NEW DAISYCLOUD Feb 9, 2024 Stealer Log Exposes 8,927 U.S. Credentials from 622 Devices
In February 2024, DarkHive detected a stealer log file uploaded to Telegram by the DAISY CLOUD [NEW] channel under the label NEW_DAISYCLOUD 09_FEBRUARY_0622_PCS_New_Password_on_channel. The file exposed 8,927 records harvested from 622 compromised endpoints across the United States, containing email addresses, plaintext passwords, and service URLs. The February 9 release is one of the earliest known drops in the DAISYCLOUD "New Password" series, establishing the pattern of daily releases that the campaign maintained through mid-March 2024. The breach date was recorded as February 9, 2024.
Why This Is Dangerous
The February 9 DAISYCLOUD release exposed 8,927 records from 622 devices, representing an average of 14.3 credentials per device. Despite being one of the lower per-device record counts in the series, the data includes plaintext passwords and service URLs that are immediately actionable for credential stuffing attacks. The DAISYCLOUD campaign's free Telegram distribution means these credentials reached an uncontrolled number of subscribers within hours of the upload, and any of those subscribers can attempt to aquire accounts at the platforms identified in the service URL field. Early-series logs like this one also benefit from being among the first to expose specific victims, before competing attackers have had a chance to drain the affected accounts.
What Was Exposed
- Email addresses
- Plaintext passwords
- Service and API host URLs
Why This Matters
The February 9 release marks the beginning of a months-long DAISYCLOUD campaign that would go on to expose hundreds of thousands of U.S. credentials through daily Telegram uploads. The campaign's longevity demonstrates the operational persistence of organized infostealer distribution networks and the challenges they pose for individual victims who have no way to monitor whether their credentials have appeared in these logs. For organizations, the campaign underscores the importance of enforcing multi-factor authentication across all external-facing systems, since plaintext passwords from stealer logs bypass all protections that rely solely on password knowledge. Individuals who seperate their personal and work accounts and use unique passwords for each service limit the damage from any single log entry.
How Stealer Log Infections Work
Infostealer malware is the primary engine behind campaigns like DAISYCLOUD. Distributed through phishing emails, fake software cracks, and malicious browser extensions, the malware silently captures credentials from browser storage and active login sessions. The DAISY CLOUD [NEW] operator aggregates these records from multiple infected devices and releases daily log files on Telegram labeled with the harvest date and device count. Victims typicaly remain unaware their credentials were captured until they notice suspicious account activity or recieve an alert from a breach monitoring service.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from stealer logs like NEW DAISYCLOUD. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
8,927 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds