PegasusCloud Jun 3 2025: 43,362 U.S. Credentials in Separate Telegram Infostealer Release
HEROIC's DarkHive intelligence system detected the PegasusCloud June 3, 2025 release, exposing 43,362 U.S. credential records on Telegram. PegasusCloud is a distinct infostealer channel -- seperate from Slurm Logs and NewWlfrCloud -- operating its own malware distribution infrastructure and publishing logs to its own subscriber base. The June 3 release predates the first documented Slurm Logs drop by four days, illustrating how multiple independent infostealer campaigns were running simultaneously in early June 2025. Data types include email addresses, plaintext passwords, and login URLs harvested from infected U.S. devices.
Why This Is Dangerous
PegasusCloud credentials are especially dangerous because the passwords are plaintext -- captured directly from the victim's device before any hashing or encryption is applied. Anyone recieving this data gets the exact password the victim typed, requiring no cracking tools. Thier combination of email, exact password, and target login URL turns each record into an instant account access package. Victims are often unaware their device was compromised until attackers have already taken over accounts.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- Login URLs
Why This Matters
With 43,362 records, PegasusCloud's June 3 release represents a significant standalone exposure, independent of the larger Slurm Logs campaign running concurrently. Victims who reuse passwords across seperate services face risk on every platform where that password was used. Once an attacker controls an email account, they can reset access to banking, shopping, and workplace systems. Affected individuals should immediatly change passwords on all accounts associated with the exposed email and enable two-factor authentication wherever possible.
How Stealer Logs Work
Stealer logs are produced by infostealer malware spread through phishing emails, pirated software, and malicious browser extensions. Once running on a victim's device, the malware silently extracts saved credentials from browsers and applications, then sends them to attacker-controlled servers. PegasusCloud operators compiled these records and distributed them through their Telegram channel. Unlike the Slurm Logs campaign, which ran for over two months, PegasusCloud's documented activity in the DarkHive dataset centers on discrete releases through mid-2025.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like PegasusCloud. Visit heroic.com to scan your email address and find out if your information was exposed in this June 2025 stealer log release.
Breach Breakdown
43,362 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds