Stealer Log 289: 4,655 Infected-Device Records Leaked to Telegram
Incident Overview
In March 2023, an anonymous Telegram user released stealer log 289, publishing 4,655 credential records extracted from devices infected with information-stealing malware. The archive contained plaintext passwords, matching email addresses, and the full login URLs where each credential was harvested, handing attackers a complete map of accounts ready for compromise.
What Was Exposed
- 4,655 endpoint credential records
- Email addresses and usernames
- Plaintext passwords captured from browsers
- Login URLs and API host endpoints
- Potential session tokens, cookies, and autofill data
Inside the Infected-Device Pipeline
Stealer logs like 289 originate from consumer devices infected through malicious downloads, pirated software, or phishing lures. Once installed, infostealer malware silently scrapes every saved credential, cookie, and wallet file from the victim's browser before exfiltrating the data to command servers. Operators then anonymize the output and release it to Telegram channels, where it is free or cheap to acquire.
MFA Bypass Through Stolen Session Artifacts
The most underappreciated risk in stealer log 289 is the inclusion of session cookies and OAuth tokens alongside the 4,655 password records. Attackers import these artifacts into clean browser profiles to impersonate victims without triggering MFA prompts, because the target service sees an already-authenticated session. Password rotation alone will not kick out an attacker who has hijacked an active session.
Response Steps for Affected Users
- Sign out of all sessions on email, banking, and cloud accounts
- Rotate passwords only after verifying the source device is clean
- Enable hardware security keys or passkeys for phishing-resistant MFA
- Audit connected OAuth applications and revoke unfamiliar ones
- Deploy a password manager to replace browser-stored credentials
Check Your Exposure in HEROIC's Database
HEROIC's threat intelligence platform maintains over 400 billion compromised records, sourced from public breaches, dark web marketplaces, and the Telegram stealer log ecosystem that produced log 289. Visit HEROIC.com for a free exposure check against your email or domain, and secure any compromised accounts before attackers finish weaponizing this dump.
Breach Breakdown
4,655 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds