Targeting SaaS and SSO credentials
Analysis of logs on the Russian market to include Acreed samples reveals that 61% of credentials are tied to software-as-a-service (SaaS) platforms, and 77% include single sign-on (SSO) credentials. These credentials are particularly dangerous because they can provide access to broad enterprise systems when compromised. In Russian Markets, the professional, scientific, and technical services sectors are among the most impacted (30%), followed by the information sector (28%).
Like other malware stealers, Acreed is engineered to exfiltrate high-value data, including saved passwords, cookies, cryptocurrency wallets, and credit card information. Its initial access vectors include phishing emails with malicious attachments or links, "ClickFix" attacks using fake CAPTCHAs, malvertising campaigns promoting cracked or premium software, and malicious tutorials on social platforms like YouTube and TikTok.
Once inside a system, Acreed extracts credentials from browsers such as Chrome, Edge, and Firefox. It hijacks session tokens from cloud platforms including Microsoft 365, Google, AWS, Azure, and Salesforce. This allows them to effectively bypass Multi-Factor Authentication (MFA) and allows the attackers to impersonate users without being detected. Additionally, Acreed collects host-level data including hardware IDs, IP addresses, and software inventories. Acreed employs advanced techniques to evade detection, such as JSON-based exfiltration and Dynamic Link Library (DLL) side-loading. These methods help the malware avoid traditional security measures.
Acreed’s expansive toolbox
Acreed’s impact goes beyond traditional credential theft. By hijacking session tokens, it bypasses MFA and enables lateral movement within enterprise networks. This can facilitate ransomware deployment or advanced persistent threat (APT) operations. A single compromised endpoint may lead to domain-wide breaches, affecting partners and clients.
The rapid emergence of Acreed in the wake of LummaC2's takedown underscores the resilience and adaptability of cybercriminal networks. As threat actors pivot to new tools, the infostealer landscape continues to evolve, placing persistent pressure on organizations to stay vigilant.
Because of Acreed’s expansive toolbox, organizations must not only implement robust preventative controls but also maintain continuous visibility into emerging threats to stay ahead. Bitsight plays a critical role in this effort, offering vendor risk assessments, proactive intelligence, dark web monitoring, and real-time alerts that empower security teams to detect, respond to, and recover from threats like Acreed before they escalate into full-scale breaches. In our 2025 State of the Underground report, Bitsight researchers addressed the most popular malware types on criminal forums, and it’s clear: infostealers aren’t going anywhere anytime soon.
How Bitsight helps defend against Acreed
Bitsight’s solutions are essential for mitigating threats like Acreed:
Recommended defensive actions:
- Prioritize Threat Monitoring
- Why: Acreed spreads quickly via phishing and malvertising. Early detection prevents escalation.
- Bitsight advantage: Real-time IOC tracking and alerting.
- Enhance Your Security Posture
- Why: MFA and software updates block common infection paths.
- Bitsight support: Vendor exposure analysis and posture benchmarking.
- Educate Users
- Why: Users are often tricked into downloading malware from fake ads and social media.
- CTI Insight: Bitsight provides tailored awareness content and briefings.
- Prepare and Test Incident Response Plans
- Why: Quick and informed response limits damage.
- Bitsight value: Real-world threat modeling and scenario planning.
To learn more about using Bitsight to stay ahead of infostealers, talk to our team or check out Bitsight Pulse, your personalized, AI-driven stream of cyber threat intelligence.