Skip to content

Malware

ACEHASH

ACEHASH is described by FireEye as combined credential harvester that consists of two components, a loader and encrypted/compressed payload.

ACEHASH is a Windows malware family operated by APT41.

Background

FireEye characterizes ACEHASH as a multi-purpose credential harvester built from two parts: a loader and an encrypted, compressed payload. Running it requires a password (for example, 9839D7F1A0), and its individual modules are selected through parameters such as -m, -w, and -h.


Source: Malpedia (Fraunhofer FKIE).