ICELOGSCLOUD 26 August: 7,353 U.S. Stealer Log Credentials (Aug 2022)
Where It Began: ICELOGSCLOUD's August 2022 Release
The ICELOGSCLOUD series of Telegram infostealer releases can be traced back at least to August 26, 2022 -- the earliest known release in the channel's documented activity. The "26 AUGUST - 554 PCS ICELOGSCLOUD" bundle establshd the format that would carry throughtout the series: a release named by date and piece count, containing individual infostealer log files sourced from infected U.S. devices. This first known release contained 554 individual log files and exposed 7,353 U.S. credential records -- enough to establish the operaton as a significant infostealer distribution channel and set the template for the subsequent September 2022 releases.
ICELOGSCLOUD August 26, 2022: Breach Summary
- Records Exposed: 7,353
- Data Types: Email addresses, plaintext passwords, target login URLs
- Breach Type: Infostealer malware log
- Country Affected: United States
- Date Leaked: August 26, 2022
The ICELOGSCLOUD Format: Dates and Piece Counts as Brand Identity
ICELOGSCLOUD's decision to embed date and piece count directly in each release name was unusual in the infostealer marketplace. Most channels used brand names or version numbers -- CRYPTON_LOGS, ATM_LOGS 173, YOULOGS mix726pcs -- without explicitly timestamping their releases. ICELOGSCLOUD's format did the opposite, creating a public ledger of the channel's activity that allows researchers to reconstruct the series timeline. The August 26 release is the begining of that record, followed by September 6 (38,655 records), September 21 (4,303 records), and September 29 (2,166 records). Together these four known releases represent over 52,000 U.S. credential records distributed across approximately five weeks of documented operation.
554 Pieces and What They Tell Buyers
The 554 individual log files in the August 26 release averaged roughly 13 credential pairs per device -- a typical yield for a consumer device with moderate browser credential storage. Buyers could work through the 554 files to identify victims with accounts at specific high-value sites, then target those credentials for account takeover. The U.S.-only focus of the ICELOGSCLOUD releases suggests the operator was specifically filtering for American victims, either because U.S. credentials command higher prices in criminal markets or because the malware campaign was specifically targeting American users. Either way, the August 26, 2022 release put 7,353 American users' login data into the criminal ecosystem in a single upload.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including ICELOGSCLOUD series releases dating back to August 2022 -- to tell you instantly if your email address or passwords have been compromised. Credentials from 2022 remain active threats if passwords haven't been updated since. Run a free scan today at HEROIC.com.
Breach Breakdown
7,353 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds