New ArtHouse Cloud v3: Telegram Stealer Log Exposes 62,805 US Records
HEROIC analysts identified a stealer log uploaded to a Telegram channel on January 23, 2025, cataloged as "New ArtHouse Cloud v3." The file contained 62,805 records harvested directly from infected devices, including email addresses, plaintext passwords, and the URLs of the accounts those credentials unlock.
Why This Is Dangerous
Unlike a stolen database of hashed passwords, a stealer log hands attackers working, plaintext logins already matched to the exact website each one opens. There is no cracking required. Anyone who buys or downloads this file can plug the email, password, and URL combinations directly into login pages and see which ones still work.
What Was Exposed in the New ArtHouse Cloud v3 Log
- Email addresses
- Plaintext passwords
- URLs of the associated login pages
Why This Matters for the 62,805 People Affected
Because the passwords in this log are stored in plaintext and paired with the exact site they belong to, they are immediately usable for account takeover. If any of the affected accounts share a password with an email inbox, banking site, or workplace login, attackers can move from one compromised account to the next through credential stuffing. That chain of access is how a single stealer log turns into identity theft or financial fraud.
How a Stealer Log Like This One Gets Created
Stealer logs come from malware quietly installed on a victim's device, often through a pirated download, fake software update, or malicious attachment. Once running, the malware scans the browser's saved credentials and autofill data, then bundles everything it finds, usernames, passwords, and the URLs they were entered on, into a single file. That file is then uploaded to Telegram channels or dark web forums, where it is sold, traded, or given away, exactly as happened with this January 2025 upload.
Check If Your Information Was in This Leak
If you have logged into any account from a device that may have been compromised, it is worth confirming whether your credentials appear in this or any other leak. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including stealer logs like this one, so you can find out quickly and change any exposed passwords before they are used against you.
Breach Breakdown
62,805 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds