385PCSOTTOMANCLOUDBOTBONUS uploaded by a Telegram User
We noticed a recent upload to a public Telegram channel on December 30, 2025, containing a stealer log file. What struck us was the direct exposure of plaintext credentials, a recurring theme in recent credential stuffing campaigns. The dataset, identified as originating from "385PCSOTTOMANCLOUDBOTBONUS," appears to be a snapshot of compromised endpoint data. The relatively small pwned count of 4404 records suggests a targeted or nascent infection vector, rather than a widespread campaign. However, the inclusion of API hosts alongside email addresses and passwords elevates the risk profile significantly.
The stealer log, uploaded by an anonymous Telegram user, details 4404 compromised records. The data types exposed include email addresses, plaintext passwords, and associated URLs, likely representing the compromised endpoints or services. The source structure indicates a stealer malware's exfiltration output, capturing active sessions and credentials. The inclusion of API hosts is particularly concerning, as these can serve as direct entry points into other systems or services that rely on those credentials for authentication. This type of data is highly valuable for threat actors seeking to escalate privileges or move laterally within an organization's infrastructure.
While specific news coverage on this particular stealer log is limited, the broader trend of stealer malware proliferation is well-documented. Numerous cybersecurity research firms, including Mandiant and CrowdStrike, have published extensive reports on the increasing sophistication and prevalence of information-stealing malware. These reports consistently highlight the danger posed by plaintext credential exposure, particularly when coupled with API endpoint information, which can facilitate automated attacks and bypass multi-factor authentication mechanisms if not properly secured.
Breach Breakdown
4,404 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds