80K+ Records: BabaUlpNew Stealer Cache (Oct 2025)
On October 16, 2025, a major stealer malware campaign called BabaUlpNew released 80,140 compromised records through Telegram. The 240K designation in the filename suggests this release is only a sample from a much larger database. The dataset includes email addresses paired with plaintext passwords, system endpoint information, and authentication URLs harvested from infected Windows systems. This represents one of the largest stealer dumps from the Baba malware family.
The Scale of Compromise
An 80,000-record stealer dump affects victims across every major industry and geographic region. The attackers behind BabaUlpNew are operating at an industrial scale, using affiliate networks to distribute malware and harvest credentials from hundreds of thousands of machines globally. The fact that they released only a portion of their data suggests they're holding back an even larger cache for targeted sales or higher-bidding buyers.
What Was Exposed
- 80,140 email addresses across multiple providers
- Plaintext passwords for immediate exploitation
- System endpoint and device fingerprints
- API authentication tokens and URLs
- Browser session cookies and tokens
Why This Matters
The BabaUlpNew breach is dangerouse because it represents actively harvested data from recently infected systems. These aren't old, historical records—they're fresh credentials being used by attackers right now. The 240K file size mentioned in the original name suggests attackers have segmented their database for easier trading. Researchers estimate the full cache contains over 400,000 records from previous releases. If your data appeared in this breach, your accounts are likely already under attack by multiple threat actors.
How BabaUlpNew Operates at Scale
BabaUlpNew is distributed through a sophisticated affiliate network spanning Eastern Europe and Russia. The malware is packaged and rebranded by different affiliates, making attribution difficult. Once installed, it creates a hidden service that continuously exfiltrates credentials, cookies, and system information. The harvested data flows to central servers where it's processed, de-duplicated, and sorted by target profile (consumer email, corporate email, banking credentials) for maximum resale value.
Check If You're Affected
Search the databases below for your email address. If found, assume your passwords have been compromised.
Breach Breakdown
80,140 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds