Our Analysts Found the ic3l0gs.part04 Dump Circulating in Private Telegram Channels
In August 2023, HEROIC analysts discovered the ic3l0gs.part04 stealer log circulating inside a private Telegram channel. This file is one installment in a multi-part credential distribution campaign and contained 345 records, each pairing a stolen email address with a plaintext password and the URL of the targeted service.
The ic3l0gs series represents a coordinated, ongoing credential harvesting operation rather than a single breach event. Part04 is a distinct file with its own set of victims and compromised accounts. If your email address appears in this dataset, an attacker has your exact password for a specific service, ready to use without any additional work.
What the ic3l0gs.part04 Log Contained
- Email Addresses: Account identifiers used to access the compromised services
- Plaintext Passwords: Unencrypted passwords captured directly from infected devices
- URLs: The exact login endpoints and cloud service addresses where each password was stolen
Our Analysts Found the ic3l0gs.part04 Dump Circulating in a Telegram Channel
HEROIC's threat intelligence team monitors underground channels, dark web forums, and private Telegram groups where stolen credentials are bought, sold, and freely distributed. The ic3l0gs campaign was identified when analysts noticed a series of numbered log files being dropped into one of these channels in rapid succession.
The part04 file was part of that series. The structured naming convention, sequential numbering, and consistent data format all point to an automated or semi-automated operation where malware was deployed at scale, logs were collected centrally, and the resulting files were distributed in batches. This is not the work of an opportunistic amateur. It is an organized credential theft pipeline.
Once a log like this is posted to Telegram, it spreads fast. Other actors download it, load it into credential stuffing tools, and begin testing the email and password pairs against popular platforms. Victims face account takeover, unauthorized purchases, identity theft, and in some cases, attackers using the compromised email account to pivot into even more sensitive systems. The 345 accounts in this particular file were immediately at risk the moment it was shared.
Why Stealer Logs Are Harder to Defend Against Than Traditional Breaches
Most people think of data breaches as something that happens to companies, not to them directly. A stealer log flips that assumption. The malware that produced ic3l0gs.part04 did not breach a corporate database. It infected individual devices and stole passwords that were never stored on any company's server. It bypassed server-side security entirely.
This means that even if every company you use has perfect security, your credentials can still end up in a stealer log if your own device is compromised. The malware typically arrives through phishing emails, cracked software, fake browser extensions, or drive-by downloads from malicious sites. Once installed, it quietly harvests everything before being exfiltrated. Many users never recieve any indication that anything is wrong.
The time between infection and publication can be weeks or months. By the time ic3l0gs.part04 appeard in a Telegram channel, some of the affected accounts had likely already been accessed. That is why regular breach monitoring matters even when you haven't clicked anything suspicious recently.
Scan Your Email Against the ic3l0gs.part04 Log for Free
HEROIC's breach scanner indexes more than 400 billion records, including the full ic3l0gs series and thousands of other stealer logs, combolists, and dark web database dumps. If your email appeared in part04 or any related file in this campaign, our tool will flag it immediately.
Run a free search with your email address to find out your exposure status. If there's a match, update the affected password right away and check every other service where you've used the same credentials. Two-factor authentication adds a critical second layer of protection that can stop an attacker even if they have your password.
Breach Breakdown
345 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds