KR121.132.131.54 Telegram Leak: 114 Korean Stealer Log Records Exposed
HEROIC analysts discovered a stealer log file uploaded to Telegram on March 14, 2025, linked to the Korean IP address KR121.132.131.54. The file, shared by an anonymous Telegram user, exposed 114 records containing email addresses, plaintext passwords, and URLs harvested directly from infected devices. While the record count may seem small, the presence of unencrypted passwords makes every single record immediately actionable for attackers.
Why This Is Dangerous
When passwords are stolen in plaintext, there is no cracking required. An attacker can take those email and password combos and start testing them against Gmail, banking apps, Amazon, and other popular services within minuets of getting their hands on the file. The included URLs also reveal exactly which sites and services the victims were logged into, giving attackers a ready-made target list.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (sites and services accessed by victims)
Why This Matters
Stealer log data is some of the most dangrous information circulating on dark web channels. Once your credentials are in a log like this, they get bundled, sold, and reused across dozens of platforms. Attackers use the exposed email and password pairs for credential stuffing, where bots automatically test logins across hundreds of websites. Successful hits lead to account takeovers, idenity theft, drained financial accounts, and fraud committed in your name.
How Stealer Logs Work
A stealer log is created by malware silently installed on a victim's computer or phone. Once active, the malware records everything the user types or saves in their browser, including usernames, passwords, and the addresses of websites they visit. All of that information gets packaged into a log file and sent back to the attacker. The attacker then sells or shares those logs in bulk through platforms like Telegram, dark web forums, or private hacker communities. The KR121.132.131.54 log is a direct example of this process: a compromised device in Korea, credentials harvested, and the data shared publicly.
Check If You Are Affected
HEROIC's free breach scanner searches over 400 billion exposed records, including stealer logs like this one. Enter your email address to see if your credentials have been compromised and take action before an attacker does.
Breach Breakdown
114 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds