13,210 U.S. Credentials Leaked in NEW DAISYCLOUD Feb 5, 2024 New Password Stealer Log
DarkHive detected a breach from the DAISY CLOUD [NEW] Telegram channel on February 5, 2024. The stealer log release, labeled 05_FEBRUARY_0829_PCS_New_Password, was harvested from 829 compromised U.S. endpoints and exposed 13,210 records. The leaked data includes plaintext passwords, email addresses, and service and API host URLs captured at the time of infection. The breach date is recorded as February 5, 2024.
Why This Is Dangerous
At 829 infected devices, this is one of the larger single-day releases in the DAISYCLOUD New Password series. The scale of the device harvest means a wide range of services and platforms are represented in the exposed credentials. Because these logs capture recently changed passwords, victims who updated thier login credentials around this time may still find their new passwords included in this release. Threat actors can aquire this data and use it for targeted account takeover attacks across email, cloud, and financial platforms.
What Was Exposed
- Email addresses
- Plaintext passwords
- Service and API host URLs
Why This Matters
The DAISY CLOUD [NEW] campaign distributes stealer log archives through a Telegram channel on a near-daily basis, making each release part of a compounding threat. Victims of the Feb 5 drop may also appear in earlier or later DAISYCLOUD releases, meaning they could recieve multiple exposures across seperate log bundles without realizing it. The campaign's consistent output throughout early 2024 reflects a highly organized and active infostealer operation.
How Stealer Log Infections Work
Infostealer malware is distributed through phishing campaigns, cracked software, and malicious browser extensions. Once active on a device, it silently captures credentials stored in browsers and applications and transmits them to the operator. The DAISY CLOUD [NEW] operator packages thier harvested logs into dated archive files named with device counts and distributes them via Telegram. Victims typicaly discover their exposure only when breach monitoring tools flag their credentials.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from stealer logs like NEW DAISYCLOUD. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
13,210 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds