How IN103.82.77.32 Stealer Log Exposed 51 Accounts on Telegram
HEROIC analysts found a stealer log posted to a public Telegram channel on March 10, 2025, tied to the source identified as IN103.82.77.32 uploaded by a Telegram User. The file exposed 51 records containing email addresses, plaintext passwords, and URLs. The presence of API host endpoints alongside raw credentials pointed directly to compromised device-level access, where malware had already done its work before anyone noticed.
Why This Is Dangerous
With 51 sets of email addresses, plaintext passwords, and API URLs in hand, an attacker has everything needed to log in directly to affected accounts and connected services. API credentials are particularly risky because they often bypass the normal login page entirely, giving automated tools direct access to backend systems, databases, and stored files without triggering standard security alerts.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (including API host endpoints)
Why This Matters
Credential stuffing, account takeover, and identity theft all become much easier when passwords are stored in plain text. Attackers don't need to crack anything. They simply take the credentials and test them against popular services. If a victim reused that password on their bank, their email, or their employer's systems, every one of those accounts is now at risk. Even fraud and financhial theft become likely when someone has unrestricted access to your email, since password resets for other accounts flow through it.
How Stealer Logs Happen
This breach followed the classic infostealer attack path. A device connected to the IN103.82.77.32 network was compromised by malware, most likely delivered through a phishing link, a trojanized software download, or a malicious browser extension. Once installed, the malware silently harvested everything it could find: passwords saved in the browser, credentials entered into login forms, and session tokens. The entire haul was packaged as a log file and exfiltrated to the attacker, who then uploaded it to a public Telegram channel where anyone could access it. The compromised users likely had no idea any of this ocurred.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion compromised records, including stealer logs like this IN103.82.77.32 file. If your email address or passwords were part of this exposure, you need to know now before attackers act on it. Scan for free at HEROIC's breach scanner and take control of your digital security today.
Breach Breakdown
51 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds