GODELESS CLOUD Stealer Log: 6,986 US Records From a September 2023 Telegram Upload
GODELESS CLOUD: 6,986 US Credentials in the September 29, 2023 Stealer Log Cluster
The GODELESS CLOUD stealer log dataset is the smallest of four uploads released on September 29, 2023 -- a single Telegram upload event that also included STARLINKCLOUD (75,634 records), STARLINKCLOUD2 (61,216 records), and a date-named log with 20,795 records. At 6,986 US credentials, the GODELESS CLOUD dataset is miniscule by comparison, but its inclusion in the September 29 cluster is notable. Small datasets released alongside large ones represent a distinct infection cluster with a separate victim population. The GODELESS CLOUD name, like its STARLINKCLOUD siblings, is likely deliberate obfuscaton designed to make the dataset appear more targeted or interesting to buyers, while the actual data follows the standard stealer log structure: plaintext passwords, endpoint URLs, and API host data from infected US devices.
GODELESS CLOUD (September 2023): Breach Summary
- Records Exposed: 6,986
- Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
- Breach Type: Stealer log
- Password Type: Plaintext -- directly usable with no cracking required
- Country: United States
- Date Leaked: September 29, 2023
Small Dataset, Full Exposure: Why 6,986 Records Still Matters
In the context of a 164,000-record upload cluster, 6,986 records might seem marginal. But for each of the individuals whose credentials appear in the GODELESS CLOUD dataset, the size of the broader cluster is irrelevant. Each of the 6,986 records represents a specific person's email address, plaintext password, and the exact URL where that credential authenticates. There's no cracking step, no credential enrichment required. An attacker with this dataset can begin testing each credential against its mapped endpoint URL immediately upon acquisition. Financial institutions, employer portals, healthcare providers, and subscription services appearing in the endpoint URL data face direct, targeted account takeover risk from every record in this batch.
Cloud-Themed Naming: Threat Actor Branding and Misdirection
The GODELESS CLOUD name is almost certainly assigned by the distributor rather than reflecting the actual breach source. Cloud-themed names like GODELESS CLOUD and STARLINKCLOUD serve two functions in the stealer log marketplace: they suggest the data contains cloud service credentials (increasing perceived value), and they create a legitmate-sounding label that can be referenced across multiple transactions. Security researchers tracking stealer log distributions often use these names as attribution markers to link multiple uploads to the same threat actor, even when the actual data sources differ. The GODELESS CLOUD name's co-release with STARLINKCLOUD and STARLINKCLOUD2 on September 29 suggests they originate from the same distribution network.
September 29, 2023: The Multi-Upload Context
The GODELESS CLOUD dataset's September 29, 2023 upload date places it within a coordinated four-dataset release event that collectively delivered over 164,000 US stealer log records to threat actor networks in a single day. This same multi-upload pattern -- multiple datasets, same channel, same day -- appeared in later campaigns like AuroraLogsTeam's five-batch April 5, 2025 release. The September 29, 2023 cluster may represent an earlier iteration of the same operational approach, suggesting this coordinated release methodology has been a persistent tactic in the stealer log distribution ecosystem for at least 18 months across multiple threat actor groups.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records including stealer log data from the September 2023 GODELESS CLOUD upload cluster. If your credentials were among the 6,986 records in this dataset, they have been in active circulation since September 2023. Check your exposure for free at HEROIC.com now.
Breach Breakdown
6,986 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds