5,937 Passwords From the MIRAGE CLOUD Dump Just Hit the Dark Web
In June 2023, 5,937 plaintext passwords were dumped to the dark web when a Telegram user uploaded the MIRAGE CLOUD stealer log file. The records, extracted directly from infected devices, included email addresses, active plaintext passwords, and the URLs of services the victims were using at the moment of compromisal. The MIRAGE CLOUD label suggests this data was assembled under a coordinated operation rather than a random one-off upload, and the breach was verified by HEROIC researchers.
Why This Is Dangerous
Every one of the 5,937 records in the MIRAGE CLOUD dump is a working credential pair. These are not hashed passwords that need cracking or old credentials that may have been rotated. Stealer logs capture passwords in plaintext as they are typed or retrieved from browser storage. Attackers who accessed this dataset on Telegram had immediate, ready-to-use logins to whatever services appear in the URL field of each record. The damage potential multiplies further when victims reuse the same password accross multiple platforms.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
Why This Matters
The MIRAGE CLOUD dump is one of hundreds of stealer log packages uploaded to Telegram in 2023 as part of a massive expansion in the stolen credential economy. Telegram has become the primary marketplace for this type of data because of its ease of use, large group sizes, and resistance to takedown. The 5,937 records in this upload feed directly into credential stuffing attacks, account takeover schemes, and spear phishing campaigns tailored to victims whose full email and service history is now known to attackers.
How Stealer Logs Work
The malware behind uploads like MIRAGE CLOUD typically arrives through phishing emails disguised as invoices or shipping notices, cracked software from torrent sites, or fake browser updates. Once the malware is exicuted on a victim's device, it systematically harvests saved passwords from Chrome, Firefox, Edge, and other browsers, extracts session cookies, and records keystrokes. The collected data is packaged into log files and uploaded to Telegram within hours of infection.
Check If You Are Affected
HEROIC's free breach scanner searches across more than 400 billion exposed records, including the MIRAGE CLOUD stealer log from Telegram. Enter your email address to instantly check whether your credentials were captured in this breach or any of the thousands of other verified data exposures in HEROIC's database. If your data is there, you will know in seconds.
Breach Breakdown
5,937 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds