JulyJailbait: Reconstructing an Underground CSAM Ecosystem
Dark web continues to host a wide range of illicit platforms that cater to criminal markets, from stolen data and malware to illegal services and child sexual abuse material (CSAM). While many of these websites disappear as quickly as they emerge, others remain active for years by continuously adapting their infrastructure, replacing seized or abandoned domains, and maintaining access through mirror sites and alternative payment mechanisms. As a result, investigating these platforms often requires looking beyond what is immediately visible to understand how they continue to operate over time.
One such platform is JulyJailbait, also referred to as July Club, a long-running dark web website advertising access to a large collection of illegal material through paid memberships. At first glance, the platform appears to be just another onion service offering subscription-based access. However, its publicly visible pages reveal only a small part of a much broader ecosystem.
This investigation reconstructs that ecosystem using artifacts collected through StealthMole, following a series of investigative pivots that extend beyond the primary website. By correlating historical infrastructure, digital assets, cryptocurrency payment information, and other operational traces, the report demonstrates how seemingly isolated pieces of evidence can be combined to reveal a far more extensive underground network than the website alone suggests.
Following the First Lead
The investigation began with the identification of the primary JulyJailbait onion service:
- julyl************************************************pid.onion
Historical snapshots indexed by StealthMole revealed that the website, also referred to as July Club, advertised subscription-based access to a large collection of illegal material through a simple membership model. The landing page claimed to host more than 8 TB of content and accepted payments in both Bitcoin (BTC) and Monero (XMR) before granting users access to the platform. The site also maintained dedicated login, payment, and FAQ pages, suggesting a structured and persistent operation rather than a temporary or opportunistic deployment.
Rather than limiting the investigation to the visible content of the website, the focus shifted towards identifying reusable artifacts that could reveal additional infrastructure. Historical snapshots, indexed files, payment pages, embedded resources, and other technical elements often persist even as underground services migrate between domains or modify their public-facing pages. These artifacts frequently provide more investigative value than the homepage itself.
Among the indexed files associated with the platform was a logo image named julylail.png. While appearing insignificant at first glance, reusable digital assets such as logos often retain identical cryptographic hashes across multiple deployments. This makes them valuable pivots for infrastructure discovery, particularly when operators reuse the same resources across mirror domains or successive versions of a website.
The image was therefore selected as the next investigative pivot to determine whether it could expose additional infrastructure beyond the primary onion service.
An Image That Led to Mirrors
With the primary website documented, the investigation shifted to the platform's embedded resources in search of reusable artifacts that could reveal additional infrastructure. Among the indexed files associated with the website was a logo image, julylail.png, bearing the JulyJailbait branding. Although visually unremarkable, the image retained a unique SHA-256 hash that made it an ideal investigative pivot.
Rather than searching for domains or keywords, the image itself was queried through StealthMole's Dark Web Tracker. Because StealthMole indexes historical files alongside websites, identical images reused across different services can often expose infrastructure that is not directly linked from a platform's public pages.
The results significantly expanded the scope of the investigation. The same image hash was found across 35 mirror domains associated with JulyJailbait, many of which had never been referenced on the primary website. This demonstrated that the operators had repeatedly reused the identical logo while deploying new domains, unintentionally leaving behind a persistent artifact that connected otherwise independent instances of the platform.
Among the identified infrastructure were both active and inactive mirrors, illustrating the platform's long operational history and its reliance on domain rotation to maintain accessibility. One of the active mirrors proved particularly valuable, as it contained a dedicated page listing both current and historical JulyJailbait domains while distinguishing them from domains the operators claimed were fraudulent or unauthorized. This provided rare insight into how the platform itself documented changes to its infrastructure and attempted to direct users toward legitimate mirrors.
- jjclub********************************************lad.onion
Some of the notable mirror domains identified during the investigation include:
- jjclubumn7vkhyuw.onion (inactive)
- jjclub***********************************************lad.onion (active)
- 232kckhwmfpl6mqqmigunmffkldxp3tbsfvxxwofrdv52ikvxshmzwid.onion (inactive)
- 5am52idv6d2azc2drzmxvstt6y7pozju3ujn7eydqnxdynvkxwl2omad.onion (inactive)
- jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion (inactive)
- cvfdjsmso5ii5twu7kmmpyvbjnggnku4v47vf2xc3m2ochmxfxi722id.onion (inactive)
- tl65h3pazhvh6ewepmlvlwbwtrsl2ap7gox2qoyveem7s44umbfzboyd.onion (inactive)
What initially appeared to be a simple branding asset ultimately became one of the most valuable investigative pivots in the case. Instead of exposing only additional websites, the recovered mirror domains provided new avenues for infrastructure analysis, historical comparison, and financial tracing, allowing the investigation to move beyond the primary onion service and into the wider ecosystem supporting the platform.
Hidden in the Past
The discovery of JulyJailbait's mirror infrastructure provided more than additional access points to the platform. By examining several inactive mirror domains individually, the investigation uncovered historical payment artifacts that no longer appeared on the current deployment. These legacy mirrors effectively served as archived snapshots of the platform's earlier operational infrastructure, preserving cryptocurrency wallets that had since been replaced.
Across the investigated mirror domains, 17 additional Bitcoin wallets were identified. None of these wallets had been observed on the primary JulyJailbait website, indicating that the platform had periodically refreshed its payment infrastructure while continuing to operate under the same branding. Unlike the cryptocurrency artifacts recovered from the active website, these historical wallets showed no overlap with other underground services during this investigation, suggesting they belonged to an earlier phase of the platform's operation.
232kckhwmfpl6mqqmigunmffkldxp3tbsfvxxwofrdv52ikvxshmzwid.onion
This inactive mirror proved to be the richest source of historical payment artifacts, revealing seven Bitcoin wallets that were not observed elsewhere during the investigation:
- bc1qj**********************************qj8
- bc1qv**********************************h8r
- bc1q8**********************************hvm
- bc1qf**********************************96x
- bc1qe**********************************hkt
- bc1qa**********************************9fv
- bc1qr**********************************nrr
5am52idv6d2azc2drzmxvstt6y7pozju3ujn7eydqnxdynvkxwl2omad.onion
Analysis of this inactive mirror identified a single Bitcoin wallet associated with the platform:
- 15UN**************************1SH
jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion
This mirror preserved two historical Bitcoin wallets:
- 18P3**************************7Stc
- 16Uyc*************************GwjW
cvfdjsmso5ii5twu7kmmpyvbjnggnku4v47vf2xc3m2ochmxfxi722id.onion
Investigation of this mirror recovered three Bitcoin wallets:
- 1PnfX*************************SES
- 1gY3w*************************czN
- 18P3F************************7Stc
Notably, the wallet 18P3F16UoQm5rEAJPXbE5p4ERYUPNS7Stc had already been observed on jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion, making it the only historical Bitcoin wallet reused across multiple archived deployments identified during this investigation.
tl65h3pazhvh6ewepmlvlwbwtrsl2ap7gox2qoyveem7s44umbfzboyd.onion
The final investigated mirror yielded three additional Bitcoin wallets:
- 1FUoh**************************qbb
- 1LBvk**************************PHk
- 1GUgu**************************31h
Beyond the archived onion services, the active mirror jjclub**************hlad.onion contained a dedicated page documenting the platform's historical infrastructure. Alongside previous onion services, the operators also referenced several surface web domains, including julyjailbait.com, julyjailbait.net, julyjailbait.org, and julyjailbait.me, while separately identifying domains they considered fraudulent or unauthorized. Although these references originate from the operators themselves and should not be treated as independently verified infrastructure, they provide valuable insight into how the platform documented its historical presence and attempted to distinguish legitimate domains from impersonation sites.
Rather than functioning solely as backup websites, the historical mirrors preserved intelligence that no longer existed on the active platform. By examining these archived deployments individually, the investigation reconstructed an earlier stage of JulyJailbait's financial infrastructure, providing a broader historical perspective that would not have been possible through analysis of the primary website alone.
Following the Financial Footprint
One of the most valuable sources of intelligence recovered from the primary JulyJailbait website was its cryptocurrency payment infrastructure. The publicly accessible payment page accepted both Bitcoin (BTC) and Monero (XMR), with users required to complete a cryptocurrency payment before gaining access to the platform. Rather than treating these wallets solely as payment addresses, each one was used as an investigative pivot within StealthMole to determine whether the same infrastructure appeared elsewhere across the underground ecosystem.
The investigation identified 10 Bitcoin wallets and 5 Monero wallets associated with the primary JulyJailbait domain. While several of these wallets appeared to be exclusive to the platform, others were reused across multiple underground services, exposing links that were not apparent through website analysis alone.
Bitcoin Wallets Identified
Bitcoin Wallet | Additional Infrastructure Identified |
bc1q*********************4gu | JulyJailbait, Alice |
bc1q*********************6f6 | JulyJailbait only |
bc1qc********************708 | JulyJailbait, MOE Connect, WormGPT |
bc1q8********************90r | JulyJailbait, MOE Connect |
bc1qg*******************50a | JulyJailbait only |
bc1qp********************g3f | JulyJailbait only |
bc1qy**********************ymm | JulyJailbait, MOE Connect |
bc1qj**********************ddp | JulyJailbait, KidBin, Snapchat account hacking service |
bc1q8********************gmt | JulyJailbait, WormGPT |
bc1qp********************ha5q | JulyJailbait only |
The Bitcoin infrastructure showed a mixture of exclusive and shared payment addresses. While several wallets appeared unique to JulyJailbait, others were reused across services such as WormGPT, MOE Connect and KidBin, suggesting that elements of the payment infrastructure extended beyond a single platform.
Monero Wallets Identified
Monero Wallet | Additional Infrastructure Identified |
86c3CZ********************qA1y | JulyJailbait, WormGPT, FraudGPT, Darkweb Porn, Daisy's Destruction |
89m2tJ*******************PKsqp | JulyJailbait, WormGPT |
87Cae********************vmnX | JulyJailbait, WormGPT, Daisy's Destruction |
86d1f********************rhVm | JulyJailbait, WormGPT |
86jCb1******************9Q9h | WormGPT, FraudGPT, Daisy's Destruction, Alice |
Compared with the Bitcoin addresses, the Monero wallets demonstrated broader overlap across multiple underground services. Several appeared repeatedly alongside platforms offering illicit AI services and other criminal offerings, making them particularly valuable investigative pivots for identifying relationships between otherwise separate dark web ecosystems.
The reuse of cryptocurrency wallets across multiple services does not, on its own, prove common ownership or operational control. It does, however, indicate shared payment infrastructure or operational relationships that warrant further investigation. By correlating these artifacts through StealthMole, the investigation extended beyond the primary JulyJailbait website and uncovered infrastructure spanning multiple underground platforms.
Beyond the Dark Web
While the investigation primarily focused on reconstructing JulyJailbait's infrastructure through its onion services, cryptocurrency wallets, and historical mirrors, the platform's footprint was not confined to the dark web alone. To determine whether JulyJailbait maintained an external presence or whether its content was being circulated elsewhere, the investigation pivoted to StealthMole's Telegram Tracker.
Searches for "July Jailbait" returned numerous references spanning several years across multiple Telegram groups and channels. Although these findings did not reveal an official Telegram channel or account directly attributable to the platform's operators, they demonstrated that JulyJailbait's name and associated content had been shared and discussed within a variety of unrelated communities.
References were identified across channels operating in English, Russian, Chinese, and Spanish, reinforcing earlier observations that the platform catered to a multilingual audience. This multilingual footprint was also consistent with the language options available on the JulyJailbait website itself, suggesting that the platform was accessible to users from different regions rather than targeting a single linguistic community.
Several Telegram messages referenced JulyJailbait by name, while others contained filenames, torrent references, or media allegedly originating from the platform. Among the more notable findings was an image shared within the Telegram channel "Хакеры | Чат | 𝓗𝓪𝓬𝓴𝓮𝓻𝓼 𝓬𝓱𝓪𝓽", which appeared to depict the contents of a JulyJailbait repository. Although the image could not be independently verified as originating directly from the platform, it demonstrated that material associated with JulyJailbait was circulating beyond its own onion services.
Additional references were identified in channels including:
- Conspiración Máxima 777, where users discussed media allegedly originating from JulyJailbait.
- 爱妈仕三群, which contained multiple references to July Jailbait alongside BitTorrent magnet links.
- 集帆阁-呦呦搜索引擎, where users shared file names associated with the platform.
These findings suggest that Telegram primarily functioned as a secondary distribution and discussion channel rather than an official communication platform operated by JulyJailbait. Instead of uncovering operator-controlled infrastructure, the investigation revealed how the platform's name, references, and associated material continued to circulate organically across multiple online communities, extending its visibility well beyond the dark web.
Conclusion
What began as the investigation of a single onion service ultimately evolved into the reconstruction of a much broader underground ecosystem. Although the publicly accessible July Jailbait website revealed only limited information due to its authentication wall, a series of investigative pivots through StealthMole uncovered infrastructure extending well beyond the primary domain.
By correlating a reusable logo image, historical mirror domains, cryptocurrency payment artifacts, and Telegram references, the investigation exposed multiple layers of the platform's operational footprint. The recovery of approximately 35 related mirror domains, 27 Bitcoin wallets, 5 Monero wallets, historical surface web domains, and shared cryptocurrency infrastructure demonstrated that July Jailbait was supported by a far more extensive network than its current website alone suggested.
The investigation also highlighted the importance of examining historical and indirect artifacts rather than focusing solely on active infrastructure. Legacy mirror domains preserved payment information that no longer appeared on the current deployment, while cryptocurrency wallet reuse revealed connections to other underground services that would not have been apparent through website analysis alone. Similarly, Telegram references illustrated how the platform's name and associated material continued to circulate across multiple language communities despite the absence of an identifiable official Telegram presence.
Rather than relying on any single source of intelligence, this investigation demonstrates how combining historical snapshots, digital artifacts, financial indicators, and cross-platform correlation can transform a seemingly isolated website into a much more comprehensive picture of an underground ecosystem.
Editorial Note
Investigations involving dark web platforms rarely produce a complete picture from a single source. Infrastructure changes, inactive domains, reused artifacts, and fragmented online traces often require analysts to reconstruct events from evidence collected across multiple locations and time periods.
This investigation illustrates how StealthMole's ability to correlate historical snapshots, reusable digital artifacts, cryptocurrency infrastructure, and cross-platform references enables analysts to move beyond individual websites and build a more complete understanding of long-running underground ecosystems while maintaining evidence-based attribution throughout the investigative process.
To access the unmasked report or full details, please reach out to us separately.
Contact us: support@stealthmole.com