that will maybe overtake the number one stealer Lumma in the future.β
For much of 2024, Lumma dominated the infostealer market. However, its global takedown in May 2025βwhen Europol and Microsoft seized more than 1,300 domainsβcreated a power vacuum. βStatistics of log offerings shows that threat actors began to move away from Lumma around April 2025, when the surge of Acreed began,β Intrinsec explains.
Although still largely controlled by a single actor known as βNu####ez,β Acreed has already captured 17% of the underground market, positioning itself just behind Rhadamanthys. Analysts warn that its private nature makes it more elusive but also more dangerous if it expands into public distribution.
Intrinsec researchers identified 18 Acreed samples and uncovered innovative C2 domain retrieval methods. Remarkably, the malware leverages both the BNB Smart Chain Testnet and even Steam profiles as dead drop resolvers. As the report details, βthe mechanism of C2 domain retrieval uses the BNB Smartchain Testnet and the Steam platform as dead drop resolvers.β
Acreed logs are intentionally minimal, containing only passwords, cookies, and autofill dataβomitting browser history or downloads. This βsmall footprint,β as Intrinsec notes, represents βa significant increase in discretion as we cannot locate the origin of the infection.β
Beyond credentials, Acreed is aggressively targeting digital assets. Intrinsec highlights that its JavaScript modules act as βclipperβ malware, stealing cryptocurrency by replacing wallet addresses in real time. The researchers warn: βThe script can identify wallets in QR codes and replace them by creating a new QR code that contains the threat actorβs wallet.β
Supported wallets include popular options such as MetaMask, Coinbase, Binance, Phantom, and Ronin, making Acreed especially dangerous for users active in DeFi and NFT markets.
Perhaps most concerning is Acreedβs overlap with the notorious Vidar stealer ecosystem. Intrinsecβs infrastructure analysis found that the C2 domain windowsupdateorg[.]liveβdisguised to mimic Microsoftβs update serviceβresolves to IPs within the same ranges previously tied to Vidarβs management servers.
The report further uncovers connections to ProManaged LLC, a hosting provider registered in Belize with Russian ties and a history of offering βbulletproofβ services. As Intrinsec concludes, βour infrastructure analysis shows that it is also integrated in an existing ecosystem that overlaps with Vidar. It is therefore likely that this malware will spread more and more in the cybercrime community.β
Acreed represents a new breed of infostealerβstealthier, more resilient, and deeply embedded in blockchain-based infrastructure. Its rise signals a shift in the cybercrime economy, where decentralized platforms are increasingly weaponized for persistence and control.
Security professionals should prepare for Acreedβs continued growth, as its evolution suggests it could soon rival or even surpass the dominance Lumma once held.
Related Posts:
- Premium Panel Phishing Toolkit Exposed: Two Years of Global Attacks
- Europol & Microsoft Lead Global Takedown of Lumma Stealer, World’s Largest Infostealer
- Steam to End Support for 32-Bit Windows 10
- Lumma Stealer Resurfaces After Takedown: New Stealth Tactics Target Users via Fake Cracks, CAPTCHAs & GitHub
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.