Proxy and VPN Users Exposed: SafeSocks5_botMIX Dump Leaked 12,321 Records
HEROIC analysts identified the SafeSocks5_botMIX stealer log in June 2023 while tracking Telegram channels used by credential-harvesting threat actors. The log file contained 12,321 records extracted from endpoint devices compromised by stealer malware. The exposed data includes email addresses, plaintext passwords, and the URLs where credentials were captured, indicating the malware targeted users across multiple online services and platforms.
Why the SafeSocks5_botMIX Log Is a High-Value Attacker Resource
The SafeSocks5 naming convention points toward a log compiled with proxy and network tool credentials in mind. Attackers who obtain logs like this can use embedded URL data to identify high-value targets including VPN services, proxy networks, and cloud platforms. With plaintext passwords already available, these accounts can be accessed immediately. Proxy and SOCKS credentials in particular are used by cybercriminals to mask their own activity, meaning this log can enable further attacks beyond simple account takeover.
What Was Exposed in the SafeSocks5_botMIX Leak
- Email addresses
- Plaintext passwords (no encryption, ready to use)
- URLs of services targeted by the malware
Why This Matters for Network and Account Security
Credential stuffing attacks using logs like SafeSocks5_botMIX are highly automated. Once a log enters circulation on Telegram or dark web forums, it gets loaded into account checker tools that test credentials across dozens of platforms within minutes. Victims face account takeovers, identity theft, and in cases involving proxy or network accounts, their compromised credentials may be used to facilitate further criminal activity. Financial fraud and unauthorized service usage are immediate downstream risks.
How Mixed Botnet Stealer Logs Are Created
The botMIX designation indicates this log was aggregated from multiple botnet infections rather than a single malware campaign. Different stealer variants running across different victim machines send harvested data to a central collector. The combined output is sorted, deduplicated, and packaged for distribution. This mixing process results in datasets that span many geographic regions and service types, making them more valuable to attackers and more dangerous for victims.
Check If You Are Affected by the SafeSocks5_botMIX Breach
HEROIC's breach scanner searches more than 400 billion exposed records and includes stealer log data from sources like SafeSocks5_botMIX. Use the free scanner at heroic.com/breach-scanner to check your email address and determine whether your credentials are in the database.
Breach Breakdown
12,321 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds