Inside the ESnew1 Stealer Log: How Malware Harvested 21,345 Passwords
HEROIC analysts identified a stealer log dataset labeled ESnew1, uploaded to a public Telegram channel by an unidentified user. The underlying malware activity is dated December 2, 2021, and the file contains 21,345 individual records pulled directly from infected devices, including email addresses, plaintext passwords, and the URLs victims were logging into when their credentials were captured.
Why the ESnew1 Leak Is Dangerous
This data was not stolen from a hacked database with hashed passwords behind it. It was captured directly off infected computers by information-stealing malware, so every password in this file is plaintext and instantly usable. There is nothing for an attacker to crack. Anyone with a copy of this file can take the exact email, password, and site combination it recorded and log straight into the account.
What Was Exposed in the ESnew1 Records
- Email addresses
- Plaintext (unencrypted) passwords
- URLs of the websites and services each login was used on
Why This Matters for the 21,345 People Affected
Because each record pairs an email, a password, and the exact site it unlocks, this dataset makes direct account takeover simple for anyone who has the file. It also fuels credential stuffing, where attackers try that same email and password combination against banking, email, and social media accounts that were never part of this leak, betting the victim reused it. That reuse is how one stealer log turns into identity theft or financial fraud on completely unrelated accounts.
How the ESnew1 Stealer Log Was Built
A stealer log like this one is generated by information-stealing malware that quietly installs itself on a victim's device, often bundled inside a pirated download, a fake software crack, or a malicious attachment. Once active, it scans the browser for saved logins and autofill data, records the web address each one belongs to, and packages everything, thousands of records at a time, into a single file. That file is sent to a server the attacker controls, then often shared or sold in Telegram channels, exactly where this ESnew1 file surfaced, to build the uploader's standing among other cybercriminals.
Check If You Are Affected
If you're not sure whether an old password of yours is sitting in a leak like this, don't guess. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including stealer logs like this one, and tells you in seconds whether your information has been exposed. Run a free scan now to find out.
Breach Breakdown
21,345 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds