TOR_LOG Credential Dump: 892 Records Now in Wild
HEROIC discovered 892 records exposed in the TOR_LOG stealer log breach on February 9, 2023. The base TOR_LOG file was posted to a public Telegram channel and contains emails, plaintext passwords, and associated URLs scraped from infected endpoints.
Why This Stealer Log Is Dangerous
Small logs like TOR_LOG are often the original seed files that later get merged into larger MIX packages. That means these 892 records continue circulating long after the original post, reappearing in combo lists and credential-stuffing feeds for years.
What Was Exposed in TOR_LOG
- Login credentials (usernames, passwords)
- Browser cookies and session tokens
- Autofill form data
- Crypto wallet data (where present)
- System fingerprints
Each record provides a ready-made credential pair plus context about which service it unlocks.
Why This Matters
A small log can still drive large-scale damage when passwords are reused across banking, email, and SaaS accounts. Exposed session cookies also let attackers bypass MFA, and the URL field narrows the attack to known-working targets.
How a Stealer Log Like TOR_LOG Works
Infostealer malware enters a device via cracked software, malvertising, or phishing attachments. It exfiltrates saved browser credentials, cookies, autofill data, and wallet files, then uploads the package to attacker infrastructure. Operators post the raw log to Telegram to attract buyers or build reputation.
Check If You Are Affected
HEROIC monitors the world's largest breach database with over 400 billion compromised records. Run a free scan to see if your email, passwords, or accounts appear in the TOR_LOG leak or other major breaches.
Breach Breakdown
892 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds