2,300+
Domains seized in the May 2025 law enforcement takedown of LummaC2 infrastructure, led by Microsoft's Digital Crimes Unit with DOJ, Europol, and Japan's JC3
100,000+
Acreed logs listed on Russian Market by mid-2025, up from a handful in early 2025, per Webz.io tracking of underground forum listings
$2
Starting price for a single infostealer log on Russian Market; prices scale up sharply based on what credentials and sessions the log contains
Q1 2025
When ReliaQuest researchers first observed Acreed had already surpassed most established stealers in Russian-market volume, trailing only LummaC2 itself

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

Two other guides on this site cover infostealer malware from angles that matter but are not this angle. The infostealer malware defense guide (/blog/infostealer-malware-defense) covers how stealer malware infects endpoints and how to detect and prevent that infection. The corporate credentials response workflow (/blog/corporate-credentials-infostealer-logs-response-workflow) covers what to do when your organization's own credentials turn up in a stealer log. Neither one asks the question this piece asks: what does the underground market that resells those logs actually look like right now, who dominates it, and what does that market structure imply about how a security team should spend its account takeover defense budget.

That question has a real answer, and it changed materially in 2025. LummaC2 was the dominant infostealer family feeding the Russian Market log economy through late 2024. In May 2025, Microsoft's Digital Crimes Unit, the US Department of Justice, Europol, and Japan's Cybercrime Control Center jointly executed a takedown that seized more than 2,300 domains tied to LummaC2's infrastructure. That takedown did not shrink the log economy. It reshuffled it. A stealer called Acreed, barely tracked by researchers before the takedown, grew from a handful of logs to more than 100,000 listed on Russian Market within months. Understanding why that happened, and which stealer families now actually supply the market, is the analytical work this piece does that the other two do not attempt.

The LummaC2 takedown created a vacuum, not a vacancy

It is tempting to read a law enforcement takedown as the end of a threat. That is rarely how the infostealer market works, and it was not what happened here. According to Microsoft and the FBI's own disclosures, LummaC2 had been used in roughly 1.7 million instances of credential theft, with Microsoft researchers identifying over 394,000 infected Windows machines in just the two months preceding the action. That is the scale of demand the takedown removed from the supply side, not the demand side. Buyers who relied on LummaC2 logs for account takeover, ransomware initial access, and fraud did not stop needing fresh credentials the week the domains were seized. They needed a new supplier.

Acreed is the family that stepped into that gap fastest. Recorded Future News reported that ReliaQuest researchers had already observed Acreed surpassing most established infostealers in Russian-market volume by the first quarter of 2025, trailing only LummaC2 itself, before the takedown even happened. That timing matters for the analysis: Acreed was not a scrappy newcomer that got lucky after a rival's disruption. It was already positioned as the clear second-place option in a market that had one dominant supplier. When that supplier's infrastructure was seized, the buyers who needed replacement inventory had an obvious place to go.

One caution for practitioners doing their own threat intelligence tracking: Acreed is a distinct malware family from ACRStealer (sometimes referenced as Acrid), a separate stealer that also shows up in AhnLab ASEC's monthly infostealer trend telemetry. The naming similarity has caused confusion in some secondary reporting. When you are reading a vendor report or building a detection rule set, confirm which family a source is actually describing before you act on it.

How fast Acreed actually grew, and what that tells you about the market

The growth numbers reported for Acreed are worth sitting with because they describe how quickly an underground market can reallocate supply once a dominant player's channel closes. Webz.io's tracking of underground forum listings found Acreed logs went from dozens of listings in early 2025 to more than 100,000 by mid-2025. That is not organic malware propagation on the timescale enterprise security teams are used to reasoning about. It reflects an operator (or operators) scaling distribution and infection specifically to capture displaced demand, and it reflects buyers on Russian Market treating stealer brand as substitutable: what matters to them is fresh, sellable logs, not loyalty to a specific malware family.

Capability profile matches the money

Reporting on Acreed describes it as extracting browser-stored credentials, session cookies, system fingerprinting data (HWID, IP, installed software), and cryptocurrency wallet data, with particular attention to SaaS and SSO sessions, the exact credential types that enable direct account takeover against Microsoft 365, Google Workspace, AWS, and Salesforce without needing to touch a password at all.

The market rewards volume and freshness, not sophistication

Acreed's rise was a distribution and market-positioning story more than a novel-technique story. There is no public reporting establishing that Acreed uses meaningfully different evasion or persistence techniques than the stealer families it displaced. What changed was supply availability at the moment demand spiked.

LummaC2 did not disappear

AhnLab ASEC's own monthly infostealer trend telemetry through 2026 continued to show LummaC2 among the most-distributed families well after the May 2025 takedown, alongside Vidar and other established stealers. Treat the takedown as a disruption that reshaped market share, not an elimination. Security teams that assumed LummaC2-specific indicators went stale after May 2025 were wrong.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

A multi-family market, not a monopoly

The practical mistake would be replacing one mental model, "LummaC2 dominates," with another, "Acreed dominates," when the actual 2026 picture is a market with several active suppliers whose relative share moves month to month. AhnLab ASEC's monthly infostealer trend reports through 2026 have repeatedly shown LummaC2, Vidar, and ACRStealer among the most heavily distributed families by telemetry volume, with the specific ordering shifting from one report to the next. Acreed's rise is best understood as adding a new major supplier to that rotation rather than replacing it outright.

StealC and Vidar remain relevant comparison points for a different reason: they represent the longer-running, more institutionally stable end of the infostealer-as-a-service market. Vidar in particular has been a fixture of underground credential markets for years, which is itself informative. A market this liquid does not require the newest malware to win. It requires whichever operator can currently deliver fresh, high-volume, reliably formatted logs. That is a commodity market dynamic, and it means defenders should expect the name at the top of the list to keep changing without the underlying attacker behavior against your environment changing much at all.

How logs actually get bought and sold

Russian Market is the reference point most threat intelligence reporting uses for how this economy functions mechanically, and the mechanics explain why speed matters more than almost any other defensive variable.

Logs are sold per infected machine, not per credential

A single log bundles everything harvested from one infected endpoint: browser-saved passwords, active session cookies, autofill data, system fingerprint, and sometimes cryptocurrency wallet files. Buyers are purchasing an infected identity's entire browser footprint in one transaction, not a single password.

Pricing starts low and scales with content, not just presence of data

Reporting on Russian Market pricing describes logs sold for as little as $2, with prices climbing well beyond that based on what the log actually contains. A log with active corporate SSO session cookies or access to financial platforms is worth substantially more to a buyer than one containing only stale personal-account passwords, and marketplace listings are searchable by country, browser, malware family, and sometimes specific domains present in the log, letting buyers filter directly for the highest-value inventory.

Freshness is the primary value driver

A session cookie's usefulness decays the moment it expires or is revoked, and a password's usefulness decays the moment the account owner rotates it. Because of that decay, buyers pay a premium for recently harvested logs and marketplaces are structured around continuous new-listing volume rather than a static inventory. This is also why Acreed's ability to scale distribution quickly translated directly into market share: a stealer that cannot maintain a steady flow of fresh logs loses relevance fast, regardless of its technical capability.

Buyers specialize by use case

Ransomware affiliates searching logs for VPN and RDP credentials, fraud operators searching for financial platform sessions, and initial access brokers searching for corporate SSO footholds are drawing from the same log inventory but filtering for different fields. The same Acreed log could feed three completely different attack types depending on who buys it.

What this market structure means for ATO defense prioritization

None of the above changes what an infostealer does to an infected endpoint. It changes how a defender should prioritize response once a log is confirmed or suspected to exist, because the market's own economics tell you which credential types get exploited fastest and which detection signals are worth paying for.

Session token invalidation cadence should be measured in hours, not in the next password-rotation cycle

Because session cookies are the fastest-decaying and therefore fastest-monetized item in a log, any confirmed or suspected infostealer infection should trigger session revocation across identity provider, SSO, and high-value SaaS applications immediately, in parallel with forensics, not after it. A password reset alone leaves an active, still-valid session cookie sitting in a log a buyer may already own.

Dark web and log-marketplace monitoring should triage by log contents, not by stealer family name

Given that the dominant supplying family rotates (LummaC2 to Acreed, and whatever comes next), a monitoring program built around alerting on named families will always be a step behind. Prioritize monitoring and triage rules around the presence of your organization's SSO and SaaS domains within any log, regardless of which malware harvested it.

SSO and SaaS session credentials deserve the fastest response SLA

The market's own pricing behavior, paying more for logs containing corporate SSO and platform sessions, is a direct signal of which credential types attackers move on quickest after purchase. Build your incident response runbook's priority order around what the market pays for: identity provider sessions and SaaS admin sessions first, followed by VPN and remote access credentials, with browser-saved personal-account passwords a lower and slower priority.

Treat takedown announcements as a market signal, not a closure signal

When you see reporting on a major infostealer family being disrupted, the correct defensive response is to increase, not decrease, monitoring sensitivity for the next 60 to 90 days. That window is exactly when displaced demand is most likely to produce a rapid volume spike from whichever family fills the gap, as happened with Acreed after May 2025.

The bottom line

The infostealer log economy behaved exactly like a commodity market when its dominant supplier was disrupted: price and volume reallocated to the next capable seller within months, and the underlying demand for fresh corporate credentials and session cookies never dropped. Acreed's rise after the May 2025 LummaC2 takedown is the clearest recent evidence that defenders cannot treat a takedown as resolution, and cannot build detection programs anchored to a single malware family's indicators. The market tells you what to prioritize even when it does not tell you which stealer will be on top next quarter: fast session invalidation, log-content-based monitoring instead of family-name-based monitoring, and response SLAs ordered by what buyers actually pay the most for, which is live SSO and SaaS sessions, not old browser passwords.

Frequently asked questions

What is Acreed and why is it significant?

Acreed is an infostealer malware family that grew from a minor player to one of the most heavily listed stealers on Russian Market during 2025, reportedly reaching over 100,000 logs by mid-2025 after starting with only a handful earlier that year. Its significance is timing: its growth accelerated sharply after the May 2025 law enforcement takedown of LummaC2 infrastructure, making it the clearest example of how quickly the underground log market reallocates supply when a dominant family is disrupted.

Did the LummaC2 takedown actually reduce infostealer activity?

The May 2025 takedown seized over 2,300 domains tied to LummaC2's infrastructure and disrupted its operations at the time, but AhnLab ASEC's monthly infostealer trend telemetry through 2026 continued to show LummaC2 among the most heavily distributed families afterward, alongside Vidar and other stealers. The takedown reshaped market share and created room for Acreed's rise; it did not eliminate LummaC2 or reduce overall infostealer log volume in the market.

Is Acreed the same malware as ACRStealer?

No. Acreed and ACRStealer (sometimes referenced as Acrid) are distinct malware families that are sometimes confused because of their similar names in secondary reporting. AhnLab ASEC's telemetry tracks ACRStealer separately from Acreed, and security teams should confirm which specific family a source is describing before using it to inform detection rules or threat intelligence.

How much does a stolen credential log cost on underground markets?

Reporting on Russian Market pricing describes logs starting as low as $2 per infected machine, with prices scaling up significantly based on what the log contains. Logs with active corporate SSO or SaaS session cookies, financial platform access, or other high-value data command a substantial premium over logs containing only stale personal browser passwords.

Why do session cookies matter more than passwords in this market?

Session cookies represent an already-authenticated session, including a completed MFA challenge, so a buyer who acquires one can access the account immediately without needing to authenticate at all. Because a session cookie's value disappears the moment it expires or is revoked, buyers pay a premium for freshly harvested logs, and that pricing pressure is exactly why session token invalidation, not just password rotation, needs to be the fast, immediate response to any confirmed infostealer infection.

How should security teams prioritize account takeover defense given this market structure?

Prioritize fast session invalidation across identity provider and SaaS applications the moment an infostealer infection is confirmed or suspected, build dark web and log monitoring around the presence of your organization's domains in log contents rather than around specific malware family names, and order incident response SLAs by what the market itself pays the most for: live SSO and SaaS sessions first, VPN and remote access credentials next, and browser-saved personal passwords last.

Sources & references

  1. Webz.io: Acreed Infostealer: Everything We Know So Far
  2. The Record (Recorded Future News): Acreed infostealer poised to replace Lumma after global crackdown
  3. Microsoft On the Issues: Disrupting Lumma Stealer
  4. The Hacker News: FBI and Europol Disrupt Lumma Stealer Malware Network
  5. AhnLab ASEC: Infostealer Trend Reports (monthly)
  6. ReliaQuest: The Infostealer Pipeline: How Russian Market Fuels Credential-Based Attacks
  7. BleepingComputer: 'Russian Market' emerges as a go-to shop for stolen credentials

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.