AuroraLogsTeam 678count: 38,480 US Records Exposed in April 2025 Stealer Log
AuroraLogsTeam's April Push: The 678count Stealer Log
The AuroraLogsTeam campain, initially tracked through a concentrated March 2025 deployment of US-targeted stealer logs, did not end with March. On April 10, 2025, a new AuroraLogsTeam batch surfaced on Telegram -- 678 infescted devices yielding 38,480 records of email addresses, plaintext passwords, endpoint URLs, and API host data. This upload, recieved just four days before the separate AlphaFreeLogs campaign launched, represents a significant continuation of AuroraLogsTeam's operational pattern into April.
AuroraLogsTeam 678count (April 2025): Breach Summary
- Records Exposed: 38,480
- Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
- Breach Type: Stealer log
- Device Count (PCS): 678 infected devices
- Password Type: Plaintext -- directly usable with no cracking required
- Country: United States
- Date Leaked: April 10, 2025
Credential Density: 57 Records Per Infected Device
The 678count batch yields approximately 57 credential records per infected device -- a density metric that falls in the mid-range for AuroraLogsTeam batches. This suggests devices with moderate browser credential store populations: users with active online presence across a moderate number of authenticated platforms, but not the power users seen in denser batches. Mid-density batches are particularly valuable for credential stuffing because they tend to contain a higher proportion of active, regularly-used credentials rather than the stale or test credentials sometimes found in very high-density dumps.
At 57 records per device, each compromised machine contributes a meaningful volume of actionable credentials -- email/banking/streaming/SaaS combinations that remain valid for immediate stuffing operations.
April Continuation: What It Means for the Campaign Timeline
The April 10 upload confirms that AuroraLogsTeam maintained operational cadence beyond its primary March 2025 deployment window. The campaign's March activity (March 17-27) was characterized by high-frequency uploads, sometimes multiple batches per day. The April continuation suggests a secondary distribution phase -- possibly drawing from the same pool of compromised endpoint data, or from fresh infections collected during April.
Crucially, this April 10 batch arrived just four days before the AlphaFreeLogs campaign launched on April 14, 2025. The overlap zone between these two campaigns creates a concentrated period of US-targeted stealer log activity that significantly amplified the overall credential exposure for American users during this period.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address appears in known data breaches, including stealer logs from the AuroraLogsTeam campaign. Run a free scan at HEROIC.com to identify any ongoing credential exposure.
Breach Breakdown
38,480 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds