68,821 Plaintext Passwords From the skull_roses Dump Just Surfaced
skull_roses Stealer Log Breach: 68,821 Records Exposed
In June 2025, HEROIC's DarkHive threat intelligence platform detected a stealer log collection shared on Telegram under the handle "skull_roses 1800count." This dataset contained 68,821 compromised records stolen from malware-infected devices, including email addresses, plaintext passwords, and the specific URLs where victims entered their credentials. The log was freely distributed through Telegram channels, giving threat actors immediate access to a large pool of exploitable login credentials.
Why This Stealer Log Is Dangerous
The skull_roses stealer log is dangerous because it delivers ready-to-use credentials at scale. With nearly 69,000 records containing plaintext passwords, attackers face no technical barriers to exploitation. There is no hashing to reverse, no encryption to break. The associated URLs tell criminals exactly which websites and services each password belongs to, eliminating guesswork entirely. This combination allows for rapid, targeted account takeover attacks across email platforms, banking sites, social media networks, and corporate systems. Because these credentials were captured from actively used devices in mid-2025, a significant portion are likely still valid and unchanged.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (login endpoints and web services)
Why This Matters
Credential stuffing remains one of the most effective attack methods, and stealer logs like this one provide the raw material that fuels it. Attackers use automated tools to test stolen email-password pairs across hundreds of websites within minutes. Given that most people reuse passwords across multiple accounts, a single compromised credential from this dump could unlock a victim's email, banking, shopping, and social media accounts simultaneously. Email compromise is particulary dangerous because it gives attackers the ability to reset passwords on connected services, creating a cascading chain of account takeovers. Financial fraud, identity theft, and corporate data breaches are all common outcomes when stealer log data reaches the wrong hands.
How Stealer Logs Work
Stealer logs are created by information-stealing malware such as RedLine, Raccoon, Vidar, Lumma, and Aurora. Victims typically become infected by downloading cracked software, opening malicious email attachments, or visiting compromised websites. Once the malware executes on a device, it harvests saved passwords from all installed web browsers, along with session cookies, autofill form data, and sometimes cryptocurrency wallet keys. The collected information is packaged into structured log files and transmitted to attacker-controlled servers. These logs are then monetized through dark web marketplaces or distributed for free on Telegram channels to build reputation within criminal comunities. Each individual log file may contain credentials for dozens of different websites, all extracted from a single compromised device.
Check If You Are Affected
HEROIC's breach intelligence database indexes over 400 billion records from thousands of known breaches and stealer log distributions. If your credentials were captured in the skull_roses stealer log or any other compromised dataset, HEROIC can help you identify the exposure. Use our free breach scanner to check your email address and take immedite action to change compromised passwords and enable two-factor authentication on your accounts.
Breach Breakdown
68,821 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds