5,723 berserklogs Accounts Exposed – Plaintext Passwords Included
We noticed an unusual data dump surfaced on a public Telegram channel on April 3rd, 2022, originating from a user identified as "300 LOGS.MARCH." This file, a stealer log, contained a concerning amount of user credential information. What struck us was the direct exposure of plaintext passwords alongside email addresses and associated URLs, indicating a sophisticated compromise rather than a simple database leak. The sheer volume of records, while not astronomical, represents a significant risk given the nature of the exposed data.
The "berserklogs" incident, as it's been informally labeled, involved the exfiltration of a stealer log file uploaded to Telegram. This log contained 5723 distinct records, each detailing an endpoint, an associated email address, and critically, plaintext passwords. The inclusion of URLs suggests these credentials were tied to specific web services or applications accessed by the compromised endpoints. The threat theme here is clear: credential harvesting through malware, likely a stealer trojan, which then indiscriminately logs and transmits sensitive user information. The direct upload to a public channel amplifies the immediate risk of these credentials being weaponized for further attacks, such as account takeover or credential stuffing.
While this specific incident hasn't garnered widespread media attention, the broader trend of stealer malware and its role in data breaches is well-documented. Security researchers frequently publish reports detailing the modus operandi of various stealer families, such as RedLine, Vidar, and Raccoon Stealer, which are known to target and exfiltrate credentials from web browsers, email clients, and other applications. The exposure of plaintext passwords, as seen in the "berserklogs" data, aligns with the capabilities of these prevalent malware strains. The ease with which such logs can be distributed via platforms like Telegram underscores the persistent threat of malware-driven data exfiltration, often serving as an initial foothold for more complex cybercriminal operations.
Breach Breakdown
5,723 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds