TOR_LOG MIX: 10,642 U.S. Stealer Log Credentials (Sep 2023)
The Day Before the Flood: TOR_LOG MIX and the September 24 Drop
The September 25, 2023 multi-operator release of infostealer logs didn't come from nowhere. One day earlier, on September 24, 2023, the Telegram channel TOR_LOG MIX was already circulatng 10,642 U.S. infostealer credentials through underground markets. The "MIX" label indicates a combined bundle -- credentials obtaind from multiple different infostealer campaigns merged into a single release, rather than logs from a single source. The TOR naming convention suggests an association with Tor network activity or simply a brand choice designed to evoke anonymity and technical credibility. Whatever the branding intent, the 10,642 records were real plaintext credentials captured from infected American devices.
TOR_LOG MIX September 24, 2023: Breach Summary
- Records Exposed: 10,642
- Data Types: Email addresses, plaintext passwords, target login URLs
- Breach Type: Infostealer malware log
- Country Affected: United States
- Date Leaked: September 24, 2023
What "MIX" Format Releases Tell Us About Infostealer Operations
When an operator labels a bundle "MIX," it additionaly signals that the contents are aggregated from multiple sources -- different malware families, different infection campaigns, or different geographic target sets merged and filtered to a single country or credential type. Mix bundles like TOR_LOG MIX are often assembled by brokers who purchase raw logs from multiple operators and repackage them for resale. This layered supply chain means that individual victims in a mix bundle may have been infected by entirely different malware variants and at entirely different times -- the 10,642 records in this release could span infections from weeks or months before the September 24, 2023 upload date.
September 23-25, 2023: A High-Activity Window
TOR_LOG MIX on September 24 was followed by LulzsecCloudLogs and YOULOGS mix726pcs the same day, and then an even larger wave on September 25 from YOU_LOGS, MIRAGE CLOUD, CRYPTON_LOGS, Fire Cloud Free, ATM_LOGS, SatanFireLogs, Wallets_Exodus, FREE LOGS FATECLOUD, GODELESS CLOUD, and Monster Cloud Free. This three-day window represents concentrated underground distribution activity targeting U.S. users -- tens of thousands of credential sets flooding the marketplace across multiple independent channels in rapid succession. For Americans whose devices were infected during this period, the September 23-25 window marked the moment their credentials became available to criminal buyers.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including mixed infostealer bundles like TOR_LOG MIX -- to tell you instantly if your email address or passwords have been compromised. Mix bundles are especially dangerous because they aggregate data from multiple campaigns. Run a free scan today at HEROIC.com.
Breach Breakdown
10,642 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds