HEROIC Traced Cloud_Rolex_2 Part 2: 6,132 Stealer Records Exposed
Cloud_Rolex_2 is part 2 of the Cloud_Rolex stealer channel series, a Telegram-distributed infostealer feed that HEROIC threat researchers traced to an April 2026 dump of 6,132 records containing plaintext passwords, email addresses, and the URLs those credentials unlock. The follow-up release confirms Cloud_Rolex operators are running an ongoing pipeline, not a one-off leak.
Why Cloud_Rolex_2 Is Dangerous
HEROIC classified Cloud_Rolex_2 as high risk because it is a fresh April 2026 release, meaning the credentials inside are likely still valid on many services. Plaintext passwords combined with URLs give attackers an immediate, targeted way to compromise webmail, banking, cloud, and corporate accounts without any cracking step. A volume two dump also confirms the operators have a reliable malware distribution chain feeding the channel.
What Was Exposed
The 6,132 records in Cloud_Rolex_2 include email addresses, plaintext passwords, and the full URL each credential was captured at. HEROIC analysts noted a mix of consumer services like webmail, streaming, and social networks alongside business portals such as SaaS dashboards and corporate SSO endpoints.
Why It Matters
Because Cloud_Rolex_2 is part of a numbered series, anyone exposed in volume one should assume continued risk in this release. HEROIC tracks these recurring channels because they feed the combo lists behind modern credential stuffing, business email compromise, and ransomware reconnaissance campaigns. Acting quickly between dumps is the only way to limit damage.
How the Attack Works
The Cloud_Rolex pipeline begins with infostealer malware pushed through cracked software, fake updates, malicious browser extensions, and phishing attachments. Once deployed, the malware silently dumps browser-saved passwords, autofill data, cookies, and crypto wallets, then ships them to the operator. HEROIC observed the operator packaging the April 2026 haul into Cloud_Rolex_2 and posting it on a Telegram distribution channel for downstream buyers.
Check If You Were Affected
If you saved passwords in a browser on any device that touched cracked software, suspicious downloads, or phishing links in early 2026, assume potential exposure in Cloud_Rolex_2. Rotate reused passwords, enable multi-factor authentication on every critical account, and run a full anti-malware scan before trusting the device again.
HEROIC's identity monitoring indexes more than 400 billion breached records, including the Cloud_Rolex series that HEROIC threat research actively tracks. Run a free scan to confirm whether your credentials appear in Cloud_Rolex_2 or any related Telegram stealer dump inside the HEROIC database.
Breach Breakdown
6,132 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds