The Many Faces of ModernStealer: Tracing an Underground Military Data Network

Underground data markets are filled with sellers offering stolen databases, compromised credentials, and confidential records. But military and defence-related data sits in a different category. Claims involving classified documents, military personnel, defence institutions, drone technology, or internal government communications naturally carry greater significance, while also raising an important question: who is actually behind these listings, and how many seemingly different sellers are truly independent?

ModernStealer emerged as one such identity, appearing across underground forums with posts advertising military and defence-related material from multiple countries. At first glance, the activity appeared to belong to a single forum user operating under a recognizable alias. But as the investigation moved beyond the username and into the contact details left behind in these posts, the picture became more complicated. The same identifiers began appearing alongside other accounts, other aliases, and similar offerings across different corners of the underground ecosystem.

Using StealthMole to follow these traces across dark web forums and Telegram, this investigation examines the digital footprint surrounding ModernStealer and the identities that appear to intersect with it. Rather than assuming that every matching alias belongs to the same person, the report follows the identifiers themselves, looking at where they reappear, how the connections develop, and what those overlaps can tell us about the network operating behind a series of military and government data offerings.

The Thread That Started It All

The investigation began with a post on DarkForums where ModernStealer was offering what appeared to be sensitive documents related to a defence agreement between Türkiye and Pakistan. The thread, titled "[PK] TUR-PAK DEFENSE DRONE DEAL," immediately stood out because the material being advertised was not a typical database or credential dump, but a document concerning defence cooperation and drone technology.

The post described a 23-page confidential document titled "TURKEY-PAKISTAN BAYKAR-NASTP COOPERATION: STRATEGIC DEFENSE INDUSTRIAL PARTNERSHIP, TECHNOLOGY TRANSFER PROSPECTS AND DRONE PROCUREMENT." According to the description provided in the listing, the document covered cooperation involving Baykar Teknoloji and Pakistan's National Aerospace Science and Technology Park (NASTP), including areas such as unmanned systems, technology transfer, joint research and development, industrial collaboration, training, localization, and potential drone procurement.

  • https://darkforums.**/Thread****PK-TUR-PAK-DEFENSE-DRONE-DEAL

The listing itself was enough to make ModernStealer worth a closer look. A seller claiming access to confidential defence material involving drone technology raised the question of whether this was an isolated offering or part of a broader pattern. At this point, however, there was no basis to assume that ModernStealer had personally obtained the document through a breach, or even that the advertised material was authentic. What the thread did provide was a clear starting point: an underground identity openly associated with the alleged sale of sensitive defence-related information.

More importantly, the post contained an artifact that could be followed beyond the thread itself. ModernStealer had included the following Session ID as a contact point:

  • 05214b***********************************************f6163

Unlike the claims surrounding the advertised documents, the Session ID provided something concrete that could be searched and compared across StealthMole's indexed data. What began with a single defence-related listing now had a potential trail to follow, and the next step was to find out where else the same identifier had appeared.

A Pattern Begins to Emerge

Before following the Session ID beyond ModernStealer's own activity, we first wanted to understand whether the TU-PAK drone deal was an isolated listing or part of something larger. Searching the keyword "ModernStealer" in StealthMole's Leaked Monitoring tool returned five listings detected between March and April 2026.

Among the results were listings involving the Pakistan Nuclear Regulatory Authority (PNRA), Pakistan's National University of Sciences and Technology (NUST), and a database allegedly containing information belonging to Lockheed Martin employees. Another result concerned the Sri Lanka Air Force. While the nature and authenticity of these advertised datasets could not be established from the listings alone, their appearance under the same actor name suggested that the defence-related material seen in the TU-PAK thread was not an isolated occurrence.

The search was then extended to StealthMole's Government Monitoring tool to see whether the same name appeared in connection with government entities. This returned eight listings associated with ModernStealer between March and July 2026. Among them were posts concerning alleged internal documents from the Bangladesh military, Pakistan's SUPARCO and Ministry of Science and Technology, and a listing referencing the PLA, CIA, Department of Defense, and DARPA.

Together, the results began to show a recurring theme around the ModernStealer identity. The listings repeatedly touched on military, defence, government, nuclear, aerospace, and science-related organizations. This did not establish that ModernStealer had personally breached each of these entities, nor did it confirm that every dataset being advertised was authentic. But it did show that the TU-PAK drone deal was part of a much broader pattern of sensitive data offerings associated with the same name.

One of those listings offered a particularly useful opportunity to look closer. The thread concerned an alleged database belonging to the Pakistan Nuclear Regulatory Authority (PNRA) and was available at:

  • https://darkforums.**/Thr*****PK-Nuclear-Regulatory-Authority-PNRA-DATABASE

In the post, ModernStealer claimed to have compromised PNRA's mail server and obtained more than 60 databases, with 17 databases totaling approximately 3.2 GB being offered for sale. The actor claimed that the material included information related to nuclear reactor and chemical laboratory locations, employees, email addresses, sensitive documents, and infrastructure. These claims remained unverified, but one detail in the post was immediately familiar.

ModernStealer had again provided the same Session ID:

  • 05214b**********************************************f6163

The identifier first encountered in the TU-PAK drone deal was therefore not confined to a single listing. It has now appeared again in another sensitive post attributed to ModernStealer. With the same contact point recurring across separate offerings, the Session ID became more than a detail buried inside a forum post. It became the most promising artifact to follow beyond ModernStealer's own activity.

Following the Session ID

With the Session ID now appearing across more than one ModernStealer listing, the next step was to search the identifier directly in StealthMole's Dark Web Tracker. The results widened the investigation almost immediately. At least 30 indexed threads contained the same identifier, suggesting that its use extended well beyond the ModernStealer posts examined so far.

Among those results was a thread on Breached titled "Pakistan Military Procurement and Defense Deals," posted by a user named Zu1f1q4r:

  • https://breached.**/threads/pakistan-military-procurement****99/

The post concerned alleged contract and procurement information related to Pakistan's defence dealings with China and Türkiye. But it was the contact information at the bottom of the post that mattered most to the investigation. Zu1f1q4r had provided the exact same Session ID previously used by ModernStealer:

  • 05214***************************************************f6163

Alongside it was another identifier that had not appeared in the ModernStealer posts examined so far, a Tox ID:

  • 65BB****************************************************BC9D

The appearance of the same Session ID under a different username created the first clear overlap between ModernStealer and another underground identity. To understand whether this was a one-time occurrence, we looked further into Zu1f1q4r's activity and identified the actor's Breached profile:

  • https://breached.**/members/zu1f1q4********8/

The trail did not stop with the military procurement post. Another thread by Zu1f1q4r concerned an alleged leak involving Pakistan's Intelligence Bureau:

  • https://breached.**/threads/intelligence-bureau-pakistan****1/

Once again, the post listed the same Session ID and the same Tox ID as contact points.

A third thread followed the same pattern, this time involving alleged documents from Pakistan's Federal Investigation Agency (FIA):

  • https://breached.**/threads/pakistan-fia-documents******0/

Here too, Zu1f1q4r provided the same pair of identifiers.

The repeated overlap was difficult to ignore. ModernStealer and Zu1f1q4r were operating under different names, but the same Session ID appeared as a contact point in posts associated with both identities. Zu1f1q4r then repeatedly paired that identifier with the same Tox ID across multiple Pakistan-focused listings.

At this stage, however, the evidence did not establish that ModernStealer and Zu1f1q4r were the same person. The Session ID could have been shared between members of a group or used as common contact infrastructure. The Tox ID also remained directly associated only with Zu1f1q4r, since it had not been observed in any ModernStealer post examined during the investigation.

From the Dark Web to Telegram

The Session ID had already connected ModernStealer's DarkForums activity with posts published by Zu1f1q4r on Breached. But underground actors rarely limit their activity to a single type of platform. To see whether the same identifier had travelled beyond dark web forums, we searched it again, this time using StealthMole's Telegram Tracker.

The search led to a message posted in the Telegram channel:

  • https://t.me/Hexvi********ach

The message came from a user identified as Sassoon Don, operating under the Telegram username S*********n. In it, the user was looking for classified documents related to Ukraine and five Central Asian countries, apparently for China, and asked anyone with access to such material to contact them through Session.

The Session ID provided in the message was immediately recognizable:

  • 05214************************************************6163

It was the exact same identifier that had already appeared in posts by ModernStealer and Zu1f1q4r.

This was an interesting shift in the investigation. Until this point, the Session ID had appeared alongside actors advertising alleged military and government data. The Telegram message showed an account using the same contact point while actively seeking classified material, adding another dimension to the activity surrounding the identifier. It did not establish how any of the previously advertised material had been obtained, but it raised the possibility that the network around the Session ID was interested not only in distributing sensitive information, but also in sourcing it.

StealthMole's Telegram data allowed the account itself to be examined further. The user Sassoon Don was associated with the immutable Telegram User ID:

  • 7605334264

Searching the user profile revealed only two indexed messages, leaving relatively little historical activity to work with. StealthMole also showed the account appearing across three Telegram channels:

  • 3990978039: https://t.me/I********d
  • 3646663287: https://t.me/N********T
  • 3542147875: https://t.me/Hex*******h

These channel associations were useful as contextual information, but they were not treated as evidence of ownership or affiliation. Simply appearing in or being a member of a Telegram channel does not establish an operational relationship with the people running it.

More importantly, the investigation had not yet found another contact identifier in Sassoon Don limited Telegram history that could independently connect the account to ModernStealer. At this point in the investigation, the connection rested on one persistent artifact: the same Session ID.

The trail now involved three different identities across dark web forums and Telegram: ModernStealer, Zu1f1q4r, and Sassoon Don. Whether they represented separate actors sharing infrastructure, members of the same operation, or different identities controlled by one person was still unclear.

The Link Back to ModernStealer

The appearance of Sassoon Don on Telegram added another identity to the investigation, but at that point, the connection to ModernStealer still depended on the shared Session ID. To determine whether a more direct link existed, we returned to StealthMole's Dark Web Tracker and began looking more closely at other threads posted under the ModernStealer name.

One of those threads concerned the alleged sale of classified Pakistani military documents:

  • https://darkforums.**/Th***PAKISTAN-CLASSIFIED-MILITARY-DOCUMENTS

This time, the contact details provided at the bottom of the post changed the picture considerably. ModernStealer had listed two ways to get in touch:

  • Session: 05214*******************************************************88163
  • Telegram: @S**********n

The Telegram account discovered through the Session ID search was therefore not simply another user who happened to mention the same identifier. ModernStealer had directly listed Sassoon Don as a contact point in their own forum post.

The same pairing appeared again in another ModernStealer thread:

  • https://darkforums.***/T*******Military-Documents-of-Various-Countries-China-East-Asia-USA-Russia

The post advertised what was described as military material from several countries and regions and again directed interested users to the same Session ID and the same Telegram account, Sassoon Don.

Another thread involving an alleged data leak from Pakistan's National University of Sciences and Technology provided further evidence of the Session ID's repeated use:

  • https://darkforums.***/Threa**DATA-LEAK-OF-NUST-PAKISTAN-DEFENCE

Here, ModernStealer once again used the same Session identifier as a contact point.

The repeated use of these identifiers provided a much clearer connection than the investigation had at the beginning. The Session ID could now be directly tied to multiple posts under the ModernStealer identity, while Sassoon Don had also been explicitly presented by ModernStealer as a Telegram contact across separate listings.

This did not necessarily mean that the person operating the Sassoon Don Telegram account and the person posting as ModernStealer were the same individual. Shared accounts and contact infrastructure remain possible, particularly if ModernStealer represents a team rather than a single operator. But the evidence now establishes a direct operational association between the ModernStealer forum activity and Sassoon Don.

One Contact, Another Name

With Sassoon Don now directly connected to ModernStealer's forum activity, the Telegram username became the next artifact to investigate. Searching "SassoonDon" in StealthMole's Dark Web Tracker surfaced another forum thread, this time on Breached.live:

  • https://breached.*****/showt*************669

The thread, titled "PLA OFFICERS AND OTHER RANKS DATABASE," was not posted by ModernStealer. Instead, the account behind the listing was operating under a different name: PriorOps.

According to the post, PriorOps was offering what was described as a database containing information related to officers and other ranks within China's People's Liberation Army (PLA). The advertised records were said to include details such as rank, position, date of birth, education, career history, operational specialties, and contact information. As with the other listings examined during the investigation, these claims could not be independently verified from the post alone.

But once again, the most useful part of the listing was not necessarily what the actor claimed to possess. It was how they asked to be contacted.

The post listed:

  • Contact: @S********n

The same Telegram username that ModernStealer had explicitly provided in military-related DarkForums posts was now being used as a contact point by PriorOps, another forum identity advertising alleged military data.

This created a more direct overlap than the one previously observed with Zu1f1q4r. In that case, the connection to ModernStealer came through the shared Session ID. Here, both ModernStealer and PriorOps had independently published the exact same Telegram username as their contact point.

By this stage, a pattern was beginning to take shape around the identifiers rather than the names themselves. ModernStealer was directly connected to both the Session ID and Sassoon Don. Zu1f1q4r repeatedly used the same Session ID across several Pakistan-focused listings, while PriorOps used the same Sassoon Don Telegram account in a post involving alleged PLA personnel data.

The overlaps raised an obvious possibility: ModernStealer, Zu1f1q4r, and PriorOps could represent different aliases used by the same operator. But the evidence also allowed for another explanation. The identities could belong to multiple individuals using shared contact infrastructure or operating as part of the same group. The available artifacts were strong enough to establish an operational connection between the identities, but not strong enough to conclusively determine who was sitting behind each account.

What was becoming increasingly clear, however, was that following usernames alone would have missed much of this picture. The names changed from one forum to another, but the contact points did not. The Session ID and Sassoon Don account provided the connective tissue between accounts that, at first glance, appeared to be unrelated.

A Second ModernStealer?

The connections uncovered so far had all developed from contact points that could be traced from one identity to another. But there was another, more obvious lead worth examining. Searching the keyword "ModernStealer" directly in StealthMole's Telegram Tracker surfaced a user using the name ModernStealer.

At first glance, the match appeared significant. But a closer look at the account's history showed why matching usernames alone can be misleading in underground investigations.

StealthMole associated the account with the immutable Telegram User ID:

  • 1628612534

Historical records showed that the same user ID had changed its username multiple times over the years, with six username changes observed in the available data. Among the account's previous identities was @Mirage2022, appearing under names including Myles and Haven.

Looking through the account's older messages revealed one detail that stood out in the context of the investigation. On 3 February 2026, while appearing as Myles / @Mirage2022, the user posted a message asking:

  • “Who knows where I can get drone leaks and blueprints”

The message was difficult to ignore. The investigation itself had begun with ModernStealer advertising documents related to a Türkiye-Pakistan drone deal, and there was a Telegram account that would later use the same username with a documented historical interest in obtaining drone-related leaks and blueprints.

Other messages provided glimpses into the account's broader activity. Historical records showed the user asking others for money, while one conversation included the statement:

  • “No, I’m not Indian, lol”

The comment offered little in the way of reliable attribution. It was a self-reported statement made by the user and could not be used to establish nationality or location.

StealthMole also preserved images associated with the account's historical Telegram activity. Among them were screenshots showing payment-related information and material referring to Apple Pay-linkable debit cards, alongside purported balances and prices. While these images added context to the type of underground activity surrounding the account, they did not establish that the user owned the financial accounts shown, controlled the advertised cards, or personally carried out any related fraud.

Taken together, the findings made Telegram User ID 1628612534 an interesting lead. The later use of the exact name and the earlier interest in drone leaks created a notable resemblance to the activity examined elsewhere in the investigation.

But unlike Sassoon Don, this account could not be tied back to ModernStealer through the Session ID or another contact point directly published in the actor's forum posts. No overlap was found with Telegram User ID 7605334264, and the investigation did not uncover another persistent identifier connecting the two accounts.

For that reason, the account remains an unconfirmed branch of the investigation. It may represent another identity connected to ModernStealer, or the username may have been adopted independently. The similarities make the account worth documenting, but they are not enough to merge it into the stronger attribution chain built around the Session ID and Sassoon Don.

Conclusion

What began with a single DarkForums listing involving an alleged Türkiye-Pakistan defence drone deal quickly developed into a much broader investigation. ModernStealer's activity extended across a series of listings involving military, government, nuclear, defence, and aerospace-related material, but it was the contact information left behind in those posts that ultimately proved more revealing than the names attached to them.

By following the Session ID and Sassoon Don across StealthMole's indexed dark web and Telegram data, the investigation uncovered connections that would have been difficult to identify through username searches alone. The same Session ID used by ModernStealer appeared repeatedly in posts by Zu1f1q4r, while the Telegram account directly advertised by ModernStealer was also used as a contact point by PriorOps. These overlaps establish a clear operational relationship between the identities, although the evidence does not conclusively determine whether they represent one person operating under multiple aliases, members of the same group, or separate actors sharing communication infrastructure.

The investigation also surfaced a separate Telegram account using the ModernStealer name, whose historical activity included an interest in obtaining drone leaks and blueprints. Despite the apparent similarities, no persistent identifier was found connecting that account to the stronger attribution trail surrounding the known Session ID and Sassoon Don. It therefore remains an unresolved lead rather than a confirmed part of the cluster.

Ultimately, the ModernStealer investigation shows why the identity displayed beside a forum post is often only the beginning of the story. Usernames changed as the investigation moved between platforms, but certain contact points continued to reappear. Following those identifiers allowed a single military data listing to develop into a wider picture of interconnected underground activity, while also leaving an important question unresolved: whether the many faces surrounding ModernStealer belong to one operator or to a network working behind shared infrastructure.

Editorial Note

Attribution in cyber and dark web investigations is rarely absolute. Shared accounts, reused identifiers, changing usernames, and common infrastructure can create strong connections without necessarily proving that the same individual is behind every identity. This investigation reflects that uncertainty: StealthMole made it possible to follow persistent artifacts across forums and Telegram and uncover relationships that were not immediately visible, while the available evidence still required each connection to be assessed on its own strength rather than treated as definitive attribution.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

JulyJailbait: Reconstructing an Underground CSAM Ecosystem

Dark web continues to host a wide range of illicit platforms that cater to criminal markets, from stolen data and malware to illegal services and child sexual abuse material (CSAM). While many of these websites disappear as quickly as they emerge, others remain active for years by continuously adapting their infrastructure, replacing seized or abandoned domains, and maintaining access through mirror sites and alternative payment mechanisms. As a result, investigating these platforms often requires looking beyond what is immediately visible to understand how they continue to operate over time.

One such platform is JulyJailbait, also referred to as July Club, a long-running dark web website advertising access to a large collection of illegal material through paid memberships. At first glance, the platform appears to be just another onion service offering subscription-based access. However, its publicly visible pages reveal only a small part of a much broader ecosystem.

This investigation reconstructs that ecosystem using artifacts collected through StealthMole, following a series of investigative pivots that extend beyond the primary website. By correlating historical infrastructure, digital assets, cryptocurrency payment information, and other operational traces, the report demonstrates how seemingly isolated pieces of evidence can be combined to reveal a far more extensive underground network than the website alone suggests.

Following the First Lead

The investigation began with the identification of the primary JulyJailbait onion service:

  • julyl************************************************pid.onion

Historical snapshots indexed by StealthMole revealed that the website, also referred to as July Club, advertised subscription-based access to a large collection of illegal material through a simple membership model. The landing page claimed to host more than 8 TB of content and accepted payments in both Bitcoin (BTC) and Monero (XMR) before granting users access to the platform. The site also maintained dedicated login, payment, and FAQ pages, suggesting a structured and persistent operation rather than a temporary or opportunistic deployment.

Rather than limiting the investigation to the visible content of the website, the focus shifted towards identifying reusable artifacts that could reveal additional infrastructure. Historical snapshots, indexed files, payment pages, embedded resources, and other technical elements often persist even as underground services migrate between domains or modify their public-facing pages. These artifacts frequently provide more investigative value than the homepage itself.

Among the indexed files associated with the platform was a logo image named julylail.png. While appearing insignificant at first glance, reusable digital assets such as logos often retain identical cryptographic hashes across multiple deployments. This makes them valuable pivots for infrastructure discovery, particularly when operators reuse the same resources across mirror domains or successive versions of a website.

The image was therefore selected as the next investigative pivot to determine whether it could expose additional infrastructure beyond the primary onion service.

An Image That Led to Mirrors

With the primary website documented, the investigation shifted to the platform's embedded resources in search of reusable artifacts that could reveal additional infrastructure. Among the indexed files associated with the website was a logo image, julylail.png, bearing the JulyJailbait branding. Although visually unremarkable, the image retained a unique SHA-256 hash that made it an ideal investigative pivot.

Rather than searching for domains or keywords, the image itself was queried through StealthMole's Dark Web Tracker. Because StealthMole indexes historical files alongside websites, identical images reused across different services can often expose infrastructure that is not directly linked from a platform's public pages.

The results significantly expanded the scope of the investigation. The same image hash was found across 35 mirror domains associated with JulyJailbait, many of which had never been referenced on the primary website. This demonstrated that the operators had repeatedly reused the identical logo while deploying new domains, unintentionally leaving behind a persistent artifact that connected otherwise independent instances of the platform.

Among the identified infrastructure were both active and inactive mirrors, illustrating the platform's long operational history and its reliance on domain rotation to maintain accessibility. One of the active mirrors proved particularly valuable, as it contained a dedicated page listing both current and historical JulyJailbait domains while distinguishing them from domains the operators claimed were fraudulent or unauthorized. This provided rare insight into how the platform itself documented changes to its infrastructure and attempted to direct users toward legitimate mirrors.

  • jjclub********************************************lad.onion

Some of the notable mirror domains identified during the investigation include:

  • jjclubumn7vkhyuw.onion (inactive)
  • jjclub***********************************************lad.onion (active)
  • 232kckhwmfpl6mqqmigunmffkldxp3tbsfvxxwofrdv52ikvxshmzwid.onion (inactive)
  • 5am52idv6d2azc2drzmxvstt6y7pozju3ujn7eydqnxdynvkxwl2omad.onion (inactive)
  • jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion (inactive)
  • cvfdjsmso5ii5twu7kmmpyvbjnggnku4v47vf2xc3m2ochmxfxi722id.onion (inactive)
  • tl65h3pazhvh6ewepmlvlwbwtrsl2ap7gox2qoyveem7s44umbfzboyd.onion (inactive)

What initially appeared to be a simple branding asset ultimately became one of the most valuable investigative pivots in the case. Instead of exposing only additional websites, the recovered mirror domains provided new avenues for infrastructure analysis, historical comparison, and financial tracing, allowing the investigation to move beyond the primary onion service and into the wider ecosystem supporting the platform.

Hidden in the Past

The discovery of JulyJailbait's mirror infrastructure provided more than additional access points to the platform. By examining several inactive mirror domains individually, the investigation uncovered historical payment artifacts that no longer appeared on the current deployment. These legacy mirrors effectively served as archived snapshots of the platform's earlier operational infrastructure, preserving cryptocurrency wallets that had since been replaced.

Across the investigated mirror domains, 17 additional Bitcoin wallets were identified. None of these wallets had been observed on the primary JulyJailbait website, indicating that the platform had periodically refreshed its payment infrastructure while continuing to operate under the same branding. Unlike the cryptocurrency artifacts recovered from the active website, these historical wallets showed no overlap with other underground services during this investigation, suggesting they belonged to an earlier phase of the platform's operation.

232kckhwmfpl6mqqmigunmffkldxp3tbsfvxxwofrdv52ikvxshmzwid.onion

This inactive mirror proved to be the richest source of historical payment artifacts, revealing seven Bitcoin wallets that were not observed elsewhere during the investigation:

  • bc1qj**********************************qj8
  • bc1qv**********************************h8r
  • bc1q8**********************************hvm
  • bc1qf**********************************96x
  • bc1qe**********************************hkt
  • bc1qa**********************************9fv
  • bc1qr**********************************nrr

5am52idv6d2azc2drzmxvstt6y7pozju3ujn7eydqnxdynvkxwl2omad.onion

Analysis of this inactive mirror identified a single Bitcoin wallet associated with the platform:

  • 15UN**************************1SH

jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion

This mirror preserved two historical Bitcoin wallets:

  • 18P3**************************7Stc
  • 16Uyc*************************GwjW

cvfdjsmso5ii5twu7kmmpyvbjnggnku4v47vf2xc3m2ochmxfxi722id.onion

Investigation of this mirror recovered three Bitcoin wallets:

  • 1PnfX*************************SES
  • 1gY3w*************************czN
  • 18P3F************************7Stc

Notably, the wallet 18P3F16UoQm5rEAJPXbE5p4ERYUPNS7Stc had already been observed on jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion, making it the only historical Bitcoin wallet reused across multiple archived deployments identified during this investigation.

tl65h3pazhvh6ewepmlvlwbwtrsl2ap7gox2qoyveem7s44umbfzboyd.onion

The final investigated mirror yielded three additional Bitcoin wallets:

  • 1FUoh**************************qbb
  • 1LBvk**************************PHk
  • 1GUgu**************************31h

Beyond the archived onion services, the active mirror jjclub**************hlad.onion contained a dedicated page documenting the platform's historical infrastructure. Alongside previous onion services, the operators also referenced several surface web domains, including julyjailbait.com, julyjailbait.net, julyjailbait.org, and julyjailbait.me, while separately identifying domains they considered fraudulent or unauthorized. Although these references originate from the operators themselves and should not be treated as independently verified infrastructure, they provide valuable insight into how the platform documented its historical presence and attempted to distinguish legitimate domains from impersonation sites.

Rather than functioning solely as backup websites, the historical mirrors preserved intelligence that no longer existed on the active platform. By examining these archived deployments individually, the investigation reconstructed an earlier stage of JulyJailbait's financial infrastructure, providing a broader historical perspective that would not have been possible through analysis of the primary website alone.

Following the Financial Footprint

One of the most valuable sources of intelligence recovered from the primary JulyJailbait website was its cryptocurrency payment infrastructure. The publicly accessible payment page accepted both Bitcoin (BTC) and Monero (XMR), with users required to complete a cryptocurrency payment before gaining access to the platform. Rather than treating these wallets solely as payment addresses, each one was used as an investigative pivot within StealthMole to determine whether the same infrastructure appeared elsewhere across the underground ecosystem.

The investigation identified 10 Bitcoin wallets and 5 Monero wallets associated with the primary JulyJailbait domain. While several of these wallets appeared to be exclusive to the platform, others were reused across multiple underground services, exposing links that were not apparent through website analysis alone.

Bitcoin Wallets Identified

Bitcoin Wallet

Additional Infrastructure Identified

bc1q*********************4gu

JulyJailbait, Alice

bc1q*********************6f6

JulyJailbait only

bc1qc********************708

JulyJailbait, MOE Connect, WormGPT

bc1q8********************90r

JulyJailbait, MOE Connect

bc1qg*******************50a

JulyJailbait only

bc1qp********************g3f

JulyJailbait only

bc1qy**********************ymm

JulyJailbait, MOE Connect

bc1qj**********************ddp

JulyJailbait, KidBin, Snapchat account hacking service

bc1q8********************gmt

JulyJailbait, WormGPT

bc1qp********************ha5q

JulyJailbait only

The Bitcoin infrastructure showed a mixture of exclusive and shared payment addresses. While several wallets appeared unique to JulyJailbait, others were reused across services such as WormGPT, MOE Connect and KidBin, suggesting that elements of the payment infrastructure extended beyond a single platform.

Monero Wallets Identified

Monero Wallet

Additional Infrastructure Identified

86c3CZ********************qA1y

JulyJailbait, WormGPT, FraudGPT, Darkweb Porn, Daisy's Destruction

89m2tJ*******************PKsqp

JulyJailbait, WormGPT

87Cae********************vmnX

JulyJailbait, WormGPT, Daisy's Destruction

86d1f********************rhVm

JulyJailbait, WormGPT

86jCb1******************9Q9h

WormGPT, FraudGPT, Daisy's Destruction, Alice

Compared with the Bitcoin addresses, the Monero wallets demonstrated broader overlap across multiple underground services. Several appeared repeatedly alongside platforms offering illicit AI services and other criminal offerings, making them particularly valuable investigative pivots for identifying relationships between otherwise separate dark web ecosystems.

The reuse of cryptocurrency wallets across multiple services does not, on its own, prove common ownership or operational control. It does, however, indicate shared payment infrastructure or operational relationships that warrant further investigation. By correlating these artifacts through StealthMole, the investigation extended beyond the primary JulyJailbait website and uncovered infrastructure spanning multiple underground platforms.

Beyond the Dark Web

While the investigation primarily focused on reconstructing JulyJailbait's infrastructure through its onion services, cryptocurrency wallets, and historical mirrors, the platform's footprint was not confined to the dark web alone. To determine whether JulyJailbait maintained an external presence or whether its content was being circulated elsewhere, the investigation pivoted to StealthMole's Telegram Tracker.

Searches for "July Jailbait" returned numerous references spanning several years across multiple Telegram groups and channels. Although these findings did not reveal an official Telegram channel or account directly attributable to the platform's operators, they demonstrated that JulyJailbait's name and associated content had been shared and discussed within a variety of unrelated communities.

References were identified across channels operating in English, Russian, Chinese, and Spanish, reinforcing earlier observations that the platform catered to a multilingual audience. This multilingual footprint was also consistent with the language options available on the JulyJailbait website itself, suggesting that the platform was accessible to users from different regions rather than targeting a single linguistic community.

Several Telegram messages referenced JulyJailbait by name, while others contained filenames, torrent references, or media allegedly originating from the platform. Among the more notable findings was an image shared within the Telegram channel "Хакеры | Чат | 𝓗𝓪𝓬𝓴𝓮𝓻𝓼 𝓬𝓱𝓪𝓽", which appeared to depict the contents of a JulyJailbait repository. Although the image could not be independently verified as originating directly from the platform, it demonstrated that material associated with JulyJailbait was circulating beyond its own onion services.

Additional references were identified in channels including:

  • Conspiración Máxima 777, where users discussed media allegedly originating from JulyJailbait.
  • 爱妈仕三群, which contained multiple references to July Jailbait alongside BitTorrent magnet links.
  • 集帆阁-呦呦搜索引擎, where users shared file names associated with the platform.

These findings suggest that Telegram primarily functioned as a secondary distribution and discussion channel rather than an official communication platform operated by JulyJailbait. Instead of uncovering operator-controlled infrastructure, the investigation revealed how the platform's name, references, and associated material continued to circulate organically across multiple online communities, extending its visibility well beyond the dark web.

Conclusion

What began as the investigation of a single onion service ultimately evolved into the reconstruction of a much broader underground ecosystem. Although the publicly accessible July Jailbait website revealed only limited information due to its authentication wall, a series of investigative pivots through StealthMole uncovered infrastructure extending well beyond the primary domain.

By correlating a reusable logo image, historical mirror domains, cryptocurrency payment artifacts, and Telegram references, the investigation exposed multiple layers of the platform's operational footprint. The recovery of approximately 35 related mirror domains, 27 Bitcoin wallets, 5 Monero wallets, historical surface web domains, and shared cryptocurrency infrastructure demonstrated that July Jailbait was supported by a far more extensive network than its current website alone suggested.

The investigation also highlighted the importance of examining historical and indirect artifacts rather than focusing solely on active infrastructure. Legacy mirror domains preserved payment information that no longer appeared on the current deployment, while cryptocurrency wallet reuse revealed connections to other underground services that would not have been apparent through website analysis alone. Similarly, Telegram references illustrated how the platform's name and associated material continued to circulate across multiple language communities despite the absence of an identifiable official Telegram presence.

Rather than relying on any single source of intelligence, this investigation demonstrates how combining historical snapshots, digital artifacts, financial indicators, and cross-platform correlation can transform a seemingly isolated website into a much more comprehensive picture of an underground ecosystem.

Editorial Note

Investigations involving dark web platforms rarely produce a complete picture from a single source. Infrastructure changes, inactive domains, reused artifacts, and fragmented online traces often require analysts to reconstruct events from evidence collected across multiple locations and time periods.

This investigation illustrates how StealthMole's ability to correlate historical snapshots, reusable digital artifacts, cryptocurrency infrastructure, and cross-platform references enables analysts to move beyond individual websites and build a more complete understanding of long-running underground ecosystems while maintaining evidence-based attribution throughout the investigative process.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

The ExtortionLord Trail: How a KakaoTalk Sale Led Back to LockBit's Leaked Infrastructure

The underground data trade rarely revolves around a single forum or marketplace. Sellers and brokers move between dark web communities, encrypted messaging platforms, and private channels, offering everything from compromised databases and source code to network access and internal corporate data. The identities behind these operations can be equally fluid. Usernames change, accounts disappear, and communication shifts from public posts to private messengers, leaving investigators to piece together fragments scattered across different platforms and points in time.

One such figure is ExtortionLord, a threat actor whose activity surfaced through the sale and distribution of compromised data on underground forums. At first glance, the actor appeared to fit a familiar profile: an underground seller advertising access to valuable stolen material. But as we began following the identifiers and traces surrounding ExtortionLord through StealthMole, the investigation started moving beyond individual sales posts and into a wider network of forum activity, aliases, encrypted communication identifiers, Telegram accounts, channels, and leaked files.

This report follows that investigation as it unfolded. Starting with the activity that first brought ExtortionLord into view, we trace the actor's footprint across underground sources and follow each meaningful lead into the next. Along the way, the investigation reaches communication channels connected through shared identifiers, profiles that may offer additional context around the people involved.

The First Trace of ExtortionLord

The investigation began when StealthMole's Leaked Monitoring tool indexed a recent post from a user operating under the name ExtortionLord. The post appeared on DarkForums, where the actor claimed to be selling KakaoTalk's full source code, alongside network access and access to the company's databases.

  • https://darkforums.**/Thread-Selling-Kakao-Talk*************96

At this stage, ExtortionLord was simply an unfamiliar name attached to a potentially significant underground sale. There was little indication of who was behind the account or whether the identity had appeared elsewhere. Rather than stopping at the leak itself, we decided to use the information captured by StealthMole as the starting point for a deeper investigation into the seller.

The DarkForums link surfaced through Leaked Monitoring tool was examined further using StealthMole's Dark Web Tracker. Inside the thread, ExtortionLord had left a single direct contact point for anyone interested in reaching them:

  • TOX: 4DEBE**********************************************B55A9

Unlike a username, which can easily be copied or reused across unrelated platforms, this long-form identifier offers a much more specific artifact to work with. It gave the investigation two immediate directions: the ExtortionLord identity itself and the Tox ID the actor had chosen as their only listed contact point.

From there, the focus shifted away from the KakaoTalk sale itself. The question was no longer simply what ExtortionLord claimed to possess, but what traces the actor and their contact information might have left elsewhere across the underground ecosystem.

Following the Contact Point

With the Tox ID established as ExtortionLord's only listed contact method on the DarkForums thread, the next step was to determine whether the same identifier had surfaced elsewhere. A search for the full Tox ID through StealthMole produced a much broader trail than the original KakaoTalk listing suggested.

The identifier appeared in a post on XSS, but this time it was not attached to the ExtortionLord name. Instead, the post was associated with the alias Mansoryx. The overlap immediately stood out. The same Tox ID that ExtortionLord had provided as the sole contact point for the KakaoTalk offering was now connected to a different underground identity.

This did not, on its own, establish that ExtortionLord and Mansoryx were the same person. Communication identifiers can potentially be shared, transferred, or used by multiple individuals. However, the exact match provided a concrete connection between the two identities and gave us another lead to follow.

We then searched the Tox ID through StealthMole's Telegram Tracker, looking for any messages or channels where it had previously been mentioned.

That search led us to a telegram channel:

  • https://t.me/+NV5**********mI0

Inside the channel, we identified a message containing two encrypted-messaging identifiers. One was the same qTox ID already encountered in the DarkForums and XSS threads:

  • 4DEBEB************************************************DB55A9

Another was a Session ID:

  • 05a19***********************************************69c74917

At this point, the investigation had moved considerably beyond the original sale post. A Tox identifier first discovered as ExtortionLord's contact point on DarkForums had led to the Mansoryx alias on XSS, which in turn led to a Telegram channel where the same Tox ID appeared alongside a second encrypted communication identifier.

The repeated appearance of the exact Tox ID across these separate sources gave the investigation a more stable thread to follow than the usernames themselves. ExtortionLord and Mansoryx remained identities requiring careful attribution, but the communication infrastructure connecting the activity was beginning to form a clearer trail.

New Names Begin to Surface

With the Tox and Session identifiers now appearing together in the same Telegram message, we continued investigating the Tox ID beyond the underground sources already uncovered. This led us to a security research report published by Trellix examining the leak of LockBit's administrative panel.

The report contained the same Tox ID we had been following since the original ExtortionLord post. More importantly, it provided additional context around the communication trail that had started to emerge through our own investigation.

Among the information documented in the research was a Telegram account:

  • https://t.me/INFO********l

The report also referenced activity involving the moniker flex, which had reportedly been used in connection with efforts to recruit pentesters on the XSS forum.

These findings introduced new names into the investigation, but they also required caution. The presence of the same Tox ID created a reason to examine the surrounding accounts and aliases, but it was not enough to conclude that ExtortionLord, flex, or the operator behind @INFO*******l were necessarily the same individual. Each would need to be investigated independently before any stronger connection could be made.

The Telegram account provided the most immediate next step. We searched @INFO*********l through StealthMole's Telegram Tracker, where the account surfaced under the name Molot.

The profile contained a particularly interesting detail. In its bio, Molot had included the following message:

Не ответил? проигнорировал? продублируй https://t.me/+NV51*********mI0

The link pointed to the same Telegram channel we had already reached by tracing ExtortionLord's Tox ID, the channel where the Tox and Session identifiers had appeared together.

This created a more meaningful connection than a shared username or alias. The investigation had reached the channel independently through ExtortionLord's Tox identifier, while the @INFO*********l account surfaced through a separate research trail and directly referenced that same channel in its profile.

We then examined Molot's wider Telegram activity through StealthMole. The account was found participating in another Telegram community:

  • https://t.me/user****forum

StealthMole's indexed data showed at least 24 messages associated with Molot in the channel, opening another avenue for examining the account's historical activity.

By this stage, the investigation had begun to move from isolated identifiers toward a more interconnected picture. Yet the relationships between the names remained unresolved. ExtortionLord, Mansoryx, flex, and Molot had now surfaced at different points along the same broader investigative trail, but the available evidence did not justify treating them as a single actor. What it did provide was a growing collection of connections that could now be examined against another source of evidence waiting in StealthMole's indexed data.

A Familiar Name Inside a Leaked Database

With the communication trail beginning to take shape, we returned to the other investigative direction created at the start of the case: the ExtortionLord username itself.

Searching ExtortionLord through StealthMole's Dark Web Tracker produced a result inside a leaked SQL file labelled Panel_DB. Unlike the earlier forum posts, this was not another public appearance of the alias. The username appeared as a record within a database dump.

To understand what the result contained, we analyzed the file using StealthMole's MoleChat. The analysis surfaced several values associated with the ExtortionLord record:

Username: ExtortionLord 

Password/value: gRh************i5 

Token/session-like value: eqnd*******************6ik2

At this point, however, the presence of the username raised more questions than it answered. A record labelled ExtortionLord inside an unidentified panel database did not tell us who operated the panel, what purpose it served, or what the actor's presence within the database actually represented. Even the additional values associated with the record could not be assigned a definitive function without understanding the underlying database structure.

The name of the file provided the next clue. We searched for references to paneldb_dump through StealthMole's Telegram Tracker and found the term appearing across several messages and shared files. One of those results came from a private Telegram channel, where copies of paneldb_dump and a corresponding torrent file had been circulated.

The accompanying message provided crucial context around what we had found. The material was described as originating from a compromise of LockBit's administrative infrastructure, with the leak attributed in the circulated material to an actor referred to as "xoxo from Prague."

This also brought the earlier Trellix report back into focus. The report we had initially reached while tracing ExtortionLord's Tox ID was examining the same broader event: the leak of LockBit's admin panel. What had previously served as a source of additional identifiers now provided context for understanding the unexplained SQL record surfaced through StealthMole.

The Panel_DB result was therefore not evidence of a database operated by ExtortionLord. Instead, the investigation indicated that the record had surfaced within data associated with the leaked LockBit admin panel.

That distinction was critical. It prevented an unrelated infrastructure attribution while opening a much more important question: why did a record carrying the ExtortionLord identity appear inside data from LockBit's leaked panel?

The answer could not be established from the username alone. But the database itself offered considerably more material to examine. Additional searches through StealthMole surfaced three more files associated with paneldb_dump, giving us an opportunity to look beyond a single ExtortionLord record and examine the structure and contents of the leaked panel in greater detail.

Looking Inside the LockBit Panel Leak

With the origin of paneldb_dump now clearer, the investigation shifted from identifying the database to understanding what it actually contained. StealthMole had surfaced three additional leaked files associated with paneldb_dump, which we analyzed using MoleChat to examine their structure and contents without manually navigating thousands of database records.

The files appeared to contain data from the backend of a ransomware operation. MoleChat identified records associated with victim and operator negotiations, including messages exchanged during ransom discussions and corresponding timestamps. Other records related to Bitcoin payment addresses, providing insight into how cryptocurrency addresses were managed within the panel.

The database also contained traces of the operational processes surrounding an extortion case. These included references to uploaded files and attachments, as well as records associated with test-decryption workflows, a process commonly used during ransomware negotiations to demonstrate that encrypted files can be recovered.

Additional tables and entries pointed to API-related activity and operational identifiers, while the records visible in the analyzed material covered activity from at least December 2024 through April 2025. Taken together, the files provided a glimpse into the administrative machinery behind the panel rather than simply a collection of leaked usernames.

This context helped us better understand the significance, and the limitations, of the earlier ExtortionLord record. Finding a username inside such a database could indicate that the identity existed somewhere within the panel's operational environment, but it did not, by itself, explain the individual's role. Without establishing precisely what table the record originated from and what that table represented, it would be premature to label ExtortionLord as a LockBit affiliate, administrator, or operator.

What made the finding more difficult to dismiss as a simple username collision, however, was the wider trail already uncovered during the investigation. The ExtortionLord identity found in the leaked panel data was being examined alongside a highly specific Tox identifier that had independently surfaced across the actor's 2026 DarkForums activity, XSS, Telegram, and external research connected to the LockBit panel leak.

The database therefore added an important historical layer to the investigation, but not a definitive attribution. Rather than providing a simple answer to who ExtortionLord was, it placed the identity within a much larger operational dataset and raised a more focused question about the nature of that connection.

With the LockBit panel data examined, one unresolved lead remained particularly interesting: Mansoryx, the alias encountered earlier on XSS using the same Tox contact point as ExtortionLord. We therefore returned to that identity to see whether StealthMole could uncover a historical footprint beyond the forum post where the name first appeared.

Conclusion

What began with StealthMole detecting an underground offer involving KakaoTalk ultimately became an investigation into the digital footprint surrounding the seller behind it. ExtortionLord initially appeared as a newly surfaced actor with little context beyond a DarkForums account and a Tox contact point. It was that contact point, rather than the username, that proved to be the most valuable lead.

Following the identifier across different sources uncovered traces that predated the KakaoTalk offering and crossed several corners of the underground ecosystem. The investigation encountered Mansoryx on XSS, a corresponding Session identifier in historical Telegram data, and the @INFO*********l account associated with Molot, whose profile pointed back to the same Telegram channel already uncovered through the Tox search. Separately, the ExtortionLord username surfaced within the leaked LockBit panel data, adding another potentially significant connection while leaving the actor's precise role within that environment unresolved.

Not every lead produced a definitive identity, and the investigation does not establish that ExtortionLord, Mansoryx, Molot, or flex are necessarily the same individual. The evidence instead shows how a single communication identifier can persist across platforms and over time, connecting activity that would otherwise appear unrelated. In this case, a Tox ID attached to a 2026 data sale opened a window into a much older and more complex trail.

The identity behind ExtortionLord therefore remains an open question. But the actor who appeared on DarkForums was not surrounded by an entirely new digital footprint. The identifiers attached to that identity had a history, and by following those traces across StealthMole's indexed dark web, leaked-data, and Telegram sources, it became possible to reconstruct parts of that history without forcing uncertain correlations into definitive attribution.

Editorial Note

Attribution in cybercrime and underground investigations is rarely absolute. Aliases can be reused, accounts can change hands, and communication identifiers may connect individuals without proving they are the same person.

The case also demonstrates the value of StealthMole in navigating these fragmented environments, allowing investigators to move between current activity and historical records, follow persistent identifiers across different sources, and distinguish meaningful connections from coincidences without overstating what the available evidence can prove.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: , , ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report