How the 90_Boss Stealer Malware Led to 4,500 Stolen Logins
HEROIC analysts identified a stealer log file named 90_Boss circulating on Telegram, dated to April 2024. The file contains 4,500 records of endpoints, email addresses, and plaintext passwords harvested directly from infected devices by information-stealing malware.
Why the 90_Boss Stealer Log Is Dangerous
This data was pulled straight from victims' browsers rather than scraped from an old database, so the logins inside tend to be current and working. That makes a stealer log like this one more immediately useful to attackers than credentials taken from a years-old breach.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated URLs
Why Malware-Harvested Logins Are Especially Risky
If a device was infected with the malware behind this log, everything saved in that browser at the time, passwords and login pages, could now be in the hands of an attacker. That can lead directly to account takeover, and if any passwords were reused, credential stuffing against other accounts too.
How Malware Like the One Behind 90_Boss Operates
Information-stealing malware typically infects a device through cracked software, fake downloads, or phishing links. Once running, it quietly scans the browser for saved passwords, autofill data, and session cookies, then sends everything back to the attacker. The results are bundled into a "log" and shared or sold under a branded name, in this case 90_Boss.
Check If Your Login Was Captured by the 90_Boss Log
HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records. Run a scan now, and if you find a match, change your passwords and scan your device for malware.
Breach Breakdown
4,500 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds