U.S. Users Targeted: DVDCLOUDFree Exposes 5,124 Passwords
In February 2024, HEROIC tracked a stealer log from the threat actor DVDCLOUDFree being distributed on Telegram. This particular release contains 5,124 records harvested from infected devices across the United States. Each record includes an email address, a plaintext password, and the URL where the credential was captured, providing attackers with everything needed to compromise the associated accounts.
Unencrypted Passwords Put Every Account at Immediate Risk
All 5,124 passwords in this DVDCLOUDFree dataset are stored in their original plaintext form. There is no cryptographic protection, no hashing algorithm, and no encryption standing between an attacker and your login credentials. Anyone who downloads this file from Telegram can begin testing these credentials against live services within seconds, making the time between leak and exploitation dangerously short.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of websites and online services
Credential Stuffing Multiplies the Impact
Each of the 5,124 credential pairs in this dataset becomes a skeleton key when the victim reuses passwords. Automated credential stuffing tools test each email and password combination against hundreds of popular services in parallel. Banking portals, email providers, social media platforms, and cloud storage services are all checked systematically. A single match from this DVDCLOUDFree release can cascade into multiple compromised accounts, especially when the leaked email also serves as the recovery address for other services.
DVDCLOUDFree: A Prolific Stealer Log Distributor
DVDCLOUDFree is a recurring name in stealer log distributions on Telegram, responsible for multiple releases containing credentials stolen through infostealer malware. The malware is typically spread through phishing campaigns, fake software downloads, and malicious advertisements targeting U.S. internet users. Once installed on a victim's device, it extracts all saved browser credentials, cookies, and form data before transmitting the information to the attacker's infrastructure. Each new release from DVDCLOUDFree adds thousands more compromised credentials to the underground ecosystem.
Check If Your Credentials Were Exposed
HEROIC's database contains over 400 billion compromised records from breaches and stealer logs around the globe. Use the HEROIC breach scanner to check whether your email address or password was captured in this DVDCLOUDFree release or any other known compromise. Early detection is essential for preventing attackers from leveraging your stolen credentials against your accounts.
Breach Breakdown
5,124 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds