How Malware Logs Led to the UHQ MIX Part 5 0930 Password Leak
How Malware Logs Turned Into the "UHQ MIX PART 5 0930" Leak
In May 2023, HEROIC's threat intelligence team traced a stealer log shared on Telegram under the name "UHQ MIX PART 5 0930." The file contained 99,771 records, each one pairing a victim's email address with a plaintext password and the URL of the login page that credential belonged to. Tracing how this data traveled from an infected device to a public Telegram channel shows exactly why it's so dangerous.
Why the Path From Infection to Leak Matters to You
This data didn't come from a company database being hacked. It came from malware sitting quietly on 99,771 individual victims' devices, watching what they typed and saved. That means the password in this file is very likely still the current, working password for that account, since it was captured recently rather than pulled from an old breach. A working plaintext password matched to its exact login URL is about as dangerous as leaked data gets.
What Was Exposed in UHQ MIX Part 5 0930
- Email addresses for 99,771 individual victims
- Plaintext passwords, captured directly from the browser
- URLs identifying the exact login page each credential pair unlocks
Why This Matters However Small the File Looks
Just under 100,000 records is small compared to some stealer logs, but each one represents a real person's working credentials. If your email and password combination is in this file and you've used that same password anywhere else, an attacker can move from this one account into your email, banking, or shopping logins. That kind of reuse is exactly what turns a single stolen password into full account takeover.
How Malware Logs Get Turned Into a File Like This
It starts with information-stealing malware infecting a device, often bundled with cracked software, pirated games, or a phishing attachment. Once running, the malware silently reads every password saved in the browser and the web address it belongs to, then quietly sends that data back to the attacker's server. From there, whoever controls the malware merges logs from thousands of infected machines, sorts them, and releases batches like this one, labeled "Part 5" of an ongoing numbered series, on Telegram.
Check If Your Credentials Are in the UHQ MIX Part 5 0930 Leak
Because this data was likely captured recently, checking your exposure now matters more than with an old, stale breach. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including stealer logs like this one, and tells you instantly if your email address is included. If it is, change that password immediately, avoid reusing it anywhere else, and turn on two-factor authentication wherever it's offered.
Breach Breakdown
99,771 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds