670,746 Passwords Exposed in ULP Good by Moon Stealer Leak
On May 3, 2025, a Telegram user uploaded a stealer log file labeled "ULP Good by Moon," exposing 670,746 records of stolen login data. The file contained email addresses, plaintext passwords, and the URLs of the websites those credentials were used on, all pulled directly from malware-infected devices rather than stolen from a single company's servers.
Why This Is Dangerous
This isn't a typical corporate data breach. It's a stealer log, a raw dump of credentials harvested straight from infected computers. That distinction matters because the passwords inside were captured in plaintext, exactly as the victims typed them. There's no encryption to break and no hash to crack. Anyone who downloads this file can try the logins immediately.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the websites the credentials were used on
Why This Matters
More than 670,000 working username-and-password pairs are now circulating on Telegram. Because so many people reuse passwords across multiple sites, attackers routinely take logins from a leak like this and try them against email, banking, and social media accounts elsewhere, a tactic known as credential stuffing. When it works, it leads to account takeover, identity theft, and financial fraud, often before the victim realizes anything was taken.
How This Stealer Log Was Built
Stealer malware typically arrives disguised as cracked software, a fake browser update, or a malicious attachment. Once it's running on a device, it quietly scans the browser for saved passwords, autofill entries, and the web addresses tied to them, then packages everything into a single file and sends it back to whoever controls the malware. That file gets bundled with thousands of others and shared in Telegram channels, exactly like the "ULP Good by Moon" log behind this 670,746-record exposure. The victim's device stays compromised the whole time the malware runs, meaning newly typed passwords can end up in the next log too.
Check If You Are Affected
With a leak this size, the safest move is to check your own exposure directly. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including stealer logs like this one, and tells you instantly if your email address has turned up in a breach. If you find a match, change the password on the affected account right away, avoid reusing it anywhere else, and turn on multi-factor authentication wherever it's offered.
Breach Breakdown
670,746 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds