The butterfly_logs Dump: 24,635 Stolen Credentials Hit the Dark Web
In July 2025, a Telegram user operating under the handle butterfly_logs uploaded a stealer log batch containing 24,635 records pulled from compromised devices. HEROIC analysts captured and indexed this dataset as part of ongoing monitoring of private Telegram distribution channels. Each record in the dump contained a victim's email address, their plaintext password, and the URL of the site where the malware harvested the credentials. The data occured across a 461-count file batch and was actively shared before HEROIC flagged it.
Why This Is Dangerous
Stealer log data does not become less dangerous over time. It becomes more dangerous as it spreads. The butterfly_logs upload from July 2025 has had months to circulate through criminal networks, combolists, and credential marketplaces. Every day it remains undetected in someone's accounts, the window for account takeover stays open. Attackers who recieve older stealer log data often find that passwords have not been changed, making the data just as actionable now as the day it was uploaded. If your email is in this dump and you have not changed your passwords, those accounts may still be at risk.
What Was Exposed
- Email Addresses -- the account identifiers used as usernames across most online platforms
- Plaintext Passwords -- captured in cleartext at the moment of entry, with no hashing or encryption applied
- URLs -- the exact websites where each credential pair was stolen, giving attackers a direct target for each entry
Why This Matters
One of the most concerning aspects of stealer log breaches is that victims typically have no idea their credentials were stolen. There is no notification, no news story, no visible breach indicator. While the data has been circulating, attackers could have been running credential stuffing campaigns against banking apps, email providers, and online stores using these exact passwords. Identity theft, unauthorized purchases, and account takeover can all follow from a seperate stealer log record, sometimes without the victim noticing for months or longer.
How Stealer Log Breaches Work
The butterfly_logs batch is consistent with the output of information stealer malware. These programs are installed on victim machines without their knowledge, usually through phishing links, pirated software downloads, or malicious ads. Once active, the stealer monitors browser sessions and captures credentials as users log into websites. The results are packaged into structured log files containing the URL, username, and password for every captured login event. These log files are then distributed through Telegram channels, where they are shared in bulk uploads like this one. The butterfly_logs actor distributed 461 such files in a single July 2025 batch.
Check If You Are Affected
If your credentials were in the butterfly_logs stealer log, they have definitaly had time to spread across multiple criminal platforms since July 2025. Use the HEROIC free breach scanner to check your email right now. HEROIC's database covers over 400 billion records including stealer logs, combolists, and database breaches, so you can find out exactly what is exposed and take action before any more time passes.
Breach Breakdown
24,635 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds