AuroraTeamSupport Dropped 16,605 Stolen Credentials on Telegram
HEROIC analysts detected a stealer log upload on a public Telegram channel on November 7, 2025. The file was posted by the actor AuroraTeamSupport and carried the batch label 539count, indicating it was part of a series of coordinated credential dumps. The upload exposed 16,605 records, each containing an email address, a plaintext password, and a service URL captured directly from infected endpoints. The scale and structure of this dump suggests automated collection across a wide range of compromised devices.
Why This Is Dangerous
AuroraTeamSupport does not just collect credentials at random. The batch numbering across their dumps points to organized, ongoing operations. Attackers who get access to this file have a polished list of over 16,000 usable logins with the target services already identified. Credential stuffing campaigns can be launched against these accounts within hours of the file going live. Users who reuse passwords across platforms face compounded risk: one stolen password can unlock banking, email, and cloud storage simultaneously.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (API hosts and service endpoints)
Why This Matters
Over 16,600 people's login credentials were placed into the hands of anyone monitoring Telegram for these drops. That means credential stuffing, account takeover, identity theft, and fraud are all live possibilities for everyone in this dataset. Victims frequently do not realise they have been breached until unauthorized charges appear, their email is locked, or their identity is used to open fraudlent accounts in their name.
How Stealer Log Breaches Work
Infostealer malware is typically delivered through pirated software, fake browser extensions, or malicous links in email. Once it runs on a device, it searches for saved passwords in every major browser and sends them to the attacker along with the URLs of active sessions. The victim's device looks and behaves completely normally throughout. The attacker then compiles hundreds or thousands of these individual logs into batch files like the AuroraTeamSupport 539count dump, which are then shared on Telegram or sold on underground markets. Most people whose data ends up in these logs never receive any notification.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion exposed records, including stealer log batches like this AuroraTeamSupport dump, and tells you immediately if your email or password has been compromised. If your credentials appear in the 539count upload or any other breach in our database, you need to act now. Check your email for free at HEROIC's breach scanner.
Breach Breakdown
16,605 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds