The THORCLOUD_NEWS Data Quietly Appeared on the Dark Web in May 2023
On May 3, 2023, the THORCLOUD_NEWS Telegram channel posted a free log drop. No announcement beyond the channel itself. No news coverage. Just a file containing 7,152 stolen email addresses and plaintext passwords quietly made available to anyone subscribed to the channel. This is how most credential theft actually works. Not a headline-making breach of a major platform, but a steady, quiet release of infostealer log output pushed to Telegram with minimal fanfare. HEROIC's DarkHive monitoring captured and indexed this upload the same day it was distribted to channel subscribers.
Why This Is Dangerous
Free log distributions are more dangerous than paid ones in a specific way. When credentials are sold, the buyer pool is limited by cost. When they are posted for free on a public Telegram channel, every subscriber can download and use them immediately. Seven thousand, one hundred and fifty-two plaintext passwords, available to an unlimited number of people at no cost. Credential stuffing tools automate the process of testing these pairs against every major service. An attacker does not need to be skilled or resourced to exploit a free log drop. They just need to be subscribed to the right Telegram channel at the right time.
What Was Exposed
- Email Addresses: 7,152 email addresses harvested by infostealer malware from infected user devices
- Plaintext Passwords: Unencrypted passwords captured directly from browser saved credential stores, requiring no cracking to use
- URLs: The specific login pages and services where each credential pair was captured, enabling targeted account takeovers
Why This Matters
The THORCLOUD_NEWS channel uses free releases as a deliberate strategy. By posting thousands of real, usable credentials at no cost, channels like this build subscriber counts, establish credibility, and attract buyers for premium paid tiers. The 7,152 people in this release are not collateral damage from a security incident at a company they trusted. They are the product. Their credentials were harvested, packaged, and distributed as a marketing sample. Meanwhile, those same credentials can unlock email accounts, banking logins, cloud storage, and every other service where the victim reused their pasword. The quiet nature of this release is part of what makes it effective for the people distributing it.
How Stealer Log Breaches Work
Infostealer malware reaches victim devices through phishing emails, trojanized software downloads, fake browser extensions, and malicious ads. Once running, it scans the browser's saved credential store and copies every username, password, and associated URL it finds. The output is compressed into a log file representing everything stolen from that single device. Operators like THORCLOUD_NEWS aggregate these log files from multiple malware campaigns, sort and package them, and distribute them through Telegram. The channel's name combines storm imagery with cloud storage and news broadcast framing, signaling regular, organized distrobution. It is a distribution pipeline, not a single incident.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion exposed records, including the THORCLOUD_NEWS May 3, 2023 free log release and thousands of other Telegram infostealer channel uploads indexed by DarkHive. Enter your email address now to check instantly whether your credentials were part of this release or any other breach in HEROIC's database. The scan is free and requires no account to run.
Breach Breakdown
7,152 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds