From Alias to Identity: Following the Digital Footprints Behind a Telegram Drug Seller

Telegram has become an increasingly convenient marketplace for illicit drug sellers. The same features that make the platform useful for ordinary communication, including public channels, direct messaging and easy-to-create accounts, also allow dealers to advertise products, reach potential buyers and operate behind usernames that reveal very little about who is actually running them. Cannabis sellers are particularly easy to come across, with accounts openly posting photographs of marijuana, prices and contact details while maintaining little obvious connection to a real-world identity.

But an alias is only as anonymous as the digital history behind it.

This investigation began with one such Telegram-based drug seller. At first glance, there was little to distinguish the account from countless others advertising cannabis through the platform. Rather than treating the visible Telegram profile as the end of the trail, the investigation used StealthMole to look beyond what was currently available and examine the historical traces surrounding the account.

This report follows that investigation from its starting point, showing how a trail scattered across Telegram history, leaked data and other online records was pieced together one artifact at a time.

The Account That Started It All

The investigation began with a deliberately broad search. Using StealthMole’s Telegram Tracker, we searched for “weed dealer” to see whether an openly advertised drug-selling account could be taken beyond what was immediately visible on Telegram. The query returned 14 user records and approximately 80 messages, providing several possible starting points.

One account stood out almost immediately. It appeared in the results under the name Weed Dealer | UG 🆓 🌱SEED 🐦 🍅 🐾/WAVE 🌊, with the Telegram username @tieuho****0. Unlike accounts that merely mentioned cannabis or appeared in conversations about drugs, this profile was notable because it presented itself directly as a weed dealer. That made it a more relevant target for examining whether an apparently pseudonymous Telegram seller could be followed through StealthMole’s historical data.

Looking at the account as it exists more recently, however, revealed surprisingly little. The profile displayed the name Tiêu Hồ, carried no profile photograph, and offered few obvious clues about the person behind it. Searching the account itself in Telegram Tracker changed that picture.

StealthMole associated the account with the persistent Telegram ID 1068143976 and preserved 25 historical name records, showing that its visible identity had changed repeatedly over the years. The historical snapshots were considerably more revealing than the current profile. Earlier versions contained multiple photographs of what appeared to be the same individual, while other snapshots shifted toward cannabis-related imagery and drug-oriented profile names.

Some of those historical photographs also exposed details that would no longer be apparent from viewing the account today. In a snapshot dated 22 December 2022, the individual was photographed standing in front of a dark vehicle with the registration plate 79A-2******8 clearly visible. Another snapshot, dated 28 February 2023, showed him alongside a white Mercedes-Benz displaying a second plate, 79A-3*****7.

The first plate offered an immediate external point of comparison. A search for 79A-2******8 produced an exact match on PlatesMania, where an independently photographed dark Lamborghini Urus, first generation (2018–2022) carried the same registration. The listing identified the plate as Vietnamese, registered in Khánh Hòa Province, and placed the photographed vehicle in Phước Long, Nha Trang. The image had been posted by a contributor using the name Bún bò on 17 January 2025 at 1:08:27 PM.

A Wallet That Wasn’t a Wallet

With the profile history offering several clues but no clear identity, the investigation moved to another artifact associated with tieuho****0: an Ethereum address.

  • 0x09c*****************************638

At first, the address looked like a promising cryptocurrency lead. If it belonged to the seller, its transaction history could potentially reveal another part of the account’s digital footprint. Consequently, the address was searched further in StealthMole’s Telegram Tracker.

The search returned several user records and messages mentioning the address. Among them was one result that could be tied directly back to the account being investigated. On 13 May 2023, Telegram ID 1068143976, appearing at the time as Seller | UG//@tieuho****0, had posted the address in a channel. The message read “Happy mother's day”, followed by the Ethereum address and an attached photograph.

The direct match confirmed that the address had indeed been shared by tieuho****0, but a closer examination changed what the artifact meant. Etherscan identified it not as a personal Ethereum wallet, but as a smart contract associated with the ERC-20 token mother (MOTHER). At the time of examination, the contract showed 1,436 transactions. Other Telegram results provided further context, including a message from the 0xGemi channel that referred to the same address as “Mother Contact” while discussing the token.

A search through StealthMole’s Dark Web Tracker produced another apparent lead. The contract address appeared within an indexed onion page containing Polygon ERC-1155/NFT transaction data. The record included Polygon transaction:

  • 0x09************************************************3a43

and was indexed from:

  • 3xplor3****************************************xyd.onion

One Alias, More Than One Footprint

After investigating the cryptocurrency, the investigation returned to the simplest artifact available: tieuho****0. This time, instead of looking at Telegram, the username was searched through StealthMole’s Dark Web Tracker to determine whether it had surfaced in previously leaked or indexed data.

One leaked document contained a record for tieuho****0 that matched the same Telegram ID 1068143976 already established through Telegram Tracker. That match was important because it provided continuity between the Telegram profile and the newly discovered record. More importantly, the entry contained several fields that had never been visible from the Telegram account itself:

  • Telegram Username: tieuho****0
  • Telegram ID: 1068143976
  • Referrer Username: thuytienbtc
  • Referrer ID: 5071132186
  • Invited: 0
  • Tokens: 2000
  • Email: tieuho****0@gmail.com
  • Wallet: 0xdFc**********************************695
  • Twitter: https://mobile.twitter.com/tieuho****0
  • Review: https://twitter.com/AirdropDet/status/1509606654905421833

The wallet field was more immediately actionable. Unlike the MOTHER contract encountered earlier, the record explicitly labelled the new ETH wallet as associated with the tieuho****0 entry. The combination of the exact username and Telegram ID made this a substantially stronger lead, although the leaked dataset alone could not establish that the person controlling the Telegram account also controlled the address.

  • 0xdFc******************************695

The wallet was therefore checked independently. Etherscan showed an address with 165 transactions, rather than another token contract. It held no ETH at the time of examination and approximately $0.07 across 18 token holdings, while its historical activity showed both incoming and outgoing transactions. Etherscan also indicated that the address had originally been funded by Binance 17.

StealthMole’s Wallet Risk Check provided a different view of the same activity. The address was flagged as Medium Risk. Of the 147 transactions analyzed by the platform, 22 were flagged as suspicious, representing 15% of the analyzed transactions and approximately 6.7% of the analyzed ETH volume. No blacklisted contacts were identified.

The behavioral indicators were more notable. StealthMole flagged Abnormal Relaying, Abnormal Mixing, and Relaying and Mixing, alongside a dormant transaction status. The last transaction recorded by the platform was dated 18 April 2025.

The transaction graph also showed how widely the address had interacted across the cryptocurrency ecosystem. Labeled nodes included Binance Exchange, Bitget Exchange, Bybit Exchange, MEXC Global Exchange, OKEx Exchange, Uniswap, Orbiter Finance Bridge, MetaMask-related contracts and routers, and a Binance User Wallet.

None of those labels, or the Medium Risk score itself, demonstrated that the wallet had been used to receive proceeds from drug sales. Likewise, StealthMole's detection of mixing and relaying patterns should not be treated as proof of money laundering. What the analysis established was narrower but still valuable: a wallet explicitly attributed to tieuho****0 by a leaked record had an extensive transaction history and displayed several behaviors that StealthMole considered worthy of additional scrutiny.

The leaked record had also introduced something the blockchain could not answer: an email address. That provided the investigation with a completely different route away from cryptocurrency and toward the identity behind the account.

The Password That Connected Two Identities

The email tieuho****0@gmail.com found in the leaked record opened a different line of investigation. Instead of looking for more blockchain activity, the next step was to determine whether tieuho****0 had appeared in credential data indexed by StealthMole.

A search in Combo Binder returned 63 results. tieuho****0@gmail.com appeared with several variations of the same password, built around Ban*****5, including versions with different capitalization and special characters.

Rather than treating the credential itself as the finding, the password became another search term. Searching the exact leaked password in Combo Binder produced a second email address:

  • ban*******5@gmail.com

This was more interesting than a simple similarity between usernames. Both tieuho****0@gmail.com and ban*******5@gmail.com appeared in compromised credential data with the same exact password. The ban******5 identifier was also embedded directly in the password family repeatedly associated with the first email address.

With ban*******5@gmail.com now providing a second account to examine, the investigation moved beyond leaked credentials to see what was publicly associated with the two email addresses. Checking the addresses through Google produced profile photographs for both accounts. The profile associated with tieuho****0@gmail.com displayed a photograph of a man, while ban*******5@gmail.com displayed a photograph of a woman.

The second image was particularly important because it introduced uncertainty rather than resolving it. Although ban*******5@gmail.com shared the exact leaked password associated with tieuho****0@gmail.com, its Google profile did not provide additional evidence that the address was controlled by the same individual. Instead, it reinforced the need to treat the email as a connected account or investigative lead rather than automatically assigning ownership to the person behind tieuho****0.

When the Alias Finally Had a Name

The search for tieuho****0@gmail.com in Dark Web Tracker produced another leaked CSV record. Unlike the earlier dataset, which had mainly exposed online identifiers, this entry contained information that appeared to move the investigation much closer to a real-world identity.

The matching record contained:

  • Location: Khánh Hòa
  • Name: Hồ Quốc Thanh
  • Email: tieuho****0@gmail.com
  • Phone: +84*********39
  • User/Record ID: 60e****************48
  • Code: qeabag8
  • Related ID: 60e06f9e9c9bb00d4bbc9ae2
  • Related Name: Lê Xuân Ngọc
  • Related Number: 382966254
  • Related Code: ykbpyy6
  • Status: NO

For the first time, Hồ Quốc Thanh appeared directly alongside the email address that had already been connected to tieuho****0 through the previous searches. The record also introduced a Vietnamese phone number and listed Khánh Hòa as the location.

The location was particularly notable in light of an earlier, completely different part of the investigation. The two vehicle plates visible in the historical Telegram photographs carried the 79 Khánh Hòa registration code, and the independent PlatesMania sighting of 79A-2******8 had placed that Lamborghini Urus in Phước Long, Nha Trang. Now, a leaked record connected to the account's email independently pointed to Khánh Hòa as well. Neither finding proved where the individual lived, but the same region emerging through unrelated artifacts made the geographic connection harder to dismiss as incidental.

The more immediate question was whether Hồ Quốc Thanh existed elsewhere in StealthMole's indexed data.

Searching the name in Dark Web Tracker produced a social-media record for the Twitter account:

  • https://twitter.com/ban*****5

The account was indexed under the name Hồ Quốc Thanh, with the Twitter ID ban****5 and email address:

  • ban*******5@gmail.com

That result brought the investigation back to an identifier discovered through an entirely different route. ban*******5@gmail.com was the same second email uncovered when the leaked credential associated with tieuho****0@gmail.com was pivoted through Combo Binder.

The connection had therefore come together from two directions. Credential data had linked tieuho****0@gmail.com and ban*******5@gmail.com through exact password reuse. Separately, Dark Web Tracker associated tieuho****0@gmail.com with the name Hồ Quốc Thanh, while another indexed record associated ban*******5@gmail.com and Twitter ID ban******5 with that same name.

Conclusion

What began as a broad search for a weed dealer on Telegram eventually moved far beyond the profile that first appeared in the results. Historical Telegram data exposed earlier photographs and vehicle registrations, cryptocurrency artifacts opened additional investigative paths, and leaked records introduced identifiers that were no longer visible from the account itself. Some of those leads went nowhere, while others became more meaningful only when they appeared again through a completely different source.

The strongest point of convergence was Hồ Quốc Thanh. The name appeared in a leaked record alongside tieuho****0@gmail.com, while the same email had already emerged through the investigation of the Telegram account and compromised credential data. A separate record then associated the same name with the ban******5 Twitter identity and ban*******5@gmail.com, an address independently connected to tieuho****0@gmail.com through exact password reuse. The geographic evidence added another layer: the leaked record placed Hồ Quốc Thanh in Khánh Hòa, the same province indicated by both vehicle registrations recovered from historical Telegram photographs.

Together, these findings provide a credible basis for assessing Hồ Quốc Thanh as a likely real-world identity associated with tieuho****0, but they stop short of definitive attribution. The investigation does not establish ownership of the photographed vehicles, prove that the attributed cryptocurrency wallet received proceeds from drug sales, or demonstrate that every connected email and social-media account was controlled by the same individual.

That distinction matters. The value of this investigation was not simply finding a name at the end of a search. It was seeing how an account that currently reveals very little had accumulated enough fragments across Telegram history, leaked databases, credentials, cryptocurrency records and other online sources for an alias to gradually become much less anonymous.

Editorial Note

Attribution in underground ecosystems is rarely absolute. Usernames change, infrastructure is shared, and associations do not always imply common ownership. This investigation shows how StealthMole's historical records and cross-source pivots can help navigate that uncertainty, connecting activity across changing identities while keeping the line between what the evidence establishes and what remains unknown.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com









Labels: ,

The Many Faces of ModernStealer: Tracing an Underground Military Data Network

Underground data markets are filled with sellers offering stolen databases, compromised credentials, and confidential records. But military and defence-related data sits in a different category. Claims involving classified documents, military personnel, defence institutions, drone technology, or internal government communications naturally carry greater significance, while also raising an important question: who is actually behind these listings, and how many seemingly different sellers are truly independent?

ModernStealer emerged as one such identity, appearing across underground forums with posts advertising military and defence-related material from multiple countries. At first glance, the activity appeared to belong to a single forum user operating under a recognizable alias. But as the investigation moved beyond the username and into the contact details left behind in these posts, the picture became more complicated. The same identifiers began appearing alongside other accounts, other aliases, and similar offerings across different corners of the underground ecosystem.

Using StealthMole to follow these traces across dark web forums and Telegram, this investigation examines the digital footprint surrounding ModernStealer and the identities that appear to intersect with it. Rather than assuming that every matching alias belongs to the same person, the report follows the identifiers themselves, looking at where they reappear, how the connections develop, and what those overlaps can tell us about the network operating behind a series of military and government data offerings.

The Thread That Started It All

The investigation began with a post on DarkForums where ModernStealer was offering what appeared to be sensitive documents related to a defence agreement between Türkiye and Pakistan. The thread, titled "[PK] TUR-PAK DEFENSE DRONE DEAL," immediately stood out because the material being advertised was not a typical database or credential dump, but a document concerning defence cooperation and drone technology.

The post described a 23-page confidential document titled "TURKEY-PAKISTAN BAYKAR-NASTP COOPERATION: STRATEGIC DEFENSE INDUSTRIAL PARTNERSHIP, TECHNOLOGY TRANSFER PROSPECTS AND DRONE PROCUREMENT." According to the description provided in the listing, the document covered cooperation involving Baykar Teknoloji and Pakistan's National Aerospace Science and Technology Park (NASTP), including areas such as unmanned systems, technology transfer, joint research and development, industrial collaboration, training, localization, and potential drone procurement.

  • https://darkforums.**/Thread****PK-TUR-PAK-DEFENSE-DRONE-DEAL

The listing itself was enough to make ModernStealer worth a closer look. A seller claiming access to confidential defence material involving drone technology raised the question of whether this was an isolated offering or part of a broader pattern. At this point, however, there was no basis to assume that ModernStealer had personally obtained the document through a breach, or even that the advertised material was authentic. What the thread did provide was a clear starting point: an underground identity openly associated with the alleged sale of sensitive defence-related information.

More importantly, the post contained an artifact that could be followed beyond the thread itself. ModernStealer had included the following Session ID as a contact point:

  • 05214b***********************************************f6163

Unlike the claims surrounding the advertised documents, the Session ID provided something concrete that could be searched and compared across StealthMole's indexed data. What began with a single defence-related listing now had a potential trail to follow, and the next step was to find out where else the same identifier had appeared.

A Pattern Begins to Emerge

Before following the Session ID beyond ModernStealer's own activity, we first wanted to understand whether the TU-PAK drone deal was an isolated listing or part of something larger. Searching the keyword "ModernStealer" in StealthMole's Leaked Monitoring tool returned five listings detected between March and April 2026.

Among the results were listings involving the Pakistan Nuclear Regulatory Authority (PNRA), Pakistan's National University of Sciences and Technology (NUST), and a database allegedly containing information belonging to Lockheed Martin employees. Another result concerned the Sri Lanka Air Force. While the nature and authenticity of these advertised datasets could not be established from the listings alone, their appearance under the same actor name suggested that the defence-related material seen in the TU-PAK thread was not an isolated occurrence.

The search was then extended to StealthMole's Government Monitoring tool to see whether the same name appeared in connection with government entities. This returned eight listings associated with ModernStealer between March and July 2026. Among them were posts concerning alleged internal documents from the Bangladesh military, Pakistan's SUPARCO and Ministry of Science and Technology, and a listing referencing the PLA, CIA, Department of Defense, and DARPA.

Together, the results began to show a recurring theme around the ModernStealer identity. The listings repeatedly touched on military, defence, government, nuclear, aerospace, and science-related organizations. This did not establish that ModernStealer had personally breached each of these entities, nor did it confirm that every dataset being advertised was authentic. But it did show that the TU-PAK drone deal was part of a much broader pattern of sensitive data offerings associated with the same name.

One of those listings offered a particularly useful opportunity to look closer. The thread concerned an alleged database belonging to the Pakistan Nuclear Regulatory Authority (PNRA) and was available at:

  • https://darkforums.**/Thr*****PK-Nuclear-Regulatory-Authority-PNRA-DATABASE

In the post, ModernStealer claimed to have compromised PNRA's mail server and obtained more than 60 databases, with 17 databases totaling approximately 3.2 GB being offered for sale. The actor claimed that the material included information related to nuclear reactor and chemical laboratory locations, employees, email addresses, sensitive documents, and infrastructure. These claims remained unverified, but one detail in the post was immediately familiar.

ModernStealer had again provided the same Session ID:

  • 05214b**********************************************f6163

The identifier first encountered in the TU-PAK drone deal was therefore not confined to a single listing. It has now appeared again in another sensitive post attributed to ModernStealer. With the same contact point recurring across separate offerings, the Session ID became more than a detail buried inside a forum post. It became the most promising artifact to follow beyond ModernStealer's own activity.

Following the Session ID

With the Session ID now appearing across more than one ModernStealer listing, the next step was to search the identifier directly in StealthMole's Dark Web Tracker. The results widened the investigation almost immediately. At least 30 indexed threads contained the same identifier, suggesting that its use extended well beyond the ModernStealer posts examined so far.

Among those results was a thread on Breached titled "Pakistan Military Procurement and Defense Deals," posted by a user named Zu1f1q4r:

  • https://breached.**/threads/pakistan-military-procurement****99/

The post concerned alleged contract and procurement information related to Pakistan's defence dealings with China and Türkiye. But it was the contact information at the bottom of the post that mattered most to the investigation. Zu1f1q4r had provided the exact same Session ID previously used by ModernStealer:

  • 05214***************************************************f6163

Alongside it was another identifier that had not appeared in the ModernStealer posts examined so far, a Tox ID:

  • 65BB****************************************************BC9D

The appearance of the same Session ID under a different username created the first clear overlap between ModernStealer and another underground identity. To understand whether this was a one-time occurrence, we looked further into Zu1f1q4r's activity and identified the actor's Breached profile:

  • https://breached.**/members/zu1f1q4********8/

The trail did not stop with the military procurement post. Another thread by Zu1f1q4r concerned an alleged leak involving Pakistan's Intelligence Bureau:

  • https://breached.**/threads/intelligence-bureau-pakistan****1/

Once again, the post listed the same Session ID and the same Tox ID as contact points.

A third thread followed the same pattern, this time involving alleged documents from Pakistan's Federal Investigation Agency (FIA):

  • https://breached.**/threads/pakistan-fia-documents******0/

Here too, Zu1f1q4r provided the same pair of identifiers.

The repeated overlap was difficult to ignore. ModernStealer and Zu1f1q4r were operating under different names, but the same Session ID appeared as a contact point in posts associated with both identities. Zu1f1q4r then repeatedly paired that identifier with the same Tox ID across multiple Pakistan-focused listings.

At this stage, however, the evidence did not establish that ModernStealer and Zu1f1q4r were the same person. The Session ID could have been shared between members of a group or used as common contact infrastructure. The Tox ID also remained directly associated only with Zu1f1q4r, since it had not been observed in any ModernStealer post examined during the investigation.

From the Dark Web to Telegram

The Session ID had already connected ModernStealer's DarkForums activity with posts published by Zu1f1q4r on Breached. But underground actors rarely limit their activity to a single type of platform. To see whether the same identifier had travelled beyond dark web forums, we searched it again, this time using StealthMole's Telegram Tracker.

The search led to a message posted in the Telegram channel:

  • https://t.me/Hexvi********ach

The message came from a user identified as Sassoon Don, operating under the Telegram username S*********n. In it, the user was looking for classified documents related to Ukraine and five Central Asian countries, apparently for China, and asked anyone with access to such material to contact them through Session.

The Session ID provided in the message was immediately recognizable:

  • 05214************************************************6163

It was the exact same identifier that had already appeared in posts by ModernStealer and Zu1f1q4r.

This was an interesting shift in the investigation. Until this point, the Session ID had appeared alongside actors advertising alleged military and government data. The Telegram message showed an account using the same contact point while actively seeking classified material, adding another dimension to the activity surrounding the identifier. It did not establish how any of the previously advertised material had been obtained, but it raised the possibility that the network around the Session ID was interested not only in distributing sensitive information, but also in sourcing it.

StealthMole's Telegram data allowed the account itself to be examined further. The user Sassoon Don was associated with the immutable Telegram User ID:

  • 7605334264

Searching the user profile revealed only two indexed messages, leaving relatively little historical activity to work with. StealthMole also showed the account appearing across three Telegram channels:

  • 3990978039: https://t.me/I********d
  • 3646663287: https://t.me/N********T
  • 3542147875: https://t.me/Hex*******h

These channel associations were useful as contextual information, but they were not treated as evidence of ownership or affiliation. Simply appearing in or being a member of a Telegram channel does not establish an operational relationship with the people running it.

More importantly, the investigation had not yet found another contact identifier in Sassoon Don limited Telegram history that could independently connect the account to ModernStealer. At this point in the investigation, the connection rested on one persistent artifact: the same Session ID.

The trail now involved three different identities across dark web forums and Telegram: ModernStealer, Zu1f1q4r, and Sassoon Don. Whether they represented separate actors sharing infrastructure, members of the same operation, or different identities controlled by one person was still unclear.

The Link Back to ModernStealer

The appearance of Sassoon Don on Telegram added another identity to the investigation, but at that point, the connection to ModernStealer still depended on the shared Session ID. To determine whether a more direct link existed, we returned to StealthMole's Dark Web Tracker and began looking more closely at other threads posted under the ModernStealer name.

One of those threads concerned the alleged sale of classified Pakistani military documents:

  • https://darkforums.**/Th***PAKISTAN-CLASSIFIED-MILITARY-DOCUMENTS

This time, the contact details provided at the bottom of the post changed the picture considerably. ModernStealer had listed two ways to get in touch:

  • Session: 05214*******************************************************88163
  • Telegram: @S**********n

The Telegram account discovered through the Session ID search was therefore not simply another user who happened to mention the same identifier. ModernStealer had directly listed Sassoon Don as a contact point in their own forum post.

The same pairing appeared again in another ModernStealer thread:

  • https://darkforums.***/T*******Military-Documents-of-Various-Countries-China-East-Asia-USA-Russia

The post advertised what was described as military material from several countries and regions and again directed interested users to the same Session ID and the same Telegram account, Sassoon Don.

Another thread involving an alleged data leak from Pakistan's National University of Sciences and Technology provided further evidence of the Session ID's repeated use:

  • https://darkforums.***/Threa**DATA-LEAK-OF-NUST-PAKISTAN-DEFENCE

Here, ModernStealer once again used the same Session identifier as a contact point.

The repeated use of these identifiers provided a much clearer connection than the investigation had at the beginning. The Session ID could now be directly tied to multiple posts under the ModernStealer identity, while Sassoon Don had also been explicitly presented by ModernStealer as a Telegram contact across separate listings.

This did not necessarily mean that the person operating the Sassoon Don Telegram account and the person posting as ModernStealer were the same individual. Shared accounts and contact infrastructure remain possible, particularly if ModernStealer represents a team rather than a single operator. But the evidence now establishes a direct operational association between the ModernStealer forum activity and Sassoon Don.

One Contact, Another Name

With Sassoon Don now directly connected to ModernStealer's forum activity, the Telegram username became the next artifact to investigate. Searching "SassoonDon" in StealthMole's Dark Web Tracker surfaced another forum thread, this time on Breached.live:

  • https://breached.*****/showt*************669

The thread, titled "PLA OFFICERS AND OTHER RANKS DATABASE," was not posted by ModernStealer. Instead, the account behind the listing was operating under a different name: PriorOps.

According to the post, PriorOps was offering what was described as a database containing information related to officers and other ranks within China's People's Liberation Army (PLA). The advertised records were said to include details such as rank, position, date of birth, education, career history, operational specialties, and contact information. As with the other listings examined during the investigation, these claims could not be independently verified from the post alone.

But once again, the most useful part of the listing was not necessarily what the actor claimed to possess. It was how they asked to be contacted.

The post listed:

  • Contact: @S********n

The same Telegram username that ModernStealer had explicitly provided in military-related DarkForums posts was now being used as a contact point by PriorOps, another forum identity advertising alleged military data.

This created a more direct overlap than the one previously observed with Zu1f1q4r. In that case, the connection to ModernStealer came through the shared Session ID. Here, both ModernStealer and PriorOps had independently published the exact same Telegram username as their contact point.

By this stage, a pattern was beginning to take shape around the identifiers rather than the names themselves. ModernStealer was directly connected to both the Session ID and Sassoon Don. Zu1f1q4r repeatedly used the same Session ID across several Pakistan-focused listings, while PriorOps used the same Sassoon Don Telegram account in a post involving alleged PLA personnel data.

The overlaps raised an obvious possibility: ModernStealer, Zu1f1q4r, and PriorOps could represent different aliases used by the same operator. But the evidence also allowed for another explanation. The identities could belong to multiple individuals using shared contact infrastructure or operating as part of the same group. The available artifacts were strong enough to establish an operational connection between the identities, but not strong enough to conclusively determine who was sitting behind each account.

What was becoming increasingly clear, however, was that following usernames alone would have missed much of this picture. The names changed from one forum to another, but the contact points did not. The Session ID and Sassoon Don account provided the connective tissue between accounts that, at first glance, appeared to be unrelated.

A Second ModernStealer?

The connections uncovered so far had all developed from contact points that could be traced from one identity to another. But there was another, more obvious lead worth examining. Searching the keyword "ModernStealer" directly in StealthMole's Telegram Tracker surfaced a user using the name ModernStealer.

At first glance, the match appeared significant. But a closer look at the account's history showed why matching usernames alone can be misleading in underground investigations.

StealthMole associated the account with the immutable Telegram User ID:

  • 1628612534

Historical records showed that the same user ID had changed its username multiple times over the years, with six username changes observed in the available data. Among the account's previous identities was @Mirage2022, appearing under names including Myles and Haven.

Looking through the account's older messages revealed one detail that stood out in the context of the investigation. On 3 February 2026, while appearing as Myles / @Mirage2022, the user posted a message asking:

  • “Who knows where I can get drone leaks and blueprints”

The message was difficult to ignore. The investigation itself had begun with ModernStealer advertising documents related to a Türkiye-Pakistan drone deal, and there was a Telegram account that would later use the same username with a documented historical interest in obtaining drone-related leaks and blueprints.

Other messages provided glimpses into the account's broader activity. Historical records showed the user asking others for money, while one conversation included the statement:

  • “No, I’m not Indian, lol”

The comment offered little in the way of reliable attribution. It was a self-reported statement made by the user and could not be used to establish nationality or location.

StealthMole also preserved images associated with the account's historical Telegram activity. Among them were screenshots showing payment-related information and material referring to Apple Pay-linkable debit cards, alongside purported balances and prices. While these images added context to the type of underground activity surrounding the account, they did not establish that the user owned the financial accounts shown, controlled the advertised cards, or personally carried out any related fraud.

Taken together, the findings made Telegram User ID 1628612534 an interesting lead. The later use of the exact name and the earlier interest in drone leaks created a notable resemblance to the activity examined elsewhere in the investigation.

But unlike Sassoon Don, this account could not be tied back to ModernStealer through the Session ID or another contact point directly published in the actor's forum posts. No overlap was found with Telegram User ID 7605334264, and the investigation did not uncover another persistent identifier connecting the two accounts.

For that reason, the account remains an unconfirmed branch of the investigation. It may represent another identity connected to ModernStealer, or the username may have been adopted independently. The similarities make the account worth documenting, but they are not enough to merge it into the stronger attribution chain built around the Session ID and Sassoon Don.

Conclusion

What began with a single DarkForums listing involving an alleged Türkiye-Pakistan defence drone deal quickly developed into a much broader investigation. ModernStealer's activity extended across a series of listings involving military, government, nuclear, defence, and aerospace-related material, but it was the contact information left behind in those posts that ultimately proved more revealing than the names attached to them.

By following the Session ID and Sassoon Don across StealthMole's indexed dark web and Telegram data, the investigation uncovered connections that would have been difficult to identify through username searches alone. The same Session ID used by ModernStealer appeared repeatedly in posts by Zu1f1q4r, while the Telegram account directly advertised by ModernStealer was also used as a contact point by PriorOps. These overlaps establish a clear operational relationship between the identities, although the evidence does not conclusively determine whether they represent one person operating under multiple aliases, members of the same group, or separate actors sharing communication infrastructure.

The investigation also surfaced a separate Telegram account using the ModernStealer name, whose historical activity included an interest in obtaining drone leaks and blueprints. Despite the apparent similarities, no persistent identifier was found connecting that account to the stronger attribution trail surrounding the known Session ID and Sassoon Don. It therefore remains an unresolved lead rather than a confirmed part of the cluster.

Ultimately, the ModernStealer investigation shows why the identity displayed beside a forum post is often only the beginning of the story. Usernames changed as the investigation moved between platforms, but certain contact points continued to reappear. Following those identifiers allowed a single military data listing to develop into a wider picture of interconnected underground activity, while also leaving an important question unresolved: whether the many faces surrounding ModernStealer belong to one operator or to a network working behind shared infrastructure.

Editorial Note

Attribution in cyber and dark web investigations is rarely absolute. Shared accounts, reused identifiers, changing usernames, and common infrastructure can create strong connections without necessarily proving that the same individual is behind every identity. This investigation reflects that uncertainty: StealthMole made it possible to follow persistent artifacts across forums and Telegram and uncover relationships that were not immediately visible, while the available evidence still required each connection to be assessed on its own strength rather than treated as definitive attribution.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

JulyJailbait: Reconstructing an Underground CSAM Ecosystem

Dark web continues to host a wide range of illicit platforms that cater to criminal markets, from stolen data and malware to illegal services and child sexual abuse material (CSAM). While many of these websites disappear as quickly as they emerge, others remain active for years by continuously adapting their infrastructure, replacing seized or abandoned domains, and maintaining access through mirror sites and alternative payment mechanisms. As a result, investigating these platforms often requires looking beyond what is immediately visible to understand how they continue to operate over time.

One such platform is JulyJailbait, also referred to as July Club, a long-running dark web website advertising access to a large collection of illegal material through paid memberships. At first glance, the platform appears to be just another onion service offering subscription-based access. However, its publicly visible pages reveal only a small part of a much broader ecosystem.

This investigation reconstructs that ecosystem using artifacts collected through StealthMole, following a series of investigative pivots that extend beyond the primary website. By correlating historical infrastructure, digital assets, cryptocurrency payment information, and other operational traces, the report demonstrates how seemingly isolated pieces of evidence can be combined to reveal a far more extensive underground network than the website alone suggests.

Following the First Lead

The investigation began with the identification of the primary JulyJailbait onion service:

  • julyl************************************************pid.onion

Historical snapshots indexed by StealthMole revealed that the website, also referred to as July Club, advertised subscription-based access to a large collection of illegal material through a simple membership model. The landing page claimed to host more than 8 TB of content and accepted payments in both Bitcoin (BTC) and Monero (XMR) before granting users access to the platform. The site also maintained dedicated login, payment, and FAQ pages, suggesting a structured and persistent operation rather than a temporary or opportunistic deployment.

Rather than limiting the investigation to the visible content of the website, the focus shifted towards identifying reusable artifacts that could reveal additional infrastructure. Historical snapshots, indexed files, payment pages, embedded resources, and other technical elements often persist even as underground services migrate between domains or modify their public-facing pages. These artifacts frequently provide more investigative value than the homepage itself.

Among the indexed files associated with the platform was a logo image named julylail.png. While appearing insignificant at first glance, reusable digital assets such as logos often retain identical cryptographic hashes across multiple deployments. This makes them valuable pivots for infrastructure discovery, particularly when operators reuse the same resources across mirror domains or successive versions of a website.

The image was therefore selected as the next investigative pivot to determine whether it could expose additional infrastructure beyond the primary onion service.

An Image That Led to Mirrors

With the primary website documented, the investigation shifted to the platform's embedded resources in search of reusable artifacts that could reveal additional infrastructure. Among the indexed files associated with the website was a logo image, julylail.png, bearing the JulyJailbait branding. Although visually unremarkable, the image retained a unique SHA-256 hash that made it an ideal investigative pivot.

Rather than searching for domains or keywords, the image itself was queried through StealthMole's Dark Web Tracker. Because StealthMole indexes historical files alongside websites, identical images reused across different services can often expose infrastructure that is not directly linked from a platform's public pages.

The results significantly expanded the scope of the investigation. The same image hash was found across 35 mirror domains associated with JulyJailbait, many of which had never been referenced on the primary website. This demonstrated that the operators had repeatedly reused the identical logo while deploying new domains, unintentionally leaving behind a persistent artifact that connected otherwise independent instances of the platform.

Among the identified infrastructure were both active and inactive mirrors, illustrating the platform's long operational history and its reliance on domain rotation to maintain accessibility. One of the active mirrors proved particularly valuable, as it contained a dedicated page listing both current and historical JulyJailbait domains while distinguishing them from domains the operators claimed were fraudulent or unauthorized. This provided rare insight into how the platform itself documented changes to its infrastructure and attempted to direct users toward legitimate mirrors.

  • jjclub********************************************lad.onion

Some of the notable mirror domains identified during the investigation include:

  • jjclubumn7vkhyuw.onion (inactive)
  • jjclub***********************************************lad.onion (active)
  • 232kckhwmfpl6mqqmigunmffkldxp3tbsfvxxwofrdv52ikvxshmzwid.onion (inactive)
  • 5am52idv6d2azc2drzmxvstt6y7pozju3ujn7eydqnxdynvkxwl2omad.onion (inactive)
  • jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion (inactive)
  • cvfdjsmso5ii5twu7kmmpyvbjnggnku4v47vf2xc3m2ochmxfxi722id.onion (inactive)
  • tl65h3pazhvh6ewepmlvlwbwtrsl2ap7gox2qoyveem7s44umbfzboyd.onion (inactive)

What initially appeared to be a simple branding asset ultimately became one of the most valuable investigative pivots in the case. Instead of exposing only additional websites, the recovered mirror domains provided new avenues for infrastructure analysis, historical comparison, and financial tracing, allowing the investigation to move beyond the primary onion service and into the wider ecosystem supporting the platform.

Hidden in the Past

The discovery of JulyJailbait's mirror infrastructure provided more than additional access points to the platform. By examining several inactive mirror domains individually, the investigation uncovered historical payment artifacts that no longer appeared on the current deployment. These legacy mirrors effectively served as archived snapshots of the platform's earlier operational infrastructure, preserving cryptocurrency wallets that had since been replaced.

Across the investigated mirror domains, 17 additional Bitcoin wallets were identified. None of these wallets had been observed on the primary JulyJailbait website, indicating that the platform had periodically refreshed its payment infrastructure while continuing to operate under the same branding. Unlike the cryptocurrency artifacts recovered from the active website, these historical wallets showed no overlap with other underground services during this investigation, suggesting they belonged to an earlier phase of the platform's operation.

232kckhwmfpl6mqqmigunmffkldxp3tbsfvxxwofrdv52ikvxshmzwid.onion

This inactive mirror proved to be the richest source of historical payment artifacts, revealing seven Bitcoin wallets that were not observed elsewhere during the investigation:

  • bc1qj**********************************qj8
  • bc1qv**********************************h8r
  • bc1q8**********************************hvm
  • bc1qf**********************************96x
  • bc1qe**********************************hkt
  • bc1qa**********************************9fv
  • bc1qr**********************************nrr

5am52idv6d2azc2drzmxvstt6y7pozju3ujn7eydqnxdynvkxwl2omad.onion

Analysis of this inactive mirror identified a single Bitcoin wallet associated with the platform:

  • 15UN**************************1SH

jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion

This mirror preserved two historical Bitcoin wallets:

  • 18P3**************************7Stc
  • 16Uyc*************************GwjW

cvfdjsmso5ii5twu7kmmpyvbjnggnku4v47vf2xc3m2ochmxfxi722id.onion

Investigation of this mirror recovered three Bitcoin wallets:

  • 1PnfX*************************SES
  • 1gY3w*************************czN
  • 18P3F************************7Stc

Notably, the wallet 18P3F16UoQm5rEAJPXbE5p4ERYUPNS7Stc had already been observed on jiujgj7saeq4clqewp2s2beeow337w7erx54nsqe5rlq4tde5ecbyeyd.onion, making it the only historical Bitcoin wallet reused across multiple archived deployments identified during this investigation.

tl65h3pazhvh6ewepmlvlwbwtrsl2ap7gox2qoyveem7s44umbfzboyd.onion

The final investigated mirror yielded three additional Bitcoin wallets:

  • 1FUoh**************************qbb
  • 1LBvk**************************PHk
  • 1GUgu**************************31h

Beyond the archived onion services, the active mirror jjclub**************hlad.onion contained a dedicated page documenting the platform's historical infrastructure. Alongside previous onion services, the operators also referenced several surface web domains, including julyjailbait.com, julyjailbait.net, julyjailbait.org, and julyjailbait.me, while separately identifying domains they considered fraudulent or unauthorized. Although these references originate from the operators themselves and should not be treated as independently verified infrastructure, they provide valuable insight into how the platform documented its historical presence and attempted to distinguish legitimate domains from impersonation sites.

Rather than functioning solely as backup websites, the historical mirrors preserved intelligence that no longer existed on the active platform. By examining these archived deployments individually, the investigation reconstructed an earlier stage of JulyJailbait's financial infrastructure, providing a broader historical perspective that would not have been possible through analysis of the primary website alone.

Following the Financial Footprint

One of the most valuable sources of intelligence recovered from the primary JulyJailbait website was its cryptocurrency payment infrastructure. The publicly accessible payment page accepted both Bitcoin (BTC) and Monero (XMR), with users required to complete a cryptocurrency payment before gaining access to the platform. Rather than treating these wallets solely as payment addresses, each one was used as an investigative pivot within StealthMole to determine whether the same infrastructure appeared elsewhere across the underground ecosystem.

The investigation identified 10 Bitcoin wallets and 5 Monero wallets associated with the primary JulyJailbait domain. While several of these wallets appeared to be exclusive to the platform, others were reused across multiple underground services, exposing links that were not apparent through website analysis alone.

Bitcoin Wallets Identified

Bitcoin Wallet

Additional Infrastructure Identified

bc1q*********************4gu

JulyJailbait, Alice

bc1q*********************6f6

JulyJailbait only

bc1qc********************708

JulyJailbait, MOE Connect, WormGPT

bc1q8********************90r

JulyJailbait, MOE Connect

bc1qg*******************50a

JulyJailbait only

bc1qp********************g3f

JulyJailbait only

bc1qy**********************ymm

JulyJailbait, MOE Connect

bc1qj**********************ddp

JulyJailbait, KidBin, Snapchat account hacking service

bc1q8********************gmt

JulyJailbait, WormGPT

bc1qp********************ha5q

JulyJailbait only

The Bitcoin infrastructure showed a mixture of exclusive and shared payment addresses. While several wallets appeared unique to JulyJailbait, others were reused across services such as WormGPT, MOE Connect and KidBin, suggesting that elements of the payment infrastructure extended beyond a single platform.

Monero Wallets Identified

Monero Wallet

Additional Infrastructure Identified

86c3CZ********************qA1y

JulyJailbait, WormGPT, FraudGPT, Darkweb Porn, Daisy's Destruction

89m2tJ*******************PKsqp

JulyJailbait, WormGPT

87Cae********************vmnX

JulyJailbait, WormGPT, Daisy's Destruction

86d1f********************rhVm

JulyJailbait, WormGPT

86jCb1******************9Q9h

WormGPT, FraudGPT, Daisy's Destruction, Alice

Compared with the Bitcoin addresses, the Monero wallets demonstrated broader overlap across multiple underground services. Several appeared repeatedly alongside platforms offering illicit AI services and other criminal offerings, making them particularly valuable investigative pivots for identifying relationships between otherwise separate dark web ecosystems.

The reuse of cryptocurrency wallets across multiple services does not, on its own, prove common ownership or operational control. It does, however, indicate shared payment infrastructure or operational relationships that warrant further investigation. By correlating these artifacts through StealthMole, the investigation extended beyond the primary JulyJailbait website and uncovered infrastructure spanning multiple underground platforms.

Beyond the Dark Web

While the investigation primarily focused on reconstructing JulyJailbait's infrastructure through its onion services, cryptocurrency wallets, and historical mirrors, the platform's footprint was not confined to the dark web alone. To determine whether JulyJailbait maintained an external presence or whether its content was being circulated elsewhere, the investigation pivoted to StealthMole's Telegram Tracker.

Searches for "July Jailbait" returned numerous references spanning several years across multiple Telegram groups and channels. Although these findings did not reveal an official Telegram channel or account directly attributable to the platform's operators, they demonstrated that JulyJailbait's name and associated content had been shared and discussed within a variety of unrelated communities.

References were identified across channels operating in English, Russian, Chinese, and Spanish, reinforcing earlier observations that the platform catered to a multilingual audience. This multilingual footprint was also consistent with the language options available on the JulyJailbait website itself, suggesting that the platform was accessible to users from different regions rather than targeting a single linguistic community.

Several Telegram messages referenced JulyJailbait by name, while others contained filenames, torrent references, or media allegedly originating from the platform. Among the more notable findings was an image shared within the Telegram channel "Хакеры | Чат | 𝓗𝓪𝓬𝓴𝓮𝓻𝓼 𝓬𝓱𝓪𝓽", which appeared to depict the contents of a JulyJailbait repository. Although the image could not be independently verified as originating directly from the platform, it demonstrated that material associated with JulyJailbait was circulating beyond its own onion services.

Additional references were identified in channels including:

  • Conspiración Máxima 777, where users discussed media allegedly originating from JulyJailbait.
  • 爱妈仕三群, which contained multiple references to July Jailbait alongside BitTorrent magnet links.
  • 集帆阁-呦呦搜索引擎, where users shared file names associated with the platform.

These findings suggest that Telegram primarily functioned as a secondary distribution and discussion channel rather than an official communication platform operated by JulyJailbait. Instead of uncovering operator-controlled infrastructure, the investigation revealed how the platform's name, references, and associated material continued to circulate organically across multiple online communities, extending its visibility well beyond the dark web.

Conclusion

What began as the investigation of a single onion service ultimately evolved into the reconstruction of a much broader underground ecosystem. Although the publicly accessible July Jailbait website revealed only limited information due to its authentication wall, a series of investigative pivots through StealthMole uncovered infrastructure extending well beyond the primary domain.

By correlating a reusable logo image, historical mirror domains, cryptocurrency payment artifacts, and Telegram references, the investigation exposed multiple layers of the platform's operational footprint. The recovery of approximately 35 related mirror domains, 27 Bitcoin wallets, 5 Monero wallets, historical surface web domains, and shared cryptocurrency infrastructure demonstrated that July Jailbait was supported by a far more extensive network than its current website alone suggested.

The investigation also highlighted the importance of examining historical and indirect artifacts rather than focusing solely on active infrastructure. Legacy mirror domains preserved payment information that no longer appeared on the current deployment, while cryptocurrency wallet reuse revealed connections to other underground services that would not have been apparent through website analysis alone. Similarly, Telegram references illustrated how the platform's name and associated material continued to circulate across multiple language communities despite the absence of an identifiable official Telegram presence.

Rather than relying on any single source of intelligence, this investigation demonstrates how combining historical snapshots, digital artifacts, financial indicators, and cross-platform correlation can transform a seemingly isolated website into a much more comprehensive picture of an underground ecosystem.

Editorial Note

Investigations involving dark web platforms rarely produce a complete picture from a single source. Infrastructure changes, inactive domains, reused artifacts, and fragmented online traces often require analysts to reconstruct events from evidence collected across multiple locations and time periods.

This investigation illustrates how StealthMole's ability to correlate historical snapshots, reusable digital artifacts, cryptocurrency infrastructure, and cross-platform references enables analysts to move beyond individual websites and build a more complete understanding of long-running underground ecosystems while maintaining evidence-based attribution throughout the investigative process.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report