← All datasets

red.develmakss.shop

Aug 7, 2026

17,776,402
Records
2
Files
Aug 7, 2026
Added

A credential dump distributed via a Telegram channel (@redcloud_link) and associated service 'RED PRIVATE CLOUD' operated by threat actor 'DevelMakSS'. Contains two files: one with email:password combos for Hotmail/Outlook/MSN/Live accounts (Mail Access), and one with URL:login:password combos (ULP format) harvested from infostealer logs. Data covers multiple countries (EU/DE/PL/FR/IT) and includes credentials for services like Netflix, Spotify, PayPal, Discord, Roblox, Epic Games, and more. The operator embeds self-promotional handles and obfuscated seller/bot account strings throughout the file to advertise their credential-selling service.

Data found in this dataset

Email

Search this dataset

Scoped to this dataset. Fill any combination — results match if any field hits.

Source files

Expand any file to inspect its column headers and the LLM's field-mapping reasoning, recorded during ingestion.

redcloud__FORUM_RED_Mail_Access__redcloud_link.txt
2,489 rows

File structure

Notes: Pre-LLM auto-detection: free-form text with visible emails / phones

redcloud__FORUM_RED_ULP__redcloud_link.txt
2 columns17,773,913 rows

File structure

Source columnMapped fieldConfidenceLLM assessment
1emailhighcombo identifier column — values parse as email addresses
2passwordhighcombo secret column — value adjacent to the email identifier

Notes: Heuristic auto-detection: credential combo list