IQ169.224.33.206: Iraqi Endpoint Stealer Log Leaks 95 Records on Telegram
HEROIC analysts flagged a stealer log linked to the Iraqi endpoint IQ169.224.33.206, which was uploaded to a public Telegram channel on March 15, 2025. The file exposed 95 records containing email addresses, plaintext passwords, and URLs harvested from compromised machines. The data was publicly accessible on Telegram, putting every individual in that log at immediate risk of account compromise.
Why This Is Dangerous
Ninety-five credential pairs with plaintext passwords and associated login URLs give an attacker everything needed to attempt account takeovers without any additional work. The URLs in the log pinpoint the exact services each victim was using, turning this into a precision toolkit rather than a random data dump. Anyone who downloaded this file from Telegram can begin testing these credentials straight away.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (login pages and API endpoints)
Why This Matters
Stealer logs shared on Telegram are a direct pipeline from infected device to active attack. Credential stuffing tools can process dozens of accounts per second, meaning 95 accounts can be tested across hundreds of services in very little time. Victims face account takeover, idenity theft, and financial fraud -- often before they have any idea their credentials were stolen. The linked URLs also expose API keys and backend systems that can be further exploited for corporate breaches.
How Stealer Logs Work
Infostealer malware embeds itself on a target device through phishing links, tainted downloads, or vulnerabilities in outdated software. It then methodically harvests saved passwords from browsers, session tokens, and stored form data. The collected information is bundled into a structured log file and silently transmitted to the attacker. That log is then distributed on Telegram channels frequnted by cybercriminals. The IP address IQ169.224.33.206 marks the infected endpoint as originating in Iraq, providing geographic context for the infection source.
Check If You Are Affected
HEROIC's free breach scanner covers more than 400 billion exposed records and can tell you in seconds whether your email or password appeared in this Telegram stealer log or any other known breach. The earlier you know, the more damage you can prevent.
Search your email for free at HEROIC.com and protect your accounts today.
Breach Breakdown
95 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds