The TOR_LOG MIX Dump: 3,587 Stolen Logins Hit the Dark Web
On 28-Jun-2024, a Telegram user uploaded a stealer log named "TOR_LOG MIX 299PCS uploaded by a Telegram User" containing 3,587 records. HEROIC analysts reviewed the file and found it packed with login URLs, email addresses, and plaintext passwords lifted directly from infected machines.
Why This Is Dangerous
What makes a stealer log especially risky is that every credential in it already works. There is no cracking or trial and error involved: malware pulled the login URL, email, and password straight from the victim's own saved passwords, handing an attacker a ready-made key to that account.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the sites and services those credentials unlock
Why This Matters
The real danger of a stealer log is speed: an attacker can move straight to logging in, skipping the guesswork entirely. With 3,587 records bundled into this file, a large number of people risk having accounts elsewhere unlocked too, if they reused the same password.
How Stealer Logs Work
Info-stealing malware works in the background: once it infects a device, it scrapes every password saved in the browser, along with autofill details and session cookies, and quietly ships that data to whoever controls the malware. The resulting package, in this case labeled "TOR_LOG MIX 299PCS", tends to circulate through Telegram channels before it reaches wider dark web forums.
Check If You Are Affected
If you suspect your information might be in this leak, HEROIC's free breach scanner lets you check your email address against more than 400 billion breached records in seconds, so you'll know right away if it's time to update a password.
Breach Breakdown
3,587 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds