Dark Web Intel: 6,274 Credentials From the Everlasting_Cloud_2 Telegram Stealer Dump
Dark web monitoring detected a stealer log dump in April 2026 in which a Telegram-based threat actor publicly released 6,274 compromised records tied to Everlasting_Cloud_2 users based primarily in the United States. The exposed data included plaintext passwords, email addresses, and URLs, the typical output of an information-stealing malware campaign. The name Everlasting_Cloud_2 suggests this is a followup to a prior collection, indicating an ongoing operation targeting cloud service users rather than a one-time incident. Threat intelligence analysts who track Telegram channels observed the dump circulating across multiple criminal networks shortly after it was posted.
Why This Is Dangerous
When stealer log data appears on the dark web and Telegram simultaneously, it signals that the threat actor is maximizing distribution to reach as many potential buyers and exploiters as possible. The 6,274 records in this dump represent real user accounts with active credentials. Attackers armed with this data can launch credential stuffing campaigns against hundreds of platforms in seconds using automated tools. Every minute that passes after a dump like this goes live increases the probability that an affected account has already been accessed by an unauthorized party.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (API endpoints and cloud service hosts)
Why This Matters
The sequentially numbered naming convention of this dump, Everlasting_Cloud_2, strongly implies that the threat actor responsible conducted multiple stealer log campaigns against similar targets. Users whose data appeared in Everlasting_Cloud may now find their credentials resurfacing in this second collection. For anyone using the same password across multiple services, the risk is compounded with each new release. Dark web intelligence operatives track these campaigns specifically because repeat actors tend to escalate the scale and frequency of their attacks over time.
How Stealer Log Breaches Work
Information stealer malware operates by installing itself silently on a victim's device, often through phishing lures or trojaned software. It scans for stored credentials in browsers, email clients, and applicaton-specific password stores before packaging the haul into structured log files. These logs are then uploaded to Telegram channles or sold on dark web marketplaces where other criminals purchase access. Unlike server-side database breaches, the victim's device is the point of compromise, meaning the platform whose credentials were stolen may have had no security failure of its own. Detection is difficult because the malware is designed to avoid triggering antivirus software and operates quickly to minimize its window of exposure.
Check If You Are Affected
HEROIC continuously ingests dark web intelligence including stealer log dumps like the Everlasting_Cloud_2 collection. Our free breach scanner covers more than 400 billion exposed records and can tell you instantly whether your email address appears in this dump or any related campaign. Check your exposure now and receive immediate guidance on securing your accounts before further damage occurs.
Breach Breakdown
6,274 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds