Your Passwords Could Be Exposed. Alien ULP P747 Leaked 10.9 Million.
HEROIC analysts identified the Telegram alien ULP P747 stealer log on February 14, 2025, after it appeared in a recurring Telegram channel operated by a threat actor using the "alien" alias. The log, labeled TXTLOG_ALIEN - 747, spanned approximately 54.7 million lines of raw data. Deduplication confirmed 10,924,078 unique records, each containing an email address paired with a plaintext password and a homepage URL. This installment is part of a sequential series, arriving one day before the P748 and P749 releases that followed in quick succession.
Why Plaintext Passwords Distributed on Telegram Pose an Immediate Threat
Telegram is not the dark web. It is a mainstream messaging app with millions of users, and distributing stealer logs there means the data reaches a far wider audience than a restricted forum. Any subscriber to the threat actor's channel can download the file within seconds of it being posted. With 10.9 million plaintext passwords immediately available, attackers do not need specialized skills or equipment to begin credential stuffing. The barrier to exploitation is near zero, and the window between log release and active misuse is typically measured in hours, not days.
What Was Exposed in the Alien ULP P747 Log
- Email addresses: 10.9 million unique addresses, functioning as usernames across most web services
- Plaintext passwords: Fully readable passwords captured directly from infected devices, requiring no decryption
- Homepage URLs: Site-specific context for each credential, enabling targeted login attempts
Why This Matters: From One Leaked Password to Full Identity Theft
Password reuse is the attacker's greatest advantage. When a credential from the P747 log matches an account on a financial platform, email provider, or social network, the attacker gains access to far more than one service. A compromised email account becomes a master key: it allows password resets on linked accounts, interception of two-factor authentication codes sent by SMS or email, and impersonation of the victim to contacts. The financial and identity theft consequences can persist for years after the initial compromise. With 10.9 million records in this single log, the probability that a meaningful share of affected users reuse passwords across critical services is statistically high.
How the Alien ULP Stealer Log Series Operates
The P747 log is one part of a larger, ongoing operation. The Alien ULP series distributes numbered batches of infostealer-harvested credentials through a dedicated Telegram channel. Infostealer malware infects endpoints through phishing links, trojanized software downloads, and malicious browser extensions. Once installed, it silently captures every credential saved in the browser, reads active cookies, and records keystrokes during login sessions. The harvested data is packaged into structured log files and transmitted to the attacker, who then aggregates, deduplicates, and releases the data in numbered installments. The sequential numbering of P747, P748, P749, and P750 within days of each other points to an automated or near-automated pipeline operating at scale.
Check If You Are Affected by the Alien ULP P747 Data Leak
HEROIC maintains a breach database of over 400 billion records, including all known installments of the Alien ULP stealer log series. Enter your email address in HEROIC's free breach scanner to find out whether your credentials were part of the P747 release or any related data leak. If they were, you will see exactly what was exposed so you can act immediately, changing passwords, enabling multi-factor authentication, and securing any accounts that share the same credentials.
Breach Breakdown
10,924,078 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds