How the Evolution ULP Free Malware Led to 203,543 Stolen Logins on Telegram
In March 2026, HEROIC analysts identified a large stealer log file posted to Telegram under the name "Evolution Ulp Free 41." The archive exposed 203,543 records, each formatted as a URL:Login:Password (ULP) triplet -- the website, the email used to log in, and the plaintext password. The "Free 41" designation indicates this is the 41st installment of a freely distributed series from a Telegram channel called Evolution, making it part of a sustained, organized campaign of credential distribution. Over 200,000 people had their login information compiled into this one file alone.
Why the Evolution ULP Free 41 Stealer Log Is Dangerous
Two hundred thousand credential triplets, each with a matching URL, is a significant attack resource. The ULP format is specifically designed for automated credential stuffing -- every record is structured so that a script can read the site, the login, and the password in sequence and immediately attempt a login. No formatting needed. The fact that this is the 41st release in a series also tells us this is not a one-time event. The Evolution channel has been releasing these files systematically, meaning hundreds of thousands of additional credentials have been distributed through earlier installments. Victims of this particular file may have already appeared in earlier Evolution releases as well.
What the Evolution Ulp Free 41 Stealer Log Exposed
- Email addresses (login identifiers for each compromised account)
- Plaintext passwords (completely unencrypted, formatted for immediate use)
- URLs (the exact websites each stolen credential belongs to)
The ULP format -- URL, Login, Password on a single line -- is the standard structure used in credential stuffing attack tools. This file was published in a format optimized for direct use by attackers running automated login campaigns.
Why This Matters: Organized Series Distribution Multiplies the Damage
Most data leaks are one-off events. Evolution ULP Free is a series. That means a coordinated actor or group has been systematically collecting infostealer output and distributing it in numbered batches. Researchers tracking this series have found consistant release patterns, suggesting the channel is backed by an ongoing infostealer infrastructure rather than a single malware campaign. Any credential set in this file has likely been seen by thousands of people in the attacker community. If you find your email in this file, you should assume the associated password has been attempted against every major platform you use.
How the Evolution ULP Malware Led to 203,543 Stolen Logins
ULP-format files originate from infostealer malware campaigns targeting individual devices. The malware installs silently -- usually through pirated software, fake downloads, or phishing links -- and monitors the browser for login activity. Each time the user logs into a site, the malware captures the URL, the email, and the password. The captures are periodically exfiltrated to a collection server and compiled into ULP-format log files. The "Evolution" series appears to represent an aggregation of these captures across multiple malware campaigns, with a Telegram channel acting as the distribution hub. By numbering each release, the operators signal reliability to the attacker community -- making the files more widely circulated than anonymus one-off uploads.
Check If Your Credentials Appeared in Evolution Ulp Free 41
HEROIC indexes over 400 billion compromised records, including stealer log compilations and breach data from across the dark web and private Telegram channels. A free search on HEROIC will tell you whether your email address appeared in this file or any other known breach. No account required. Given the scale and organization of the Evolution series, if your email appeared in this installment it is worth checking whether it also appeared in earlier releases.
Breach Breakdown
203,543 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds