5,077 Plaintext Passwords Dumped on Telegram via AnubisCloud
HEROIC detected a stealer log file attributed to AnubisCloud_bot posted on Telegram in March 2024. The collection contains 5,077 records, each exposing an email address paired with a plaintext password and the URL where those credentials were originally entered. The data has been freely circulating in threat actor channels since its initial upload.
Plaintext Passwords Are an Open Invitation to Attackers
The passwords in the AnubisCloud_bot dump require no decryption or cracking. They are stored exactly as victims typed them, making exploitation trivially easy. Any person who downloads this file can read every password in plain English and start attempting logins immediately. This is the most dangerous form of credential exposure because it eliminates all technical barriers to misuse.
What Was Exposed
- Email Addresses — login identifiers tied to personal and professional accounts
- Plaintext Passwords — completely unencrypted, human-readable credentials
- URLs — the specific websites where each email-password pair was used
How Credential Stuffing Multiplies the Damage
Armed with 5,077 email-password combinations, attackers use automated tools to test each pair across hundreds of popular services including email providers, financial platforms, and social media sites. This process, known as credential stuffing, succeeds far more often than most people expect because password reuse remains extremely common. A single leaked credential can unlock multiple accounts belonging to the same victim.
The Infostealer Malware Behind AnubisCloud
AnubisCloud_bot is associated with infostealer malware operations that infect devices through phishing links, trojanized software downloads, and malicious browser extensions. Once a device is compromised, the malware silently extracts stored passwords, browser cookies, and autofill data. This stolen information is compiled into log files and distributed through Telegram bots and channels, making it accessible to a wide audience of cybercriminals.
Check If Your Credentials Were Exposed
Your email and password could be among the 5,077 records in this collection. The HEROIC data breach scanner searches more than 400 billion compromised records to help you determine if your data was exposed in the AnubisCloud_bot dump or any other breach. If you discover a match, change your password right away, make sure every account uses a unique password, and enable two-factor authentication for an additional layer of security.
Breach Breakdown
5,077 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds