The Satanic Cloud ULP Dump Contains More Passwords Than the Population of Philadelphia
On December 6, 2024, a threat actor operating under the handle "Satanic" posted five large stealer logs to BreachForums in a single day. This page covers Part 2 of that series, containing approximately 1.8 million unique compromised credentials drawn from a 5-million-line raw log file. The back-to-back release of all five parts on the same day points to a coordinated, high-volume credential distribution operation rather than a one-off opportunistic leak.
This is Part 2 of a 5-part series. See all parts:
Part 1 - Satanic Cloud 5M ULP |
Part 3 - Satanic Cloud 5M ULP |
Part 4 - Satanic Cloud 5M ULP |
Part 5 - Satanic Cloud 5M ULP
Why This Is Dangerous
Stealer logs aggregate credentials harvested from malware infections across thousands of individual devices. Unlike a breach of a single site, the data in this log comes from real users across hundreds of different services, all captured at the moment of login. Every credential in this set was captured in plaintext, meaning attackers have direct, ready-to-use passwords with no cracking step required. The scale of this single release, nearly two million records, makes it a significant source of fuel for automated credential stuffing attacks.
What Was Exposed
The Satanic Cloud 5M ULP Part 2 stealer log exposed the following data types for 1,835,363 unique records:
- Email Address
- Plaintext Password
- HomePage URL (the site each credential was stolen from)
Why This Matters
The combination of email address, plaintext password, and target URL enables a precise and efficient attack chain:
- Credential stuffing: Automated tools test each email-password pair across banking, email, and e-commerce platforms. Plaintext passwords require zero preparation.
- Account takeover: When a password is reused across services, attackers can chain access from one compromised account to others.
- Identity theft: Email account access gives attackers a pivot point to reset passwords on financial and government services.
- Fraud: Access to shopping or payment accounts enables direct financial theft or fraudulent purchases.
- Targeted phishing: Knowing which site a user's credentials were stolen from enables highly convincing impersonation emails.
How Stealer Log Leaks Work
Stealer logs originate from infostealer malware, such as RedLine, Vidar, or Raccoon, that infects individual computers through phishing emails, malicious downloads, or drive-by attacks. Once installed, the malware silently harvests saved browser credentials, form autofill data, and active session cookies. These raw logs are then compiled, deduplicated, and sold or freely shared on dark web forums. The "ULP" designation refers to the URL-Login-Password format, a structured layout that makes the data immediately usable in automated attack tools. The Satanic Cloud series represents a single actor's distribution of a large, pre-compiled log archive.
Check If You Are Affected
If your email address and password appear in this log, any account where you use that same password is at risk right now. Heroic's breach search database covers over 400 billion compromised records, including stealer log data like this series.
Search your email at Heroic to find out immediately if your credentials are part of the Satanic Cloud dumps or any other known data leak.
Related Parts
Breach Breakdown
1,835,363 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds