ACEHASH
- Malware type
- credential-stealer, loader
- Profile updated
- 2026-07-07 12:56:56
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
ACEHASH is described by FireEye as combined credential harvester that consists of two components, a loader and encrypted/compressed payload. To execute, a password is necessary (e.g. 9839D7F1A0) and the individual modules are addressed with parameters (-m, -w, -h).
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Acehash_Auto (yara-rule)
Reports & references
- secureworks.com — Bronze Atlas (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Acehash (report)
- Mandiant — Game Over Detecting And Stopping An Apt41 Operation (report)
- ESET — No Game Over Winnti Group (report)