Breach Intelligence Report 14 May 2026

How the Evolution ULP Free Malware Led to 203,543 Stolen Logins on Telegram

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs Evolution Ulp Free 41 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 203,543
Source Type Stealer log
Origin United States
Password Type plaintext

In March 2026, HEROIC analysts identified a large stealer log file posted to Telegram under the name "Evolution Ulp Free 41." The archive exposed 203,543 records, each formatted as a URL:Login:Password (ULP) triplet -- the website, the email used to log in, and the plaintext password. The "Free 41" designation indicates this is the 41st installment of a freely distributed series from a Telegram channel called Evolution, making it part of a sustained, organized campaign of credential distribution. Over 200,000 people had their login information compiled into this one file alone.


Why the Evolution ULP Free 41 Stealer Log Is Dangerous

Two hundred thousand credential triplets, each with a matching URL, is a significant attack resource. The ULP format is specifically designed for automated credential stuffing -- every record is structured so that a script can read the site, the login, and the password in sequence and immediately attempt a login. No formatting needed. The fact that this is the 41st release in a series also tells us this is not a one-time event. The Evolution channel has been releasing these files systematically, meaning hundreds of thousands of additional credentials have been distributed through earlier installments. Victims of this particular file may have already appeared in earlier Evolution releases as well.


What the Evolution Ulp Free 41 Stealer Log Exposed

  • Email addresses (login identifiers for each compromised account)
  • Plaintext passwords (completely unencrypted, formatted for immediate use)
  • URLs (the exact websites each stolen credential belongs to)

The ULP format -- URL, Login, Password on a single line -- is the standard structure used in credential stuffing attack tools. This file was published in a format optimized for direct use by attackers running automated login campaigns.


Why This Matters: Organized Series Distribution Multiplies the Damage

Most data leaks are one-off events. Evolution ULP Free is a series. That means a coordinated actor or group has been systematically collecting infostealer output and distributing it in numbered batches. Researchers tracking this series have found consistant release patterns, suggesting the channel is backed by an ongoing infostealer infrastructure rather than a single malware campaign. Any credential set in this file has likely been seen by thousands of people in the attacker community. If you find your email in this file, you should assume the associated password has been attempted against every major platform you use.


How the Evolution ULP Malware Led to 203,543 Stolen Logins

ULP-format files originate from infostealer malware campaigns targeting individual devices. The malware installs silently -- usually through pirated software, fake downloads, or phishing links -- and monitors the browser for login activity. Each time the user logs into a site, the malware captures the URL, the email, and the password. The captures are periodically exfiltrated to a collection server and compiled into ULP-format log files. The "Evolution" series appears to represent an aggregation of these captures across multiple malware campaigns, with a Telegram channel acting as the distribution hub. By numbering each release, the operators signal reliability to the attacker community -- making the files more widely circulated than anonymus one-off uploads.


Check If Your Credentials Appeared in Evolution Ulp Free 41

HEROIC indexes over 400 billion compromised records, including stealer log compilations and breach data from across the dark web and private Telegram channels. A free search on HEROIC will tell you whether your email address appeared in this file or any other known breach. No account required. Given the scale and organization of the Evolution series, if your email appeared in this installment it is worth checking whether it also appeared in earlier releases.

Breach Breakdown

Domain Evolution Ulp Free 41 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 May 2026
Check in 5 seconds

203,543 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,664 scanned today
Breach Rank #N/A by affected users
Impact Score
8
sensitivity + scale + recency
Est. Financial Impact $1.5M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance