Our Analysts Found the BabaUlpNew Dump Circulating in Telegram Channels
HEROIC analysts found the BabaUlpNew 196 K ULP LINE dataset circulating in private Telegram channels in October 2025. The stealer log file, uploaded by an anonymous Telegram user on October 7, 2025, exposed 65,250 records containing email addresses, plaintext passwords, and URLs that were harvested directly from infected devices. Rather than a single company being breached, this dataset represents credentials silently stolen from tens of thousands of real users' machines by information-stealing malware before being compiled and shared in underground distribution channels.
Why This Is Dangerous
Even at 65,250 records, the BabaUlpNew stealer log represents a serious threat to every individual in it. All passwords are in plaintext, meaning attackers need zero additional work to begin using them. The URLs included with each record show exactly which services each victim used, giving attackers a precise targeting list. One compromised device in this dataset could expose the victim's email, banking, social media, and workplace accounts simultaneously -- especially if they reuse passwords across services.
Data Exposed in the BabaUlpNew ULP LINE Stealer Log
- Email Addresses -- the primary login identifier used to access virtually every online account
- Plaintext Passwords -- ready to use immediately with no decryption, cracking, or additonal processing required
- URLs -- a precise map of which websites and services each victim's browser had stored credentails for
How Attackers Monetize ULP Stealer Log Data
- Credential stuffing: Automated tools test each email and password pair across major platforms, banking sites, and e-commerce stores within hours of the data being downloaded
- Account takeover: Successful logins are converted into locked-out accounts by changing passwords, phone numbers, and recovery emails
- Identity theft: Email account access allows criminals to intercept password reset links and impersonate the victim across services
- Financial fraud: Banking and payment service URLs in the dataset are singled out for immediate account draining attempts
What Is a ULP LINE Stealer Log and How Does It Get Created
ULP stands for URL-Login-Password, describing the exact format of each record in these stealer log files. LINE refers to the line-by-line text structure of the file itself. These files are created entirely by information-stealing malware running on victim computers. The malware, distributed through phishing emails, pirated software, and fake download pages, silently locates and decrypts the browser's saved password database after infecting the machine. It then formats every entry as a URL, username, and password on a single line -- hence ULP LINE -- and transmits the file to attacker servers. These files are then sold or shared freely on Telegram, where distributors like the one behind BabaUlpNew package them in batches and upload them to channels with thousands of subscribers. The entire process from infection to Telegram upload can happen within minutes of a device being compromised.
Find Out If Your Email Is in This Breach -- Free HEROIC Scanner
HEROIC's free breach scanner searches over 400 billion compromised records, including stealer log dumps like the BabaUlpNew 196 K ULP LINE dataset. Enter your email address now to check whether your credentials were harvested and are currently circulating in hacker communities. If your email appears in this or any other breach, change your passwords on all affected services immediately and turn on two-factor authentication to prevent unauthorized access even if your password is already known.
Breach Breakdown
65,250 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds