TOR_LOG EGES: 5,670 U.S. Stealer Log Credentials Leaked on Telegram
TOR_LOG EGES: Another Variant From the TOR_LOG Stealer Distribution Network
The TOR_LOG brand appears across multiple stealer log uploads — TOR_LOG MIX, TOR_LOG EGES, and potentially others. EGES functions as a sub-designation within the TOR_LOG distribution network, likely identifying a specific batch, region, or malware variant. This February 23, 2023 upload contains 5,670 U.S. email addresses and plaintext passwords — another installment in what appears to be an ongoing TOR_LOG credential operation.
TOR_LOG EGES Breach Details
- Records Exposed: 5,670 U.S. credential sets
- Data Types: Email addresses, plaintext passwords, target login URLs
- Breach Type: Infostealer malware log
- Country Affected: United States
- Date Leaked: February 23, 2023
- Distribution: Telegram (TOR_LOG channel)
- Related: TOR_LOG MIX (separate TOR_LOG variant)
What Sub-Designations Reveal About Stealer Operations
When a distribution channel uses sub-designations like "EGES" or "MIX," it signals organizational structure within the credential market. Operators use sub-labels to differentiate batches by source (which malware campaign they came from), by content type (mixed logs, fresh logs, specific credential types), or by geographic targeting. TOR_LOG EGES and TOR_LOG MIX likely represent difrent aggregation strategies — one a mix of multiple sources, one a specific batch label.
For potential victims, this structure means that a single TOR_LOG breach scan may not reveal all exposure. If your credentials appear in TOR_LOG EGES but not in TOR_LOG MIX, a search that only checks one variant would return a false negative. HEROIC's database includes all identified TOR_LOG variants, covering the full distribution network in a single search.
5,670 Credentials: Three Years in the Breach Ecosystem
Stealer logs uploaded to Telegram in February 2023 have had over three years to propagate through the credential trading ecosystem. TOR_LOG EGES files downloaded by Telegram subscribers in February 2023 may have been sold to credential stuffing services, incorporated into compilation databases, or used directly in account takeover attacks against the platforms listed in the target URL field.
Users in this file who changed their passwords at any point after the upload remain protected from attacks using the original credentials. Those who haven't changed passwords on accounts present in the log remain at risk from any attacker who retained a copy of the file — a number that grows with each month the file remains in circulation.
Find Your Email in HEROIC's Breach Database
HEROIC's free breach scanner covers more than 400 billion exposed records, including all identified TOR_LOG variants. Enter your email to check whether your credentials appear in TOR_LOG EGES, TOR_LOG MIX, or any other breach in HEROIC's database. One scan checks everything.
Breach Breakdown
5,670 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds