Criminal service / underground operation
REDX CLOUD
Status: Active
Confidence: Confirmed
REDX CLOUD is a Telegram-centered distribution brand associated with multipart files containing URL-login-password records and stealer-derived credentials. Public analysis documents several large uploads during May–August 2026, but current evidence does not establish that REDX CLOUD develops or operates the infostealer malware responsible for collecting the source data.
INFERENCE (confidence: medium): The current profile should be updated through event-level validation rather than by inheriting capabilities from associated personas, channels or adjacent ecosystems.
Research
Selected OSINT
Stealer Logs: Guide for Security Teams|FlareThe RedX_Cloud Leak: 44,434 Stolen Logins Hit the Dark Web|HEROIC Threat IntelligenceRedX_Cloud Part 3 Leak: 91,809 Stolen Logins|HEROIC Threat IntelligenceRedX_Cloud Part 1 Leak: 50,742 Stolen Credentials|HEROIC Threat IntelligenceRedX Cloud Stealer Log Exposes 80,564 Login Credentials|HEROIC Threat Intelligence