ACEHASH

Malware type
credential-stealer, loader
Profile updated
2026-07-07 12:56:56

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

ACEHASH is described by FireEye as combined credential harvester that consists of two components, a loader and encrypted/compressed payload. To execute, a password is necessary (e.g. 9839D7F1A0) and the individual modules are addressed with parameters (-m, -w, -h).

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Acehash_Auto (yara-rule)

Reports & references

  • secureworks.com — Bronze Atlas (report)
  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Acehash (report)
  • Mandiant — Game Over Detecting And Stopping An Apt41 Operation (report)
  • ESET — No Game Over Winnti Group (report)

External references