The 270931_MA Telegram Stealer Log Exposed Moroccan Account Credentials in June 2023
HEROIC analysts identified a stealer log file posted to Telegram in June 2023 linked to a Moroccan IP address (105.74.5.248). Catalogued as 270931_MA_105.74.5.248_07-06-23, the file contained 3 records including email addresses, plaintext passwords, and URLs identifying the services victims were using when the malware struck. The log was distributed through Telegram networks where stolen credential files are routinely traded by threat actors targeting users in North Africa and beyond.
Why the 270931_MA Stealer Log Is Dangerous
Plaintext passwords in this log require no additional work from an attacker. Each record includes a verified email address paired with a working password, ready to be tested against banking, social media, and webmail services. For users in Morocco, where cybersecurity incident reporting is less common, this type of exposure can go undetected for months while attackers silently drain accounts or sell the access onward.
What Was Exposed in 270931_MA_105.74.5.248_07-06-23
- Email addresses
- Plaintext passwords
- URLs (services and sessions active on the infected device)
Why This Matters
Stealer log data from Moroccan endpoints feeds into regional credential markets where attackers specifically seek accounts tied to local banks, telecoms, and government services. Even a small number of exposed records can result in financial fraud, unauthorized access to personal accounts, identity theft, and downstream compromise of other people or organizations the victim communicates with online.
How the 270931_MA Stealer Log Reached Telegram
Stealer malware silently infects a device, copies credentials from the browser, and packages them into a log file. That file is automatically sent to the attacker's server and then uploaded to Telegram, where criminal channels distribute it to buyers. Logs are often labeled with country codes like MA so buyers can quickly identify records from specific regions. The 270931_MA log followed this pipeline from infection to public distribution before HEROIC captured and indexed it.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion exposed records, including stealer logs like 270931_MA that circulate in Telegram criminal channels. If your credentials were captured in this or any related breach, a free HEROIC scan will surface it immediately. Check your exposure now before it becomes an active account takeover.
Breach Breakdown
3 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds