red.develmakss.shop
Aug 7, 2026
A credential dump distributed via a Telegram channel (@redcloud_link) and associated service 'RED PRIVATE CLOUD' operated by threat actor 'DevelMakSS'. Contains two files: one with email:password combos for Hotmail/Outlook/MSN/Live accounts (Mail Access), and one with URL:login:password combos (ULP format) harvested from infostealer logs. Data covers multiple countries (EU/DE/PL/FR/IT) and includes credentials for services like Netflix, Spotify, PayPal, Discord, Roblox, Epic Games, and more. The operator embeds self-promotional handles and obfuscated seller/bot account strings throughout the file to advertise their credential-selling service.
Data found in this dataset
Source files
Expand any file to inspect its column headers and the LLM's field-mapping reasoning, recorded during ingestion.
redcloud__FORUM_RED_Mail_Access__redcloud_link.txt2,489 rows
File structure
Notes: Pre-LLM auto-detection: free-form text with visible emails / phones
redcloud__FORUM_RED_ULP__redcloud_link.txt2 columns17,773,913 rows
File structure
| Source column | Mapped field | Confidence | LLM assessment |
|---|---|---|---|
| 1 | high | combo identifier column — values parse as email addresses | |
| 2 | password | high | combo secret column — value adjacent to the email identifier |
Notes: Heuristic auto-detection: credential combo list