Inside the Mr_Daadaa Pack: How Stealer Malware Took 4,570 Passwords
HEROIC analysts found a stealer log file labeled "PACK 17-10-2025mr_daadaa" uploaded to a public Telegram channel on October 17, 2025. The file contained 4,570 records pulled from infected devices, pairing email addresses with plaintext passwords and the associated URLs and API hosts those logins connect to.
Why the Mr_Daadaa Pack Leak Is Dangerous
The passwords in this file are stored in plaintext, so there is no encryption standing between an attacker and the account it unlocks. Because each record also lists the URL or API host tied to the credential, an attacker can go straight to the correct login page instead of guessing where a stolen password might work.
What the Mr_Daadaa Pack Leak Exposed
- Email addresses
- Plaintext passwords
- Associated URLs and API hosts tied to each credential
Why This Matters for Anyone Reusing Passwords
Credential dumps like this one are the raw material for credential stuffing, where attackers automate login attempts across banking, email, and social media sites using leaked email and password pairs. If any of the 4,570 people in this leak reused a password elsewhere, they are exposed to account takeover, financial fraud, or identity theft on accounts unrelated to the original infection.
How a Stealer Log Like This One Works
An infostealer is malware that infects a device, often through a malicious download or phishing link, and quietly copies saved passwords, autofill entries, and API access details straight out of the browser. The stolen data is then compiled into a log file and shared, in this case uploaded openly to a Telegram channel by the user behind the "mr_daadaa" pack. Because the credentials come directly from the victim's own browser, they tend to be accurate and current at the time of infection.
Check If You Are Affected
If you think your email might be among the 4,570 records in this leak, HEROIC's free breach scanner can check in seconds. It searches your email against a database of more than 400 billion leaked records, including stealer logs like this one, so you know right away if you were exposed and can update any affected passwords.
Breach Breakdown
4,570 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds