NEW DAISYCLOUD Oct 23, 2023: 1,708 U.S. Credentials, 372 Devices
The Second October 23 Drop: 1,708 More U.S. Credentials From 372 Devices
Hours after releasing a 300-PCS batch on October 23, 2023, the DAISY CLOUD [NEW] channel released a second infostealer log containing 1,708 U.S. email and password pairs from 372 infected devices. The second batch was larger -- both in device count and total records -- and maintained a similar 4.59 credentials-per-device yield. Together, the two October 23 releases demonstrate that the NEW DAISYCLOUD operation was allready processing multiple malware-harvested datasets simultaneously, packaging and distributing them in segmented batches rather than a single combined dump.
NEW_DAISYCLOUD 23_OCTOBER_0372_PCS: Breach Summary
- Records Exposed: 1,708
- Data Types: Email addresses, plaintext passwords, target login URLs
- Breach Type: Infostealer malware log (372 PCS)
- Country Affected: United States
- Date Leaked: October 23, 2023
Why Operators Split the Same Day's Data Into Multiple Batches
Releasing the same day's infected-device pool as two separate files -- rather than one combined log -- serves several purposes for Telegram credential operators. First, it creates the appearance of higher activity, giving subscribers the impression that fresh logs are arriving frequentely throughout the day. Second, it allows operators to segment data by source, quality, or target type, with each batch potentially appealing to diferent buyer profiles. Third, smaller and more frequent drops are harder to track and attribute than a single large dump. The DAISY CLOUD [NEW] channel's October 23 dual release prefigures the daily multi-batch cadence it would sustain in March 2024.
The Malware Gap Between October 2023 and March 2024
At 4.59 records per device, the October 23 yield is roughly one-sixth of what the same channel would achieve in its best March 2024 sessions (over 37 records per device). This gap almost certainly reflects changes in the underlying malware configuration. More sophisticatd infostealer variants -- or more targeted deployment against users with dense browser password stores -- can dramaticly increase per-device yield. The five months between October 2023 and March 2024 apparently included significant optimization of the campaign.
Check Your Exposure in HEROIC's Free Breach Scanner
HEROIC's free breach scanner searches across more than 400 billion exposed records, including the full arc of NEW DAISYCLOUD operations from October 2023 through March 2024. Enter your email to see if your credentials appear in this or any other known breach. Credentials from 2023 breaches remain a live threat as long as the original password hasn't been changed.
Breach Breakdown
1,708 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds