TOR_LOG MIX 136pcs uploaded by a Telegram User
We've been tracking an uptick in stealer log aggregations appearing on Telegram channels, and what really struck us wasn't the volume of records, but the increasing specificity of the targets and the clear intent to monetize compromised credentials. The data had been circulating quietly for a few weeks, but we noticed a particular upload – named TOR_LOG MIX 136pcs – that contained a concerning concentration of potentially sensitive information. The setup here felt different because it wasn't just a random assortment of browser data; it appeared curated.
Stealer Log Aggregation Exposes 2,500+ Credentials
In November 2023, a Telegram user uploaded a stealer log file, dubbed TOR_LOG MIX 136pcs, exposing 2,504 records. This wasn't a typical grab-bag of stolen data; the file contained a collection of endpoints, email addresses, API host information, and plaintext passwords. The appearance of plaintext passwords immediately raised a red flag, indicating either poor security practices on the user's part or a sophisticated attacker specifically targeting easily-decrypted credentials. The breach was discovered on November 10, 2023, when the file was initially uploaded to the Telegram channel.
What caught our attention was the structure and content of the log file. It appeared to be a curated selection of data, rather than a raw dump from a single compromised machine. This suggests a targeted approach, where the attacker may have been selectively extracting specific types of information from multiple sources. This matters to enterprises now because it highlights the increasing sophistication of stealer log operations. Attackers are not just collecting data; they are analyzing and filtering it to identify high-value targets and credentials.
- Total records exposed: 2,504
- Types of data included: Email Addresses, Plaintext Passwords, URLs, API Host Information
- Sensitive content types: Credentials, potentially sensitive URLs
- Source structure: Stealer log file
- Leak location(s): Telegram channel
- Date of first appearance: November 10, 2023
External Context & Supporting Evidence
The rise of Telegram as a marketplace for stolen credentials and stealer logs has been noted by multiple security researchers. A recent report by Cyberint details the increasing activity of threat actors on Telegram, using channels and groups to buy, sell, and trade compromised data. They specifically highlight the ease with which attackers can monetize stolen information on these platforms. BleepingComputer has also covered the trend of stealer logs being sold on Telegram, noting the potential for these logs to be used in follow-on attacks, such as account takeovers and ransomware deployments.
Breach Breakdown
2,504 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds