Party Heaven and the Storefronts Next Door: Mapping a Dark Web Drug Network

Dark web drug markets rarely stay still for long. Storefronts disappear, onion addresses change, and familiar shops can return under new names or slightly altered branding. What looks like a single marketplace at first glance may therefore represent only one visible part of a much larger and longer-running operation. Following these markets requires looking beyond what is currently online and paying attention to the traces they leave behind.

Party Heaven, a Tor-based drug storefront describing itself as “The Paradise of Partying,” became the starting point for this investigation. The platform advertised a broad catalogue of illicit drugs and pharmaceutical products through a conventional e-commerce-style interface, presenting itself much like an ordinary online shop despite the nature of the products being sold.

What began as a closer look at Party Heaven gradually moved beyond the storefront itself. Using StealthMole, the investigation followed the digital traces surrounding the platform across historical dark web records, cryptocurrency infrastructure, archived content and recurring product material. Each pivot added another piece to the picture and raised a larger question: was Party Heaven really an isolated marketplace, or was it sitting alongside a wider collection of connected storefronts?

This report follows that investigation from the original Party Heaven shop outward, examining the relationships that emerged along the way while separating direct technical connections from similarities that, on their own, cannot establish common ownership.

Behind the Shop Window

The investigation began with Party Heaven’s primary Tor storefront:

  • w543g*******************************************cmid.onion

Indexed in StealthMole’s Darkweb Tracker under the title “Party Heaven – The Paradise of Partying,” the site followed a familiar e-commerce format. Products were displayed with photographs, prices and “Add to Cart” options, with categories spanning illicit drugs and pharmaceutical products. StealthMole had indexed around 70 images associated with the platform, including listings for products such as Viagra, morphine, cocaine, GHB, ketamine, PCP, LSD and other substances.

The storefront itself provided only part of the picture. A closer look at Party Heaven’s Frequently Asked Questions page offered considerably more insight into how the operation claimed to handle orders. According to the page, customers could pay using either Bitcoin (BTC) or Monero (XMR), while prices were also displayed in US dollars. Party Heaven claimed orders would be shipped within 24 hours, vacuum-sealed and packaged with a decoy. Weekend orders were reportedly held until Monday, while tracking information could be provided on request, although the operators reserved the right to withhold it if they believed doing so was necessary for security.

The refund policy was equally revealing. Party Heaven stated that refunds would not be provided without “proof of seizure,” and placed responsibility for providing a correct shipping address on the buyer. Rather than functioning as a multi-vendor marketplace with visible seller profiles, the site presented these policies as platform-wide operating procedures.

The FAQ also provided a contact point for customers, directing questions to the TorBox address:

  • PartyHeaven@torbox*******************************6to3uyqad.onion

The checkout page added another layer. Customers were specifically instructed not to use a clearnet email provider such as Gmail or ProtonMail, and were instead encouraged to use an onion-based hidden-service email account, with TorBox given as an example. Payment was required before an order would ship, and unpaid orders were stated to be automatically cancelled if payment was not received within one hour.

More importantly for the investigation, StealthMole exposed the cryptocurrency infrastructure attached to the storefront. Two Bitcoin addresses were associated with Party Heaven:

  • bc1q0v********************************0lkr
  • bc1qdn********************************dlmt

A Monero address was also identified:

  • 887v1Eg******************************************JfHx

At this point, Party Heaven was no longer simply a storefront with a catalogue of drugs. It had left behind several different kinds of artifacts that could be investigated independently: cryptocurrency addresses, historical web content, contact infrastructure and dozens of indexed product images.

One Monero Address, Another Party Heaven

The Monero address gave the investigation its first indication that the Party Heaven storefront visible today was not the only version of the platform that had existed.

Searching the address in StealthMole’s Darkweb Tracker led to another onion domain:

  • w543g***************************************7bqd.onion

It had been indexed under the same title, “Party Heaven – The Paradise of Partying,” and was first scanned on April 18, 2026. The last recorded scan was on August 6, 2026.

The site carried the same Party Heaven identity and presented a familiar catalogue of drugs through a storefront closely resembling the active domain. One preserved product page, for example, advertised “3-CL-PCP Crystals, 5g” for $199, under the PCP (Angel Dust) category.

There were some differences beneath the surface. While the active Party Heaven domain identified its web server as nginx/1.18.0, StealthMole recorded the inactive domain running Apache/2.4.68 (Debian). This meant visual similarity alone was not enough to simply assume identical infrastructure. However, the combination of the Party Heaven branding, matching storefront characteristics and its appearance during the Monero-address pivot made the inactive onion a much stronger lead than a lookalike website discovered in isolation.

That historical storefront contained another particularly useful source of evidence: its product images.

Rather than treating those photographs simply as illustrations for drug listings, the investigation began using them as searchable artifacts. One image associated with a Nepal hash listing was selected and traced through StealthMole to determine whether the exact same material had appeared elsewhere.

Same Shelves, Different Shop Signs

The Nepal hash image provided the first clear indication that Party Heaven's product catalogue was not confined to Party Heaven.

When the image was searched through StealthMole, the same artifact appeared across several other Tor domains. What made the results particularly interesting was that these sites were not presenting themselves as Party Heaven mirrors. They carried entirely different names and branding:

  • syorb4**********************************************ccyd.onion Party Pharmacy – Where going to the pharmacy can be FUN
  • ipqqm**********************************************f2eid.onion Dope Temple – In Dope We Trust
  • h5jaug*********************************************rajqd.onion Party Paradise – Come and Join the Party :)
  • lkbp4**********************************************ja2ad.onion Fun Pharmacy – Everyone's Favorite Party Doc

The shared image was enough to put these storefronts on the investigative map, but there were other similarities worth noting. Their names followed a noticeably similar theme, while the storefronts themselves used familiar product-led layouts. Fun Pharmacy, for example, displayed 45 products through a Shop, FAQ, Cart and Checkout structure that closely resembled what had already been observed on Party Heaven. Its catalogue included products such as Generic Viagra and Adderall alongside other drugs and pharmaceuticals.

A second image pivot reinforced the pattern. The same morphine.jpg seen across these storefronts was searched by its exact file hash in StealthMole, which associated it with nine Tor domains. Among them were Party Heaven and additional instances of familiar brands:

  • efcygzbnh5fow3jl5gr6rudejbw7yabixe4c5ggo5iw2mnqlz3yxaqqd.onion Dope King – The King of Partying
  • sloxx2hmdsdme4lynn77old67f52nadaed4rpqbyjnyt54divsqny7id.onion Party Animals – Everything For Your Party Needs
  • yjzto6mzyns4wwwckdbjgdrp3nepbjv4wvm2knqzbx3ycx7udchhlbqd.onion Partylicious – The Party Pros

Together, the two image pivots showed the same product material recurring across differently branded storefronts. That was enough to widen the investigation, but not enough to establish common ownership. Product images and storefront templates can be copied or reused, so these domains were treated as content-overlap leads rather than Party Heaven mirrors.

The Wallet That Actually Moved

The first Bitcoin address provided little room to continue.

  • bc1q********************************lmt

Although the address had appeared directly on Party Heaven's checkout page as a payment option, checking its blockchain history showed no transactions. Whatever its intended purpose on the storefront, there was no financial activity to follow.

The second address told a very different story:

  • bc1q0********************************500lkr

Running it through StealthMole first produced another Party Heaven onion:

  • W543gjeqesapphdx7gtu7cepkp2i2k6cfmcvczt4au4szknsd6d7afid.onion

This domain was no longer active. Its association with the Bitcoin address nevertheless provided another route into Party Heaven's past and added a further onion address to the growing collection of storefront infrastructure uncovered during the investigation.

This time, however, the blockchain itself also had something to say.

StealthMole's Crypto Tracker showed activity associated with the wallet stretching across several years. The address first received Bitcoin on January 7, 2022, and its last recorded incoming transaction occurred on January 28, 2025. Outgoing activity began on March 25, 2022 and continued until May 18, 2025.

StealthMole's Crypto Tracker also flagged transaction relationships involving addresses attributed to Crypto.com Exchange and Paxos. These connections were useful investigative markers, but they did not identify whoever was behind Party Heaven. A blockchain interaction with an address associated with an exchange or financial service does not, by itself, establish that the Party Heaven operator personally maintained an account there, nor does it reveal the identity of an account holder.

The more consequential finding came from the inactive Party Heaven domain discovered through the wallet.

When w543gjeqesapphdx7gtu7cepkp2i2k6cfmcvczt4au4szknsd6d7afid.onion was examined further in StealthMole, it produced 25 Bitcoin addresses associated with its historical records.

That changed the scale of the investigation again. Until this point, the connections around Party Heaven had largely emerged through mirrors and reused product content. The new dataset provided something different: a collection of cryptocurrency artifacts that could each be followed independently.

Bitcoin Wallets and a Lot More Than Party Heaven

The 25 Bitcoin addresses associated with the inactive Party Heaven domain offered 25 possible directions for the investigation. Most did not provide meaningful blockchain activity, but searching the addresses through StealthMole produced something arguably more useful: several of them appeared alongside other dark web storefronts.

The full set identified from the Party Heaven domain was:

  • Bc1qj*********************************d5fe
  • Bc1ql*********************************lf4u
  • Bc1qr********************************cj640
  • Bc1qj********************************8z9ke
  • Bc1qw*********************************fy4m
  • Bc1q7*********************************yevk
  • Bc1qn*********************************q72q
  • Bc1q7*********************************z3ew
  • Bc1qn*********************************eeyv
  • Bc1qa*********************************gd7d
  • Bc1q3*********************************mfvc
  • Bc1qe*********************************j3a8
  • Bc1qc*********************************87s7
  • Bc1q8*********************************wuaf
  • Bc1q0*********************************0lkr
  • Bc1qp*********************************zs2p
  • Bc1qm*********************************q3uq
  • Bc1q3*********************************h775
  • Bc1qs*********************************z48y
  • Bc1q3*********************************h8nv
  • Bc1q2*********************************y342
  • Bc1q8*********************************dktk
  • Bc1qy*********************************pzjy
  • Bc1ql*********************************v9w2
  • Bc1qy*********************************0v0r

Several addresses immediately opened doors into storefronts carrying names that felt increasingly familiar.

The address bc1qly********************lf4u appeared in connection with an inactive shop called “Party Animals – Everything For Your Party Needs”:

  • Sloxx2hmmc7gdkzkzkkfsvicrrmibx6fxffckjzetlgesithy4mq7oad.onion

Another address, bc1q7dy**********************z3ew, led to “Dope King – The King of Partying”:

  • efcyaq3453xjisugllr4lazoedyo6pthhc4j5tpl5cyoihp6huscnpqd.onion

Then came Party Paradise. The address:

  • bc1qs************************************z48y

was associated with an inactive storefront titled “Party Paradise – Come and Join the Party :)” at:

  • H5jauggmlbo3ntusetik6uvylwckmjwixaab4htnddoy65qki7ibk2id.onion

Its archived storefront contained 36 products, with product names and imagery again resembling material encountered elsewhere during the investigation.

The same Bitcoin address also appeared in connection with another inactive onion titled Silver Magazine:

  • 7lr3qeslthipebdvn424wwvb272eowsrw33fracoqjpeohj66hvff3id.onion

That association was recorded, but deliberately not treated as evidence that Silver Magazine formed part of the same drug-storefront cluster. The nature of the site differed substantially from the other findings, and an indexed wallet relationship without further context was not enough to establish why the address appeared there.

Another unexpected result came from:

  • bc1q3****************************mh8nv

StealthMole associated the address with an inactive weapons storefront titled “Guns"R"Us – The 2nd Amendment Store”:

  • 7vugm3oxle3e6z5v2snu5fwvbgajqmt2hw3hgqviaafaqd2levfsubid.onion

Again, the finding was kept separate from the developing drug-storefront cluster. Without additional evidence explaining the relationship, folding an unrelated weapons shop into the network simply because an address appeared in both datasets would have gone beyond what the evidence could support.

Other pivots stayed much closer to the pattern already emerging.

  • bc1q8******************************dktk

led to “Drugazon – The Amazon of Drugs”:

  • 4wmicvgfw2nodbvlj7ovvfwyxr5guj64sqtnkvwhjtcmonc4ywabvoad.onion

StealthMole had first scanned Drugazon on March 10, 2025, with its last recorded scan on November 19, 2025. Its orange colour scheme distinguished it visually from Party Heaven, but underneath the different branding the similarities were difficult to miss. The archived shop displayed 40 products through the same familiar Shop, FAQ, Cart and Checkout structure, while numerous product photographs, names and prices closely resembled those already observed on Party Heaven.

Finally,

  • bc1ql****************************v9w2

surfaced another inactive storefront, Dopassic Park, at:

  • Hyzmpq2fo637gfuerzwtqzqcpgmu2kyhibd3kfx6aq2vgtniz3eu2rqd.onion

By now, the investigation had reached a very different place from where it started. A single Party Heaven domain had led to a historical mirror, that mirror had exposed a collection of Bitcoin artifacts, and those artifacts were repeatedly surfacing alongside differently branded dark web shops. Not every association carried the same weight, and some were intentionally set aside rather than forced into the emerging picture.

Party Paradise Opens Another Ledger

Party Paradise was worth examining more closely because the connection no longer rested on product imagery alone. The domain had already surfaced through a Bitcoin address found within the Party Heaven-associated dataset, giving the investigation a financial artifact that could be tested from the other direction.

The storefront in question was:

  • H5jauggmlbo3ntusetik6uvylwckmjwixaab4htnddoy65qki7ibk2id.onion

When this domain was investigated independently in StealthMole, Darkweb Tracker returned 21 Bitcoin addresses associated with its historical records:

  • Bc1q**********************************h8nv
  • Bc1q8*********************************wuaf
  • Bc1qy*********************************nphx
  • Bc1q8*********************************sgya
  • Bc1qn*********************************eeyv
  • Bc1qc*********************************87s7
  • Bc1q3*********************************mfvc
  • Bc1qa*********************************gd7d
  • Bc1q7*********************************z3ew
  • Bc1qe*********************************j3a8
  • Bc1q**********************************xayr
  • Bc1q**********************************7jja
  • Bc1q**********************************ejmg
  • Bc1q**********************************u69a
  • Bc1q**********************************jkxj
  • Bc1q**********************************aaf6
  • Bc1q**********************************yevk
  • Bc1q**********************************z48y
  • Bc1q**********************************cvat
  • Bc1q**********************************4rce
  • Bc1q**********************************lyzl

The list became much more interesting when it was compared with the 25 addresses previously surfaced from the Party Heaven-associated onion. Ten Bitcoin addresses appeared in both datasets:

  • Bc1q************************************h8nv
  • Bc1q************************************wuaf
  • Bc1q************************************eeyv
  • Bc1q************************************87s7
  • Bc1q************************************mfvc
  • Bc1q************************************gd7d
  • Bc1q************************************z3ew
  • Bc1q************************************j3a8
  • Bc1q************************************yevk
  • Bc1q************************************z48y

This was a more meaningful overlap than the visual similarities that had first drawn attention to the other storefronts. Party Paradise and the Party Heaven-associated domain were not connected by a single address appearing somewhere in StealthMole's historical data. Nearly half of the Bitcoin artifacts identified for this Party Paradise instance were also present in the Party Heaven-derived set.

Conclusion

What began as a closer look at a single drug storefront ultimately revealed a much broader collection of relationships. Party Heaven appeared across multiple onion addresses, while pivots through its cryptocurrency artifacts and product imagery repeatedly surfaced differently branded shops such as Party Paradise, Party Animals, Dope King, Drugazon, Dopassic Park and others.

The strongest indication of a deeper connection came from the cryptocurrency data. Party Paradise independently surfaced 21 Bitcoin addresses, ten of which overlapped with the 25-address dataset associated with a Party Heaven domain. Combined with recurring product imagery, similar storefront structures and multiple instances of the same brands, the findings suggest these sites were not simply isolated shops encountered by chance.

What the evidence does not establish is equally important. It cannot confirm that every storefront identified in the investigation was operated by the same individual or group. Some relationships were considerably stronger than others, and shared content or indexed cryptocurrency artifacts alone cannot prove common ownership. What StealthMole did reveal, however, was a persistent and interconnected footprint surrounding Party Heaven that extended well beyond the single active storefront where the investigation began.

Editorial Note

Dark web investigations rarely produce absolute answers, particularly when storefronts change domains, reuse content, rotate cryptocurrency addresses, or disappear altogether. The connections identified in this investigation should therefore be understood according to the strength of the underlying evidence rather than treated as proof of common ownership.

The Party Heaven case demonstrates how StealthMole can help navigate that uncertainty by bringing historical Tor records, cryptocurrency artifacts, archived storefronts and recurring digital content together, allowing relationships to emerge that would be difficult to see from any single data point alone.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com




Labels: ,

From Alias to Identity: Following the Digital Footprints Behind a Telegram Drug Seller

Telegram has become an increasingly convenient marketplace for illicit drug sellers. The same features that make the platform useful for ordinary communication, including public channels, direct messaging and easy-to-create accounts, also allow dealers to advertise products, reach potential buyers and operate behind usernames that reveal very little about who is actually running them. Cannabis sellers are particularly easy to come across, with accounts openly posting photographs of marijuana, prices and contact details while maintaining little obvious connection to a real-world identity.

But an alias is only as anonymous as the digital history behind it.

This investigation began with one such Telegram-based drug seller. At first glance, there was little to distinguish the account from countless others advertising cannabis through the platform. Rather than treating the visible Telegram profile as the end of the trail, the investigation used StealthMole to look beyond what was currently available and examine the historical traces surrounding the account.

This report follows that investigation from its starting point, showing how a trail scattered across Telegram history, leaked data and other online records was pieced together one artifact at a time.

The Account That Started It All

The investigation began with a deliberately broad search. Using StealthMole’s Telegram Tracker, we searched for “weed dealer” to see whether an openly advertised drug-selling account could be taken beyond what was immediately visible on Telegram. The query returned 14 user records and approximately 80 messages, providing several possible starting points.

One account stood out almost immediately. It appeared in the results under the name Weed Dealer | UG 🆓 🌱SEED 🐦 🍅 🐾/WAVE 🌊, with the Telegram username @tieuho****0. Unlike accounts that merely mentioned cannabis or appeared in conversations about drugs, this profile was notable because it presented itself directly as a weed dealer. That made it a more relevant target for examining whether an apparently pseudonymous Telegram seller could be followed through StealthMole’s historical data.

Looking at the account as it exists more recently, however, revealed surprisingly little. The profile displayed the name Tiêu Hồ, carried no profile photograph, and offered few obvious clues about the person behind it. Searching the account itself in Telegram Tracker changed that picture.

StealthMole associated the account with the persistent Telegram ID 1068143976 and preserved 25 historical name records, showing that its visible identity had changed repeatedly over the years. The historical snapshots were considerably more revealing than the current profile. Earlier versions contained multiple photographs of what appeared to be the same individual, while other snapshots shifted toward cannabis-related imagery and drug-oriented profile names.

Some of those historical photographs also exposed details that would no longer be apparent from viewing the account today. In a snapshot dated 22 December 2022, the individual was photographed standing in front of a dark vehicle with the registration plate 79A-2******8 clearly visible. Another snapshot, dated 28 February 2023, showed him alongside a white Mercedes-Benz displaying a second plate, 79A-3*****7.

The first plate offered an immediate external point of comparison. A search for 79A-2******8 produced an exact match on PlatesMania, where an independently photographed dark Lamborghini Urus, first generation (2018–2022) carried the same registration. The listing identified the plate as Vietnamese, registered in Khánh Hòa Province, and placed the photographed vehicle in Phước Long, Nha Trang. The image had been posted by a contributor using the name Bún bò on 17 January 2025 at 1:08:27 PM.

A Wallet That Wasn’t a Wallet

With the profile history offering several clues but no clear identity, the investigation moved to another artifact associated with tieuho****0: an Ethereum address.

  • 0x09c*****************************638

At first, the address looked like a promising cryptocurrency lead. If it belonged to the seller, its transaction history could potentially reveal another part of the account’s digital footprint. Consequently, the address was searched further in StealthMole’s Telegram Tracker.

The search returned several user records and messages mentioning the address. Among them was one result that could be tied directly back to the account being investigated. On 13 May 2023, Telegram ID 1068143976, appearing at the time as Seller | UG//@tieuho****0, had posted the address in a channel. The message read “Happy mother's day”, followed by the Ethereum address and an attached photograph.

The direct match confirmed that the address had indeed been shared by tieuho****0, but a closer examination changed what the artifact meant. Etherscan identified it not as a personal Ethereum wallet, but as a smart contract associated with the ERC-20 token mother (MOTHER). At the time of examination, the contract showed 1,436 transactions. Other Telegram results provided further context, including a message from the 0xGemi channel that referred to the same address as “Mother Contact” while discussing the token.

A search through StealthMole’s Dark Web Tracker produced another apparent lead. The contract address appeared within an indexed onion page containing Polygon ERC-1155/NFT transaction data. The record included Polygon transaction:

  • 0x09************************************************3a43

and was indexed from:

  • 3xplor3****************************************xyd.onion

One Alias, More Than One Footprint

After investigating the cryptocurrency, the investigation returned to the simplest artifact available: tieuho****0. This time, instead of looking at Telegram, the username was searched through StealthMole’s Dark Web Tracker to determine whether it had surfaced in previously leaked or indexed data.

One leaked document contained a record for tieuho****0 that matched the same Telegram ID 1068143976 already established through Telegram Tracker. That match was important because it provided continuity between the Telegram profile and the newly discovered record. More importantly, the entry contained several fields that had never been visible from the Telegram account itself:

  • Telegram Username: tieuho****0
  • Telegram ID: 1068143976
  • Referrer Username: thuytienbtc
  • Referrer ID: 5071132186
  • Invited: 0
  • Tokens: 2000
  • Email: tieuho****0@gmail.com
  • Wallet: 0xdFc**********************************695
  • Twitter: https://mobile.twitter.com/tieuho****0
  • Review: https://twitter.com/AirdropDet/status/1509606654905421833

The wallet field was more immediately actionable. Unlike the MOTHER contract encountered earlier, the record explicitly labelled the new ETH wallet as associated with the tieuho****0 entry. The combination of the exact username and Telegram ID made this a substantially stronger lead, although the leaked dataset alone could not establish that the person controlling the Telegram account also controlled the address.

  • 0xdFc******************************695

The wallet was therefore checked independently. Etherscan showed an address with 165 transactions, rather than another token contract. It held no ETH at the time of examination and approximately $0.07 across 18 token holdings, while its historical activity showed both incoming and outgoing transactions. Etherscan also indicated that the address had originally been funded by Binance 17.

StealthMole’s Wallet Risk Check provided a different view of the same activity. The address was flagged as Medium Risk. Of the 147 transactions analyzed by the platform, 22 were flagged as suspicious, representing 15% of the analyzed transactions and approximately 6.7% of the analyzed ETH volume. No blacklisted contacts were identified.

The behavioral indicators were more notable. StealthMole flagged Abnormal Relaying, Abnormal Mixing, and Relaying and Mixing, alongside a dormant transaction status. The last transaction recorded by the platform was dated 18 April 2025.

The transaction graph also showed how widely the address had interacted across the cryptocurrency ecosystem. Labeled nodes included Binance Exchange, Bitget Exchange, Bybit Exchange, MEXC Global Exchange, OKEx Exchange, Uniswap, Orbiter Finance Bridge, MetaMask-related contracts and routers, and a Binance User Wallet.

None of those labels, or the Medium Risk score itself, demonstrated that the wallet had been used to receive proceeds from drug sales. Likewise, StealthMole's detection of mixing and relaying patterns should not be treated as proof of money laundering. What the analysis established was narrower but still valuable: a wallet explicitly attributed to tieuho****0 by a leaked record had an extensive transaction history and displayed several behaviors that StealthMole considered worthy of additional scrutiny.

The leaked record had also introduced something the blockchain could not answer: an email address. That provided the investigation with a completely different route away from cryptocurrency and toward the identity behind the account.

The Password That Connected Two Identities

The email tieuho****0@gmail.com found in the leaked record opened a different line of investigation. Instead of looking for more blockchain activity, the next step was to determine whether tieuho****0 had appeared in credential data indexed by StealthMole.

A search in Combo Binder returned 63 results. tieuho****0@gmail.com appeared with several variations of the same password, built around Ban*****5, including versions with different capitalization and special characters.

Rather than treating the credential itself as the finding, the password became another search term. Searching the exact leaked password in Combo Binder produced a second email address:

  • ban*******5@gmail.com

This was more interesting than a simple similarity between usernames. Both tieuho****0@gmail.com and ban*******5@gmail.com appeared in compromised credential data with the same exact password. The ban******5 identifier was also embedded directly in the password family repeatedly associated with the first email address.

With ban*******5@gmail.com now providing a second account to examine, the investigation moved beyond leaked credentials to see what was publicly associated with the two email addresses. Checking the addresses through Google produced profile photographs for both accounts. The profile associated with tieuho****0@gmail.com displayed a photograph of a man, while ban*******5@gmail.com displayed a photograph of a woman.

The second image was particularly important because it introduced uncertainty rather than resolving it. Although ban*******5@gmail.com shared the exact leaked password associated with tieuho****0@gmail.com, its Google profile did not provide additional evidence that the address was controlled by the same individual. Instead, it reinforced the need to treat the email as a connected account or investigative lead rather than automatically assigning ownership to the person behind tieuho****0.

When the Alias Finally Had a Name

The search for tieuho****0@gmail.com in Dark Web Tracker produced another leaked CSV record. Unlike the earlier dataset, which had mainly exposed online identifiers, this entry contained information that appeared to move the investigation much closer to a real-world identity.

The matching record contained:

  • Location: Khánh Hòa
  • Name: Hồ Quốc Thanh
  • Email: tieuho****0@gmail.com
  • Phone: +84*********39
  • User/Record ID: 60e****************48
  • Code: qeabag8
  • Related ID: 60e06f9e9c9bb00d4bbc9ae2
  • Related Name: Lê Xuân Ngọc
  • Related Number: 382966254
  • Related Code: ykbpyy6
  • Status: NO

For the first time, Hồ Quốc Thanh appeared directly alongside the email address that had already been connected to tieuho****0 through the previous searches. The record also introduced a Vietnamese phone number and listed Khánh Hòa as the location.

The location was particularly notable in light of an earlier, completely different part of the investigation. The two vehicle plates visible in the historical Telegram photographs carried the 79 Khánh Hòa registration code, and the independent PlatesMania sighting of 79A-2******8 had placed that Lamborghini Urus in Phước Long, Nha Trang. Now, a leaked record connected to the account's email independently pointed to Khánh Hòa as well. Neither finding proved where the individual lived, but the same region emerging through unrelated artifacts made the geographic connection harder to dismiss as incidental.

The more immediate question was whether Hồ Quốc Thanh existed elsewhere in StealthMole's indexed data.

Searching the name in Dark Web Tracker produced a social-media record for the Twitter account:

  • https://twitter.com/ban*****5

The account was indexed under the name Hồ Quốc Thanh, with the Twitter ID ban****5 and email address:

  • ban*******5@gmail.com

That result brought the investigation back to an identifier discovered through an entirely different route. ban*******5@gmail.com was the same second email uncovered when the leaked credential associated with tieuho****0@gmail.com was pivoted through Combo Binder.

The connection had therefore come together from two directions. Credential data had linked tieuho****0@gmail.com and ban*******5@gmail.com through exact password reuse. Separately, Dark Web Tracker associated tieuho****0@gmail.com with the name Hồ Quốc Thanh, while another indexed record associated ban*******5@gmail.com and Twitter ID ban******5 with that same name.

Conclusion

What began as a broad search for a weed dealer on Telegram eventually moved far beyond the profile that first appeared in the results. Historical Telegram data exposed earlier photographs and vehicle registrations, cryptocurrency artifacts opened additional investigative paths, and leaked records introduced identifiers that were no longer visible from the account itself. Some of those leads went nowhere, while others became more meaningful only when they appeared again through a completely different source.

The strongest point of convergence was Hồ Quốc Thanh. The name appeared in a leaked record alongside tieuho****0@gmail.com, while the same email had already emerged through the investigation of the Telegram account and compromised credential data. A separate record then associated the same name with the ban******5 Twitter identity and ban*******5@gmail.com, an address independently connected to tieuho****0@gmail.com through exact password reuse. The geographic evidence added another layer: the leaked record placed Hồ Quốc Thanh in Khánh Hòa, the same province indicated by both vehicle registrations recovered from historical Telegram photographs.

Together, these findings provide a credible basis for assessing Hồ Quốc Thanh as a likely real-world identity associated with tieuho****0, but they stop short of definitive attribution. The investigation does not establish ownership of the photographed vehicles, prove that the attributed cryptocurrency wallet received proceeds from drug sales, or demonstrate that every connected email and social-media account was controlled by the same individual.

That distinction matters. The value of this investigation was not simply finding a name at the end of a search. It was seeing how an account that currently reveals very little had accumulated enough fragments across Telegram history, leaked databases, credentials, cryptocurrency records and other online sources for an alias to gradually become much less anonymous.

Editorial Note

Attribution in underground ecosystems is rarely absolute. Usernames change, infrastructure is shared, and associations do not always imply common ownership. This investigation shows how StealthMole's historical records and cross-source pivots can help navigate that uncertainty, connecting activity across changing identities while keeping the line between what the evidence establishes and what remains unknown.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com









Labels: ,

The Many Faces of ModernStealer: Tracing an Underground Military Data Network

Underground data markets are filled with sellers offering stolen databases, compromised credentials, and confidential records. But military and defence-related data sits in a different category. Claims involving classified documents, military personnel, defence institutions, drone technology, or internal government communications naturally carry greater significance, while also raising an important question: who is actually behind these listings, and how many seemingly different sellers are truly independent?

ModernStealer emerged as one such identity, appearing across underground forums with posts advertising military and defence-related material from multiple countries. At first glance, the activity appeared to belong to a single forum user operating under a recognizable alias. But as the investigation moved beyond the username and into the contact details left behind in these posts, the picture became more complicated. The same identifiers began appearing alongside other accounts, other aliases, and similar offerings across different corners of the underground ecosystem.

Using StealthMole to follow these traces across dark web forums and Telegram, this investigation examines the digital footprint surrounding ModernStealer and the identities that appear to intersect with it. Rather than assuming that every matching alias belongs to the same person, the report follows the identifiers themselves, looking at where they reappear, how the connections develop, and what those overlaps can tell us about the network operating behind a series of military and government data offerings.

The Thread That Started It All

The investigation began with a post on DarkForums where ModernStealer was offering what appeared to be sensitive documents related to a defence agreement between Türkiye and Pakistan. The thread, titled "[PK] TUR-PAK DEFENSE DRONE DEAL," immediately stood out because the material being advertised was not a typical database or credential dump, but a document concerning defence cooperation and drone technology.

The post described a 23-page confidential document titled "TURKEY-PAKISTAN BAYKAR-NASTP COOPERATION: STRATEGIC DEFENSE INDUSTRIAL PARTNERSHIP, TECHNOLOGY TRANSFER PROSPECTS AND DRONE PROCUREMENT." According to the description provided in the listing, the document covered cooperation involving Baykar Teknoloji and Pakistan's National Aerospace Science and Technology Park (NASTP), including areas such as unmanned systems, technology transfer, joint research and development, industrial collaboration, training, localization, and potential drone procurement.

  • https://darkforums.**/Thread****PK-TUR-PAK-DEFENSE-DRONE-DEAL

The listing itself was enough to make ModernStealer worth a closer look. A seller claiming access to confidential defence material involving drone technology raised the question of whether this was an isolated offering or part of a broader pattern. At this point, however, there was no basis to assume that ModernStealer had personally obtained the document through a breach, or even that the advertised material was authentic. What the thread did provide was a clear starting point: an underground identity openly associated with the alleged sale of sensitive defence-related information.

More importantly, the post contained an artifact that could be followed beyond the thread itself. ModernStealer had included the following Session ID as a contact point:

  • 05214b***********************************************f6163

Unlike the claims surrounding the advertised documents, the Session ID provided something concrete that could be searched and compared across StealthMole's indexed data. What began with a single defence-related listing now had a potential trail to follow, and the next step was to find out where else the same identifier had appeared.

A Pattern Begins to Emerge

Before following the Session ID beyond ModernStealer's own activity, we first wanted to understand whether the TU-PAK drone deal was an isolated listing or part of something larger. Searching the keyword "ModernStealer" in StealthMole's Leaked Monitoring tool returned five listings detected between March and April 2026.

Among the results were listings involving the Pakistan Nuclear Regulatory Authority (PNRA), Pakistan's National University of Sciences and Technology (NUST), and a database allegedly containing information belonging to Lockheed Martin employees. Another result concerned the Sri Lanka Air Force. While the nature and authenticity of these advertised datasets could not be established from the listings alone, their appearance under the same actor name suggested that the defence-related material seen in the TU-PAK thread was not an isolated occurrence.

The search was then extended to StealthMole's Government Monitoring tool to see whether the same name appeared in connection with government entities. This returned eight listings associated with ModernStealer between March and July 2026. Among them were posts concerning alleged internal documents from the Bangladesh military, Pakistan's SUPARCO and Ministry of Science and Technology, and a listing referencing the PLA, CIA, Department of Defense, and DARPA.

Together, the results began to show a recurring theme around the ModernStealer identity. The listings repeatedly touched on military, defence, government, nuclear, aerospace, and science-related organizations. This did not establish that ModernStealer had personally breached each of these entities, nor did it confirm that every dataset being advertised was authentic. But it did show that the TU-PAK drone deal was part of a much broader pattern of sensitive data offerings associated with the same name.

One of those listings offered a particularly useful opportunity to look closer. The thread concerned an alleged database belonging to the Pakistan Nuclear Regulatory Authority (PNRA) and was available at:

  • https://darkforums.**/Thr*****PK-Nuclear-Regulatory-Authority-PNRA-DATABASE

In the post, ModernStealer claimed to have compromised PNRA's mail server and obtained more than 60 databases, with 17 databases totaling approximately 3.2 GB being offered for sale. The actor claimed that the material included information related to nuclear reactor and chemical laboratory locations, employees, email addresses, sensitive documents, and infrastructure. These claims remained unverified, but one detail in the post was immediately familiar.

ModernStealer had again provided the same Session ID:

  • 05214b**********************************************f6163

The identifier first encountered in the TU-PAK drone deal was therefore not confined to a single listing. It has now appeared again in another sensitive post attributed to ModernStealer. With the same contact point recurring across separate offerings, the Session ID became more than a detail buried inside a forum post. It became the most promising artifact to follow beyond ModernStealer's own activity.

Following the Session ID

With the Session ID now appearing across more than one ModernStealer listing, the next step was to search the identifier directly in StealthMole's Dark Web Tracker. The results widened the investigation almost immediately. At least 30 indexed threads contained the same identifier, suggesting that its use extended well beyond the ModernStealer posts examined so far.

Among those results was a thread on Breached titled "Pakistan Military Procurement and Defense Deals," posted by a user named Zu1f1q4r:

  • https://breached.**/threads/pakistan-military-procurement****99/

The post concerned alleged contract and procurement information related to Pakistan's defence dealings with China and Türkiye. But it was the contact information at the bottom of the post that mattered most to the investigation. Zu1f1q4r had provided the exact same Session ID previously used by ModernStealer:

  • 05214***************************************************f6163

Alongside it was another identifier that had not appeared in the ModernStealer posts examined so far, a Tox ID:

  • 65BB****************************************************BC9D

The appearance of the same Session ID under a different username created the first clear overlap between ModernStealer and another underground identity. To understand whether this was a one-time occurrence, we looked further into Zu1f1q4r's activity and identified the actor's Breached profile:

  • https://breached.**/members/zu1f1q4********8/

The trail did not stop with the military procurement post. Another thread by Zu1f1q4r concerned an alleged leak involving Pakistan's Intelligence Bureau:

  • https://breached.**/threads/intelligence-bureau-pakistan****1/

Once again, the post listed the same Session ID and the same Tox ID as contact points.

A third thread followed the same pattern, this time involving alleged documents from Pakistan's Federal Investigation Agency (FIA):

  • https://breached.**/threads/pakistan-fia-documents******0/

Here too, Zu1f1q4r provided the same pair of identifiers.

The repeated overlap was difficult to ignore. ModernStealer and Zu1f1q4r were operating under different names, but the same Session ID appeared as a contact point in posts associated with both identities. Zu1f1q4r then repeatedly paired that identifier with the same Tox ID across multiple Pakistan-focused listings.

At this stage, however, the evidence did not establish that ModernStealer and Zu1f1q4r were the same person. The Session ID could have been shared between members of a group or used as common contact infrastructure. The Tox ID also remained directly associated only with Zu1f1q4r, since it had not been observed in any ModernStealer post examined during the investigation.

From the Dark Web to Telegram

The Session ID had already connected ModernStealer's DarkForums activity with posts published by Zu1f1q4r on Breached. But underground actors rarely limit their activity to a single type of platform. To see whether the same identifier had travelled beyond dark web forums, we searched it again, this time using StealthMole's Telegram Tracker.

The search led to a message posted in the Telegram channel:

  • https://t.me/Hexvi********ach

The message came from a user identified as Sassoon Don, operating under the Telegram username S*********n. In it, the user was looking for classified documents related to Ukraine and five Central Asian countries, apparently for China, and asked anyone with access to such material to contact them through Session.

The Session ID provided in the message was immediately recognizable:

  • 05214************************************************6163

It was the exact same identifier that had already appeared in posts by ModernStealer and Zu1f1q4r.

This was an interesting shift in the investigation. Until this point, the Session ID had appeared alongside actors advertising alleged military and government data. The Telegram message showed an account using the same contact point while actively seeking classified material, adding another dimension to the activity surrounding the identifier. It did not establish how any of the previously advertised material had been obtained, but it raised the possibility that the network around the Session ID was interested not only in distributing sensitive information, but also in sourcing it.

StealthMole's Telegram data allowed the account itself to be examined further. The user Sassoon Don was associated with the immutable Telegram User ID:

  • 7605334264

Searching the user profile revealed only two indexed messages, leaving relatively little historical activity to work with. StealthMole also showed the account appearing across three Telegram channels:

  • 3990978039: https://t.me/I********d
  • 3646663287: https://t.me/N********T
  • 3542147875: https://t.me/Hex*******h

These channel associations were useful as contextual information, but they were not treated as evidence of ownership or affiliation. Simply appearing in or being a member of a Telegram channel does not establish an operational relationship with the people running it.

More importantly, the investigation had not yet found another contact identifier in Sassoon Don limited Telegram history that could independently connect the account to ModernStealer. At this point in the investigation, the connection rested on one persistent artifact: the same Session ID.

The trail now involved three different identities across dark web forums and Telegram: ModernStealer, Zu1f1q4r, and Sassoon Don. Whether they represented separate actors sharing infrastructure, members of the same operation, or different identities controlled by one person was still unclear.

The Link Back to ModernStealer

The appearance of Sassoon Don on Telegram added another identity to the investigation, but at that point, the connection to ModernStealer still depended on the shared Session ID. To determine whether a more direct link existed, we returned to StealthMole's Dark Web Tracker and began looking more closely at other threads posted under the ModernStealer name.

One of those threads concerned the alleged sale of classified Pakistani military documents:

  • https://darkforums.**/Th***PAKISTAN-CLASSIFIED-MILITARY-DOCUMENTS

This time, the contact details provided at the bottom of the post changed the picture considerably. ModernStealer had listed two ways to get in touch:

  • Session: 05214*******************************************************88163
  • Telegram: @S**********n

The Telegram account discovered through the Session ID search was therefore not simply another user who happened to mention the same identifier. ModernStealer had directly listed Sassoon Don as a contact point in their own forum post.

The same pairing appeared again in another ModernStealer thread:

  • https://darkforums.***/T*******Military-Documents-of-Various-Countries-China-East-Asia-USA-Russia

The post advertised what was described as military material from several countries and regions and again directed interested users to the same Session ID and the same Telegram account, Sassoon Don.

Another thread involving an alleged data leak from Pakistan's National University of Sciences and Technology provided further evidence of the Session ID's repeated use:

  • https://darkforums.***/Threa**DATA-LEAK-OF-NUST-PAKISTAN-DEFENCE

Here, ModernStealer once again used the same Session identifier as a contact point.

The repeated use of these identifiers provided a much clearer connection than the investigation had at the beginning. The Session ID could now be directly tied to multiple posts under the ModernStealer identity, while Sassoon Don had also been explicitly presented by ModernStealer as a Telegram contact across separate listings.

This did not necessarily mean that the person operating the Sassoon Don Telegram account and the person posting as ModernStealer were the same individual. Shared accounts and contact infrastructure remain possible, particularly if ModernStealer represents a team rather than a single operator. But the evidence now establishes a direct operational association between the ModernStealer forum activity and Sassoon Don.

One Contact, Another Name

With Sassoon Don now directly connected to ModernStealer's forum activity, the Telegram username became the next artifact to investigate. Searching "SassoonDon" in StealthMole's Dark Web Tracker surfaced another forum thread, this time on Breached.live:

  • https://breached.*****/showt*************669

The thread, titled "PLA OFFICERS AND OTHER RANKS DATABASE," was not posted by ModernStealer. Instead, the account behind the listing was operating under a different name: PriorOps.

According to the post, PriorOps was offering what was described as a database containing information related to officers and other ranks within China's People's Liberation Army (PLA). The advertised records were said to include details such as rank, position, date of birth, education, career history, operational specialties, and contact information. As with the other listings examined during the investigation, these claims could not be independently verified from the post alone.

But once again, the most useful part of the listing was not necessarily what the actor claimed to possess. It was how they asked to be contacted.

The post listed:

  • Contact: @S********n

The same Telegram username that ModernStealer had explicitly provided in military-related DarkForums posts was now being used as a contact point by PriorOps, another forum identity advertising alleged military data.

This created a more direct overlap than the one previously observed with Zu1f1q4r. In that case, the connection to ModernStealer came through the shared Session ID. Here, both ModernStealer and PriorOps had independently published the exact same Telegram username as their contact point.

By this stage, a pattern was beginning to take shape around the identifiers rather than the names themselves. ModernStealer was directly connected to both the Session ID and Sassoon Don. Zu1f1q4r repeatedly used the same Session ID across several Pakistan-focused listings, while PriorOps used the same Sassoon Don Telegram account in a post involving alleged PLA personnel data.

The overlaps raised an obvious possibility: ModernStealer, Zu1f1q4r, and PriorOps could represent different aliases used by the same operator. But the evidence also allowed for another explanation. The identities could belong to multiple individuals using shared contact infrastructure or operating as part of the same group. The available artifacts were strong enough to establish an operational connection between the identities, but not strong enough to conclusively determine who was sitting behind each account.

What was becoming increasingly clear, however, was that following usernames alone would have missed much of this picture. The names changed from one forum to another, but the contact points did not. The Session ID and Sassoon Don account provided the connective tissue between accounts that, at first glance, appeared to be unrelated.

A Second ModernStealer?

The connections uncovered so far had all developed from contact points that could be traced from one identity to another. But there was another, more obvious lead worth examining. Searching the keyword "ModernStealer" directly in StealthMole's Telegram Tracker surfaced a user using the name ModernStealer.

At first glance, the match appeared significant. But a closer look at the account's history showed why matching usernames alone can be misleading in underground investigations.

StealthMole associated the account with the immutable Telegram User ID:

  • 1628612534

Historical records showed that the same user ID had changed its username multiple times over the years, with six username changes observed in the available data. Among the account's previous identities was @Mirage2022, appearing under names including Myles and Haven.

Looking through the account's older messages revealed one detail that stood out in the context of the investigation. On 3 February 2026, while appearing as Myles / @Mirage2022, the user posted a message asking:

  • “Who knows where I can get drone leaks and blueprints”

The message was difficult to ignore. The investigation itself had begun with ModernStealer advertising documents related to a Türkiye-Pakistan drone deal, and there was a Telegram account that would later use the same username with a documented historical interest in obtaining drone-related leaks and blueprints.

Other messages provided glimpses into the account's broader activity. Historical records showed the user asking others for money, while one conversation included the statement:

  • “No, I’m not Indian, lol”

The comment offered little in the way of reliable attribution. It was a self-reported statement made by the user and could not be used to establish nationality or location.

StealthMole also preserved images associated with the account's historical Telegram activity. Among them were screenshots showing payment-related information and material referring to Apple Pay-linkable debit cards, alongside purported balances and prices. While these images added context to the type of underground activity surrounding the account, they did not establish that the user owned the financial accounts shown, controlled the advertised cards, or personally carried out any related fraud.

Taken together, the findings made Telegram User ID 1628612534 an interesting lead. The later use of the exact name and the earlier interest in drone leaks created a notable resemblance to the activity examined elsewhere in the investigation.

But unlike Sassoon Don, this account could not be tied back to ModernStealer through the Session ID or another contact point directly published in the actor's forum posts. No overlap was found with Telegram User ID 7605334264, and the investigation did not uncover another persistent identifier connecting the two accounts.

For that reason, the account remains an unconfirmed branch of the investigation. It may represent another identity connected to ModernStealer, or the username may have been adopted independently. The similarities make the account worth documenting, but they are not enough to merge it into the stronger attribution chain built around the Session ID and Sassoon Don.

Conclusion

What began with a single DarkForums listing involving an alleged Türkiye-Pakistan defence drone deal quickly developed into a much broader investigation. ModernStealer's activity extended across a series of listings involving military, government, nuclear, defence, and aerospace-related material, but it was the contact information left behind in those posts that ultimately proved more revealing than the names attached to them.

By following the Session ID and Sassoon Don across StealthMole's indexed dark web and Telegram data, the investigation uncovered connections that would have been difficult to identify through username searches alone. The same Session ID used by ModernStealer appeared repeatedly in posts by Zu1f1q4r, while the Telegram account directly advertised by ModernStealer was also used as a contact point by PriorOps. These overlaps establish a clear operational relationship between the identities, although the evidence does not conclusively determine whether they represent one person operating under multiple aliases, members of the same group, or separate actors sharing communication infrastructure.

The investigation also surfaced a separate Telegram account using the ModernStealer name, whose historical activity included an interest in obtaining drone leaks and blueprints. Despite the apparent similarities, no persistent identifier was found connecting that account to the stronger attribution trail surrounding the known Session ID and Sassoon Don. It therefore remains an unresolved lead rather than a confirmed part of the cluster.

Ultimately, the ModernStealer investigation shows why the identity displayed beside a forum post is often only the beginning of the story. Usernames changed as the investigation moved between platforms, but certain contact points continued to reappear. Following those identifiers allowed a single military data listing to develop into a wider picture of interconnected underground activity, while also leaving an important question unresolved: whether the many faces surrounding ModernStealer belong to one operator or to a network working behind shared infrastructure.

Editorial Note

Attribution in cyber and dark web investigations is rarely absolute. Shared accounts, reused identifiers, changing usernames, and common infrastructure can create strong connections without necessarily proving that the same individual is behind every identity. This investigation reflects that uncertainty: StealthMole made it possible to follow persistent artifacts across forums and Telegram and uncover relationships that were not immediately visible, while the available evidence still required each connection to be assessed on its own strength rather than treated as definitive attribution.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report