Malware Harvested 7.8 Million Logins in the HUNTER_ULP Stealer Log
On November 1, 2025, a stealer log with the clunky name HUNTER_ULP PRIVATE NEW BASE landed on Telegram, and buried inside it were 7,830,257 individual login records. That number puts it among the larger dumps HEROIC has tracked recently, and how it got that big is worth explaining.
Why This Is Dangerous
Malware infections happen quietly, one device at a time, but they add up fast when criminals combine thousands of infected machines into a single "combo" file. Nearly 8 million records in one place means this file definately gives attackers a massive, ready-made list to run automated login attempts against banks, email providers, and online stores.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated login URLs
- 7,830,257 total records exposed
Why This Matters
At this scale, credential stuffing attacks become highly efficient for criminals. They can imediately test millions of email and password pairs against popular websites within hours, and even a small success rate still means tens of thousands of hijacked accounts.
How It Happened
Each record in HUNTER_ULP began as malware sitting on an individual victim's computer, quietly copying saved browser passwords and the sites they unlock. Those thousands of small individual thefts were then merged by whoever operates this Telegram channel into one enormous "ULP" file, short for username, password, and login combination.
Check If You Are Affected
Given the size of this leak, checking your own exposure only takes a few seconds. HEROIC's free breach scanner searches a database of over 400 billion leaked records so you can see immediately whether your email shows up here or elsewhere.
Breach Breakdown
7,830,257 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds