The MetaCloudVipNew Part 4 Log Gave Hackers Everything They Need to Drain Accounts
HEROIC analysts identified Part 4 of the MetaCloudVipNew stealer log series uploaded to Telegram in March 2026. This installment contained 2,702 records extracted from compromised devices, including email addresses, plaintext passwords, and the URLs of the accounts from which those credentials were harvested. This file is one segment of a larger multi-part release from the same threat actor who distributed Part 1 of the same campaign, indicating an organized and sustained operation against users of cloud-connected services.
The MetaCloudVipNew Part 4 Log Gave Hackers Everything They Need to Drain Accounts
Stealer log data is optimized for immediate use. The 2,702 records in this file include not just credentials but the exact destination where each one works. An attacker holding this file does not need to run broad guessing campaigns or test logins across random sites. They already have a map. Email accounts can be accessed and used to reset passwords on banking or financial platforms. Cloud storage accounts can be raided for personal documents, business files, and any additional credentials stored there. Connected subscriptions and services linked to the same email can be compromised in sequence. The plaintext nature of the passwords removes the last barrier to exploitation.
What Was Exposed in This Leak
- Email Addresses
- Plaintext Passwords
- URLs (the exact accounts and services targeted by the malware)
Why This Matters for Account Takeover and Downstream Fraud
Even at 2,702 records, this file is operationally significant. Credential stuffing campaigns do not require millions of records to be effective. A small, targeted file with URL pairings and plaintext passwords produces a much higher success rate than a large dataset of hashed or cracked credentials. Victims in this log face account takeovers, unauthorized financial transactions, identity theft, and the risk that attackers use their compromised accounts to target contacts with phishing messages. The multi-part nature of this release also means affected users may appear across multiple files in the same series.
How Multi-Part Stealer Log Campaigns Work
When a threat actor uploads a log file series in numbered parts, it usually indicates one of two things: either the total dataset is too large to share as a single file, or the actor is releasing data in installments to maintain engagement within a Telegram channel or underground community. The MetaCloudVipNew series describes itself as coming from 3,850 infected PCs, and Part 4 represents one segment of that larger harvest. Each part draws from a different subset of the compromised machines, meaning this file's 2,702 records overlap minimally with those in Parts 1, 2, and 3. The malware responsible for this collection targets cloud service credentials specifically, harvesting logins saved in browsers and applications on infected devices and packaging them into structured log files for distribution.
Check If You Appear in the MetaCloudVipNew Log Series
HEROIC tracks multi-part stealer log campaigns from Telegram channels as part of a breach database covering more than 400 billion exposed records. If your email address was in any segment of the MetaCloudVipNew series, including Part 4, our free breach scanner will identify it. Search your email at HEROIC's breach lookup tool to see your full exposure across all known data leaks.
Breach Breakdown
2,702 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds