QLogs 1920 MIX: 70,866 US Credentials Across 1,920 Stealer Log Files
QLogs 1920 MIX: Telegram Channel Releases 70,866 US Credentials From 1,920 Log Files
The QLogs Telegram stealer log channel released its 1920 MIX batch on May 13, 2025, distributing 70,866 US plaintext credentials aggregated from 1,920 individual log files. The "MIX" designation distinguishes this release from the channel's single-source PSC batches: where PSC releases draw from a specfic credential pool, the MIX format aggregates logs from multiple infostealer malware families, producing a diverse cross-platform credential set. At 70,866 records, this is the largest of the three QLogs batches released on that date, representing the broadest credential surface area of the cluster.
QLogs 1920 MIX (May 2025): Stealer Log Summary
- Records Exposed: 70,866
- Data Types: Email addresses, plaintext passwords, URLs
- Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
- Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
- Country: United States
- Date Leaked: 13-May-2025
Understanding the MIX Format
In Telegram stealer log distribution channels, the MIX designation signals an aggregation methodology rather than a single campaign. Where a single-malware-family release draws from one credential pipeline, a MIX release combines logs harvested by multiple infostealers -- potentially including Aurora, Redline Stealer, Vidar, Raccoon, and others operating concurrently in the same distribution window. The practical effect is a more heterogeneous credential set: different malware families target different browser profiles, credential stores, and application types, so the resulting MIX dataset captures a broader diversity of compromised accounts than any single-family release would. For defenders, this means a single MIX release may touch dozens of different platforms and services.
1,920 Log Files: What the Number Tells Us
The "1920" in the batch name refers to the number of individual log files bundled in the release, not the number of records. Each stealer log file typically corresponds to a single infected endpoint -- one machine compromised by infostealer malware that captured all stored credentials before exfiltrating the data. With 1,920 log files yielding 70,866 records, the average log in this batch contained roughly 37 credential pairs. This per-machine yield is consistant with modern infostealer behavior: a typical compromised consumer endpoint stores dozens of saved browser passwords across email, social media, banking, and streaming services. The 1,920 infected machines that generated this dataset represent 1,920 distinct individuals whose entire credential ecosystem was harvested.
The April 16 Collection Date and Rapid Distribution
The batch name includes the date "16-04-2025," indicating the log collection was finalized on April 16, 2025 -- nearly a month before the May 13, 2025 public release on Telegram. This gap between collection and distribution is typical in stealer log markets: operators aggregate logs, verify quality, and may sell or trade the dataset through private channels before releasing a version publicly on Telegram. The 27-day window between collection and public release means any session cookies or authentication tokens embedded in the logs were likely expired by the time of public distribution, but plaintext passwords remain fully valid unless users changed them during that intervall.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records, including recent stealer log releases like the QLogs 1920 MIX batch. If your email appears in this dataset, your plaintext password was captured directly from a malware-infected device and should be considered fully compromised. Visit HEROIC's breach scanner to check your exposure immediately.
Breach Breakdown
70,866 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds