How Malware Led to 1,268 Stolen Hotmail Logins
HEROIC's threat intelligence team identified a stealer log file titled "Hotmail Valid by MrAwexx" shared on Telegram in December 2025. This dataset traces a clear path from malware infection to credential theft: infostealer malware harvested Hotmail login credentials from 1,268 infected devices, and a threat actor known as MrAwexx then validated each credential to confirm it was still active. The result is a curated list of 1,268 confirmed-working Hotmail accounts ready for exploitation.
Validated Plaintext Passwords Are Immediately Exploitable
Unlike bulk credential dumps where many entries may be outdated, every one of the 1,268 passwords in this file was verified to work at the time of compilation. The passwords are stored in plaintext with no encryption. This combination of validation and plaintext storage means attackers face zero friction. There is no guessing, no cracking, and no testing required. Each credential is a confirmed working key to a real Hotmail account.
What Was Exposed
- Email Addresses — active Hotmail accounts verified by the threat actor to be accessible
- Plaintext Passwords — working passwords confirmed through automated validation testing
- URLs — the login pages and web services where credentials were originally captured
Credential Stuffing With Verified Data Is Devastating
When credential stuffing campaigns use pre-validated data, their success rate skyrockets. Attackers know these 1,268 Hotmail email-password combinations work, so they focus on testing them against high-value targets like online banking, enterprise email, and cloud storage services. Because Hotmail accounts are deeply integrated into the Microsoft ecosystem, a compromised Hotmail password may also unlock access to OneDrive, Skype, Xbox Live, and any third-party service where the victim registered with their Hotmail address.
Tracing the Attack: From Infection to Telegram
The journey of each credential in this dataset began with a malware infection. A victim downloaded a compromised file, clicked a malicious link, or installed a trojanized application. Infostealer malware activated on their device, silently extracting saved passwords from their browser's credential store, recording login keystrokes, and copying session cookies. The raw stolen data was compiled into log files and transmitted to the malware operator. MrAwexx then processed these logs, filtering for Hotmail accounts and running automated scripts to verify which credentials were still valid. Only the confirmed-active entries made it into this final distribution file.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence database contains over 400 billion records from data breaches, stealer logs, and dark web marketplaces. Use the HEROIC breach scanner to check whether your Hotmail email or password appears in the MrAwexx validated dump or any other breach. Because these credentials were confirmed active, the risk of account takeover is elevated. Change your Hotmail password immediately if you find a match, and ensure you are using a unique password not shared with any other service.
Breach Breakdown
1,268 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds