Inside Gaming UHQ Part 5 Stealer Logs: 97,710 Passwords
HEROIC identified the fifth volume of a gaming-focused stealer log series, GAMING UHQ PART 5, circulating on Telegram. Dated February 2023, this installment contains 97,710 records of email addresses, plaintext passwords, and URLs extracted from gaming platform users' devices by infostealer malware. As part of a larger multi-part collection, it represents a sustained effort to compile and distribute gaming account credentials.
Technical Anatomy of Plaintext Password Extraction
The 97,710 credentials in this dump exist in plaintext because of how infostealers operate at the browser level. Modern browsers store passwords in encrypted SQLite databases, but the encryption keys are accessible to any process running under the user's session. Infostealers exploit this by calling the browser's own decryption routines to extract passwords in their original form. The result is a log file where every credential appears exactly as the user typed it—no hashing, no intermediate encoding, just raw login data ready for immediate abuse.
What Was Exposed
- Email Addresses — gaming platform accounts and associated email identifiers
- Plaintext Passwords — browser-decrypted credentials in their original, unprotected form
- URLs — gaming service endpoints including platform launchers, web stores, and community portals
Multi-Part Series Amplifies Credential Stuffing Reach
The GAMING UHQ series being released in numbered volumes means this is not an isolated dump but an ongoing campaign to harvest and distribute gaming credentials. Each part adds nearly 100,000 credential pairs to the attacker's arsenal. Credential stuffing operators combine these volumes to create massive attack lists, testing millions of gaming credentials against Steam, PlayStation Network, Xbox Live, Epic Games, and other platforms. Users who reuse gaming passwords on email or financial services become collateral damage in these campaigns.
The Stealer-to-Market Technical Pipeline
The technical pipeline behind GAMING UHQ PART 5 follows a well-documented pattern. Initial access comes through trojanized game modifications, cheat tools, or cracked games that bundle infostealer payloads. Once executed, the malware—commonly RedLine, Vidar, or Lumma—hooks into browser processes to extract the credential database, session cookies, and sometimes Discord tokens and cryptocurrency wallet keys. The raw logs are uploaded to command-and-control servers, then processed through deduplication and validation scripts before being sorted into industry-specific packages like this gaming collection.
Check If Your Credentials Were Exposed
With over 400 billion records in its breach intelligence database, HEROIC provides extensive coverage of gaming-related stealer log leaks and data breaches. Use HEROIC's free breach scanner to check if your email or gaming credentials appear in the GAMING UHQ PART 5 dump or any other compromised dataset. If a match is found, reset your gaming passwords immediately, enable two-factor authentication on all gaming platforms, and check linked payment methods for suspicious activity.
Breach Breakdown
97,710 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds