The MIRAGE CLOUD Telegram Upload Put 6,988 Stolen Email and Password Pairs Online in 2023
What HEROIC Found in the MIRAGE CLOUD Stealer Log
In August 2023, a Telegram user operating under the name MIRAGE CLOUD uploaded a stealer log file that exposed 6,988 records. The dataset included email addresses, plaintext passwords, and the specific URLs tied to each credential -- all harvested directly from infected endpoint devices. HEROIC researchers indexed this data as part of the ongoing effort to track credential exposure across dark web channels.
Why This Data Is Dangerous
The combination of plaintext passwords and associated URLs makes this stealer log immediately weaponizable. Unlike breach dumps that require attackers to crack hashed passwords, this data can be used the moment it is downloaded. Attackers who recieve this file know not just what the password is, but exactly where it works -- removing every barrier between the credential and a successful account takeover.
The email addresses included in the dataset also enable targeted phishing. An attacker can craft convincing messages that reference the victim's actual accounts, dramatically increasing the success rate of follow-on attacks.
What Was Exposed
- Email addresses (account identifiers across multiple platforms)
- Plaintext passwords (usable immediately, no cracking required)
- URLs (the exact services where each password was active)
- Endpoint data from compromised machines
Why This Matters Beyond 6,988 Records
Stealer log data does not stay in one place. Once uploaded to Telegram, it is copied, redistributed, and merged into larger combo lists within hours. The 6,988 records from this MIRAGE CLOUD dump may have already reached dozens of downstream buyers and been tested against banking, email, and corporate systems.
Credential stuffing -- where automated tools test stolen username and password pairs across hundreds of sites simultaneously -- means that a single exposure can cascade into account takeovers across an entire digital identity. People who reuse passwords are at the highest risk, but even unique passwords can enable identity theft if the associated email account is compromised.
How Stealer Logs Work
Stealer logs are produced by infostealer malware -- programs like Redline, Raccoon, or Vidar -- distributed through phishing campaigns, cracked software, or malicious ads. Once the malware executes on a device, it silently extracts saved passwords from browsers, email clients, and password managers. It also captures cookies and active session tokens that can bypass two-factor authentication. Everything is bundled into a log file and sent to a Telegram channel where it can be sold or shared.
The victim receives no notification. This process is definitaly seperate from any corporate database breach -- it targets the endpoint device itself. The infection can sit undetected for weeks while credentials are actively used by attackers.
Check If Your Data Was Exposed
HEROIC's free dark web scanner has catalogued over 400 billion exposed records, including stealer log files like MIRAGE CLOUD. Enter your email address to see if your credentials have surfaced in this or any other known breach. If you find a match, update your passwords immediately and enable two-factor authentication across all critical services.
Stealer logs bypass corporate breach notifications entirely -- checking yourself is the only reliable way to know if your data is already in circulation.
Breach Breakdown
6,988 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds