How the TOR_LOG MIX Leak Impacts 6,736 Users
HEROIC researchers found 6,736 records on November 10, 2024 from TOR_LOG MIX 299PCS, a stealer log batch uploaded to a public Telegram channel.
Why This Stealer Log Is Dangerous
The TOR_LOG MIX 299PCS batch is a mixed-source stealer dump, meaning credentials come from many different infected devices and target hundreds of sites at once. Because it is delivered as working email, password, and URL triplets, attackers can run automated login attempts against banking, email, corporate SSO, and crypto platforms within minutes of download.
What Was Exposed in TOR_LOG MIX 299PCS
- Email addresses
- Plaintext passwords
- Login URLs and API host endpoints
- Browser autofill and session artifacts from infected endpoints
Why This Matters
Plaintext credentials tied to known URLs make account takeover trivial, especially for anyone who reuses passwords. Mixed stealer batches like this one seed credential stuffing tools, fuel business email compromise, and give initial access brokers fresh inventory to sell onward to ransomware crews.
How a Stealer Log Like TOR_LOG MIX Works
Infostealers such as RedLine, StealC, and Lumma are dropped on victim machines through cracked software, malicious ads, or phishing. They grab saved browser logins, cookies, crypto wallets, and Telegram or Discord tokens, then exfiltrate everything to an operator. Operators bundle logs from many victims into mixed drops like TOR_LOG MIX and publish them for free or for sale on Telegram.
Check If You Are Affected
HEROIC scans 400B+ exposed records across stealer logs, dark web markets, and breach dumps so you can instantly see if your accounts appear in drops like TOR_LOG MIX 299PCS. Run a free HEROIC scan now and lock down any compromised logins.
Breach Breakdown
6,736 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds