Following the Shells: From Ghost Seoul to PandaChina

A compromised website does not always end with a defacement, a ransom note, or stolen data. Sometimes, the real value is simply keeping the door open and selling the key.

Web shells make that possible. Planted on compromised servers, they can provide attackers with continued remote access, allowing them to interact with files and systems long after the initial intrusion. In underground markets, that access has become a commodity of its own. Sellers advertise compromised websites, administrative panels and webshell access to buyers who may have had no involvement in breaching the target in the first place. Some accesses are sold individually, while others are packaged by the hundreds, turning compromised infrastructure into inventory.

One seller operating in this space is Ghost Seoul, a Telegram-based operation advertising webshell access across a surprisingly broad range of targets. Government agencies, educational institutions, commercial organizations and other websites appeared among its listings, with prices varying according to the access being offered. On the surface, there was little to distinguish Ghost Seoul from the many sellers competing in the same underground economy.

But looking beyond the latest advertisements revealed a different story. Historical Telegram records on StealthMole showed that the identity visible today was only one part of a longer trail. Older usernames, archived messages and connections between seemingly separate accounts and channels gradually pushed the investigation further back, raising questions about how long the operation had really been active and who had been behind it before the name Ghost Seoul appeared.

This report follows that trail, starting with a webshell market active in 2026 and working backward through the digital traces its operator left behind. What emerged was not simply a snapshot of another Telegram seller, but a history that had been hiding behind changing names.

Where the Trail Began

Ghost Seoul first drew attention through a Telegram channel built around a straightforward business: selling access to websites that had already been compromised. Throughout July 2026, the channel advertised webshell and root-shell access across a broad mix of targets, from commercial websites and universities to government and defence-related domains. Alongside individual listings, the operator also offered webshells in bulk, suggesting that compromised access was being treated less as the outcome of individual attacks and more as inventory for resale.

  • https://t.me/web******r

The listings followed a fairly consistent pattern. A domain would be posted alongside a price and, in some cases, details about the level of access being offered. On July 21, for example, the channel advertised 100 “fresh & clean” webshells for $70, an offer that appeared again on July 25, 26 and 27. Individual domains were priced separately, with listings ranging from relatively low-cost website access to several hundred dollars for more notable targets. Some posts were later updated to indicate that the advertised access had been sold.

The targets themselves made the channel difficult to dismiss as just another small webshell shop. South Korean government domains including seoul.go.kr and busan.go.kr appeared alongside Germany's bmvg.de, the UN Food and Agriculture Organization's fao.org, and Singapore's Ministry of Defence domain, mindef.gov.sg. The mindef.gov.sg listing was particularly notable: Ghost Seoul advertised what it described as root shell access for $200 on July 25, before marking the access as sold three days later. These posts document what the seller claimed to possess and sell; they do not, by themselves, independently verify the compromise or transaction.

There were signs that the operation was not limited to simply posting whatever access happened to become available. Listings appeared repeatedly throughout the month, bulk packages were offered alongside individual domains, and the channel included targets spanning multiple countries and sectors. Taken together, the activity presented Ghost Seoul as an active participant in the market for compromised web infrastructure rather than a channel focused on a single campaign or target set.

The listings also provided the first lead beyond the channel itself. Across multiple posts, interested buyers were directed to @c******es to arrange purchases, while @web*****r was repeatedly presented as the channel or proof point for the operation. The same pattern appeared in bulk advertisements, including posts that instructed buyers to “DM @c******es” while pointing them back to Ghost Seoul for proof. Rather than being an occasional mention, @c******es appeared consistently at the point where an advertised shell or access was expected to turn into a transaction.

At that stage, we knew what Ghost Seoul was selling and had a direct contact used by the operation, but very little about the person behind it. That made @c******es the natural next pivot. Instead of looking at another advertised domain, we searched the account itself through StealthMole's historical Telegram records.

One Account, Many Names

The first account worth following was @c******es. Ghost Seoul repeatedly directed interested buyers to this handle, while the account itself left little ambiguity about what it was connected to: its Telegram bio listed “DOMAIN MARKET: Web*****r.” Rather than treating the username as a permanent identity, the investigation pivoted on the account's underlying Telegram identifier, User ID 8423162304.

That distinction quickly became important. StealthMole's historical Telegram indexing showed that the account visible as COVID77 / @c******es in July 2026 had appeared under a series of different identities during the preceding months. At least eight name and username combinations were captured across the available snapshots, including:

  • Panda / @panda******0x
  • PANDA0X / @panda****0x
  • PANDA/X1ON / @panda****0x
  • Panda/Cod3r / @panda***0x
  • THE/PANDA / @panda****a0x
  • Panda/PANDA / @panda***0x
  • JiuPanda / @x*****panda
  • COVID77 / @c******es

The names changed, but Telegram User ID 8423162304 remained the common identifier. This was significant because @x***npanda and @Panda*****0x had already surfaced elsewhere during searches for Ghost Seoul-related material. Initially, those appearances could have been interpreted as other users circulating or promoting the seller's advertisements. Historical indexing showed otherwise: the Panda, x***npanda and COVID77 identities were different snapshots of the same Telegram account.

The account's activity also remained concentrated around the webshell trade despite the changing names. StealthMole associated User ID 8423162304 with only four observed Telegram communities, one being the Ghost Seoul channel. Three were explicitly centered on the sale or exchange of webshell and server access, while the fourth, Indonesia Defacer, placed the account within another community closely adjacent to that activity.

  • https://t.me/ma***tweb***l
  • https://t.me/WebshellCpan*****S
  • https://t.me/IndonesiaD*****r

This also changed the meaning of earlier messages uncovered during the investigation. In the Webshell / Cpanel / Smtp / Rdp channel, a user appearing as JiuPanda / @x***npanda had circulated Ghost Seoul material. The same Telegram User ID later appeared as Panda / @Panda*****0x in INDONESIA DEFACER | WEBSHELL MARKET. What had initially looked like separate accounts promoting the same seller could now be followed back to User ID 8423162304.

Even the visual identity evolved without completely abandoning the theme. The July @c******es account used imagery closely resembling Ghost Seoul's profile branding, while the channel itself leaned heavily into a South Korean persona through the Korean flag, Seoul imagery and the words “KOREA CYBER UNIT.” The historical records, however, showed that this presentation came after months of Panda-branded identities. The Korean branding therefore provides useful context about how the operation presented itself at that point in time, but it cannot establish where the operator was actually located or their nationality.

That raised a different question: what had PandaChina been doing before Ghost Seoul appeared?

Before Ghost Seoul

Once the historical identities behind Telegram User ID 8423162304 were established, the earlier Panda-era messages could be viewed in a different light. They were no longer references to another seller who happened to circulate Ghost Seoul material. They were part of the same account's earlier activity, and that activity showed that selling compromised web access had begun well before the Ghost Seoul name appeared.

Under @Panda*****0x, the account was already advertising webshells and other forms of server access through Telegram in March 2026. The posts followed a commercial format that would later remain familiar: lists of available domains, prices, payment instructions and direct contact details. Buyers were offered payment through BTC, USDT, Ethereum and DOGE, while advertisements directed them to @Panda*****0x to complete a purchase. Some posts also pointed users toward another contact point, @Pandam******0x, for additional information.

The scale of the inventory was visible in PRICELIST23.txt, a file circulated by the account containing a long list of access points across multiple countries. Many entries included URLs using port 2083, alongside educational and other domains from countries including Peru, Bolivia, Colombia, India, Pakistan, Nepal, Bhutan, Nigeria and Indonesia. Elsewhere, the seller advertised access individually and in bulk, showing that the later Ghost Seoul model of turning compromised infrastructure into priced inventory was already present during the Panda period.

Some of the earlier advertisements also reached government infrastructure. In one March post, @Panda*****0x was listed as the contact for access involving domains such as apd.lacounty.gov, lcc.nebraska.gov, jakarta.bps.go.id, sanjuandelrio.gob.mx, poderjudicialchiapas.gob.mx, dprf.gov.br, and pn-jambi.go.id. Individual prices were attached to the listings, while some entries were subsequently marked as sold. The same message directed users to @Pandam******0x for further information, placing that handle alongside the Panda-era sales activity.

One listing provided a closer look at what was being offered. The account advertised bandungkota.bps.go.id as “shell access” for $100, with @Panda*****0x listed as the contact. An accompanying image showed what appeared to be an active Hidden Shell Version 3.0.2 interface carrying ALFA TEAM branding. The screen displayed server and filesystem information, including the path /datos/www/bandungkota/images/, as well as an Apache/PHP environment and functionality for interacting with files on the host. As with the later Ghost Seoul listings, the screenshot reflects evidence presented by the seller and should not be treated as independent verification that the advertised access remained valid at the time of observation.

The Panda operation also used a separate space for credibility and sales proof. Advertisements from @Panda*****0x directed buyers to the private Telegram invite:

  • https://t.me/+VPB*******NTM1

The link was described as a “Proofs Channel,” and its Telegram preview identified it as Panda Shells. One of the associated messages combined the invite with the seller's payment options and direct contact:

  • DM: @Panda*****0x
  • Proofs Channel: @t.me/+VPB***********NTM1

Another identifier, @panda***x, also appeared in text associated with the Panda Shells channel. At this stage, however, the available evidence does not establish what role that account played, so it remains an associated artifact rather than an attributed identity.

Overall, the Panda-era records push the observable webshell activity back months before the current Ghost Seoul branding. The names and presentation changed, but the underlying business was already recognizable: compromised access was advertised, priced, marked as sold, supported by proof material and promoted through dedicated Telegram channels.

The private Panda Shells link also gave the investigation somewhere new to go. Unlike a username that could change, the same invite began appearing in messages posted by other sellers, opening a path from the history of one account into the wider market operating around it.

Following the Market Around Panda

The Panda Shells invite offered a useful pivot because it was not confined to messages from @Panda*****0x. Searching the same private Telegram link across StealthMole surfaced it in other webshell-related activity, suggesting that the sales infrastructure around Panda extended beyond a single public account.

One of those appearances came from jacky27 / @ja*****7, Telegram User ID 7595948503. Messages associated with the account advertised webshell and cPanel access while pointing buyers toward the same private channel previously promoted by @Panda*****0x:

  • https://t.me/+VP************NTM1

This was a more meaningful overlap than two sellers simply appearing in the same Telegram group. During the Panda period, User ID 8423162304 had explicitly described the invite as its “Proofs Channel.” Finding @ja*****7 directing users toward that same destination connected the account to infrastructure already associated with Panda's sales activity.

The overlap, however, does not tell us exactly what that relationship was. @ja*****7 could have been another seller using a shared proof channel, a reseller working from the same inventory, someone cooperating with Panda, or simply a user republishing existing advertisements. The available evidence does not establish common ownership of the two Telegram accounts, so User ID 7595948503 remains a separate actor rather than another Panda alias.

Another contact surfaced repeatedly as the investigation moved through these webshell communities: @os*******e. Earlier searches for web*****r had already captured posts from an account appearing as C0L1N / @os*******e, Telegram User ID 6767763093. In one message, buyers were instructed:

  • Pm: @os*******e
  • Channels & Support: @web*****r

Other material placed the same account around Panda-era sales. A message attributed to Os/M1d / @os*******e, for example, advertised access to carnalprime.cl, quaorealty.com, carverdentallab.dev.tqnia.me and vermione.cz, but ended by directing buyers to:

  • PM: @Panda*****0x
  • CH: @Pandam******0x

The relationship also appeared in the opposite direction. On March 19, StealthMole captured C0L1N forwarding material originating from Ghost Seoul channel ID 3512450200, while the resulting advertisement used @os*******e as the direct contact and @web*****r as the channel. Rather than two completely separate sales footprints, the records showed C0L1N appearing around both the earlier Panda infrastructure and the later Ghost Seoul operation.

That pattern is significant, but it has limits. Nothing found so far establishes that User IDs 6767763093 and 8423162304 were controlled by the same person, nor does the overlap prove that C0L1N was formally part of Ghost Seoul. What the records do show is repeated commercial crossover: advertisements, contact points and channels associated with one seller appearing in activity involving the other.

Keeping those distinctions mattered, particularly with @os*******e, because unlike most of the surrounding accounts, his Telegram profile exposed an artifact that could be followed outside Telegram altogether: a phone number.

The C0L1N Pivot

The phone number attached to @os*******e offered something the other Telegram artifacts had not: a lead that could be followed outside the webshell channels themselves. Searching the account in StealthMole showed that C0L1N was no longer active under its observed identity, with the Telegram account currently deleted, but historical snapshots preserved enough information to continue tracing it.

The account was anchored to Telegram User ID 6767763093. In a March 8, 2026 snapshot, StealthMole recorded it as:

  • Name: C0L1N
  • Username: @os*******e
  • Telegram User ID: 6767763093
  • Phone: 18**********90
  • Bio: col1n has return

Like the primary Ghost Seoul account, C0L1N's Telegram identity had not remained static. Historical records captured at least three username or profile-name changes during March 2026 alone, while hundreds of messages associated with the account revolved around webshells and related access sales. The profile itself used Brazilian-themed imagery, including the country's flag, but there was no evidence to treat that branding as an indication of the operator's actual location or nationality.

The more useful artifact was 18**********90. Rather than stopping at the Telegram profile, the number was searched against StealthMole's compromised-data holdings, where it appeared across seven leaked files. This shifted the investigation away from what C0L1N chose to publish on Telegram and toward identifiers that had appeared alongside the same number elsewhere.

Several of those records were then examined through MoleChat to identify useful correlations without manually working through each dataset. One recurring association linked the phone number to the numeric identifier 30*****61 and the corresponding QQ email address:

  • 30********1@qq.com

The finding was useful, but it was not enough to put a real-world name behind C0L1N. The leaked records establish an association between 18**********90 and 30********1@qq.com; they do not establish who was controlling either identifier during the webshell activity observed in 2026.

Conclusion

Ghost Seoul initially appeared to be a relatively straightforward Telegram operation selling webshell and server access. Following the account behind those listings, however, showed that the identity visible in July 2026 was only the latest part of a longer history.

The most important thread throughout the investigation was not a username, but the underlying Telegram User ID. While names shifted from Panda and x***npanda identities to @c******es, User ID 8423162304 allowed activity separated by months, different handles and different Telegram communities to be connected back to the same account. That history showed that the commercial activity associated with Ghost Seoul had roots in an earlier Panda-branded webshell operation, where compromised access was already being priced, advertised and supported through dedicated sales and proof channels.

Following those older artifacts also exposed a wider marketplace around the account. The private Panda Shells channel, @Pandam******0x, @ja*****7 and @os*******e showed how advertisements and contact points moved between sellers and webshell-focused communities. Those overlaps do not establish a single organized group behind the accounts, but they do show that Ghost Seoul operated within an interconnected trading environment rather than in isolation. The C0L1N branch pushed that trail beyond Telegram altogether, linking User ID 6767763093 to phone number 18**********90 and, through leaked records, to QQ identifier 30*****61 and 30********1@qq.com. The trail ended there, without enough evidence to identify the person behind the account.

There are still important questions the available data cannot answer. The investigation does not establish the real-world identity or location of the Ghost Seoul operator, despite the operation's prominent Korean branding. It also does not reveal how the advertised systems were initially compromised, who purchased the access, or what buyers subsequently did with it. Likewise, listings marked as sold remain claims made by the seller rather than independent confirmation of successful transactions.

What the investigation does establish is a traceable history behind an identity that, viewed only in its current form, would have appeared much newer and more isolated. Ghost Seoul was where the trail began, but the account's earlier footprints showed that it was not where the story started.

Editorial Note

Attribution in underground ecosystems is rarely absolute. Usernames change, infrastructure is shared, and associations do not always imply common ownership. This investigation shows how StealthMole's historical records and cross-source pivots can help navigate that uncertainty, connecting activity across changing identities while keeping the line between what the evidence establishes and what remains unknown.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com




Labels: ,

Party Heaven and the Storefronts Next Door: Mapping a Dark Web Drug Network

Dark web drug markets rarely stay still for long. Storefronts disappear, onion addresses change, and familiar shops can return under new names or slightly altered branding. What looks like a single marketplace at first glance may therefore represent only one visible part of a much larger and longer-running operation. Following these markets requires looking beyond what is currently online and paying attention to the traces they leave behind.

Party Heaven, a Tor-based drug storefront describing itself as “The Paradise of Partying,” became the starting point for this investigation. The platform advertised a broad catalogue of illicit drugs and pharmaceutical products through a conventional e-commerce-style interface, presenting itself much like an ordinary online shop despite the nature of the products being sold.

What began as a closer look at Party Heaven gradually moved beyond the storefront itself. Using StealthMole, the investigation followed the digital traces surrounding the platform across historical dark web records, cryptocurrency infrastructure, archived content and recurring product material. Each pivot added another piece to the picture and raised a larger question: was Party Heaven really an isolated marketplace, or was it sitting alongside a wider collection of connected storefronts?

This report follows that investigation from the original Party Heaven shop outward, examining the relationships that emerged along the way while separating direct technical connections from similarities that, on their own, cannot establish common ownership.

Behind the Shop Window

The investigation began with Party Heaven’s primary Tor storefront:

  • w543g*******************************************cmid.onion

Indexed in StealthMole’s Darkweb Tracker under the title “Party Heaven – The Paradise of Partying,” the site followed a familiar e-commerce format. Products were displayed with photographs, prices and “Add to Cart” options, with categories spanning illicit drugs and pharmaceutical products. StealthMole had indexed around 70 images associated with the platform, including listings for products such as Viagra, morphine, cocaine, GHB, ketamine, PCP, LSD and other substances.

The storefront itself provided only part of the picture. A closer look at Party Heaven’s Frequently Asked Questions page offered considerably more insight into how the operation claimed to handle orders. According to the page, customers could pay using either Bitcoin (BTC) or Monero (XMR), while prices were also displayed in US dollars. Party Heaven claimed orders would be shipped within 24 hours, vacuum-sealed and packaged with a decoy. Weekend orders were reportedly held until Monday, while tracking information could be provided on request, although the operators reserved the right to withhold it if they believed doing so was necessary for security.

The refund policy was equally revealing. Party Heaven stated that refunds would not be provided without “proof of seizure,” and placed responsibility for providing a correct shipping address on the buyer. Rather than functioning as a multi-vendor marketplace with visible seller profiles, the site presented these policies as platform-wide operating procedures.

The FAQ also provided a contact point for customers, directing questions to the TorBox address:

  • PartyHeaven@torbox*******************************6to3uyqad.onion

The checkout page added another layer. Customers were specifically instructed not to use a clearnet email provider such as Gmail or ProtonMail, and were instead encouraged to use an onion-based hidden-service email account, with TorBox given as an example. Payment was required before an order would ship, and unpaid orders were stated to be automatically cancelled if payment was not received within one hour.

More importantly for the investigation, StealthMole exposed the cryptocurrency infrastructure attached to the storefront. Two Bitcoin addresses were associated with Party Heaven:

  • bc1q0v********************************0lkr
  • bc1qdn********************************dlmt

A Monero address was also identified:

  • 887v1Eg******************************************JfHx

At this point, Party Heaven was no longer simply a storefront with a catalogue of drugs. It had left behind several different kinds of artifacts that could be investigated independently: cryptocurrency addresses, historical web content, contact infrastructure and dozens of indexed product images.

One Monero Address, Another Party Heaven

The Monero address gave the investigation its first indication that the Party Heaven storefront visible today was not the only version of the platform that had existed.

Searching the address in StealthMole’s Darkweb Tracker led to another onion domain:

  • w543g***************************************7bqd.onion

It had been indexed under the same title, “Party Heaven – The Paradise of Partying,” and was first scanned on April 18, 2026. The last recorded scan was on August 6, 2026.

The site carried the same Party Heaven identity and presented a familiar catalogue of drugs through a storefront closely resembling the active domain. One preserved product page, for example, advertised “3-CL-PCP Crystals, 5g” for $199, under the PCP (Angel Dust) category.

There were some differences beneath the surface. While the active Party Heaven domain identified its web server as nginx/1.18.0, StealthMole recorded the inactive domain running Apache/2.4.68 (Debian). This meant visual similarity alone was not enough to simply assume identical infrastructure. However, the combination of the Party Heaven branding, matching storefront characteristics and its appearance during the Monero-address pivot made the inactive onion a much stronger lead than a lookalike website discovered in isolation.

That historical storefront contained another particularly useful source of evidence: its product images.

Rather than treating those photographs simply as illustrations for drug listings, the investigation began using them as searchable artifacts. One image associated with a Nepal hash listing was selected and traced through StealthMole to determine whether the exact same material had appeared elsewhere.

Same Shelves, Different Shop Signs

The Nepal hash image provided the first clear indication that Party Heaven's product catalogue was not confined to Party Heaven.

When the image was searched through StealthMole, the same artifact appeared across several other Tor domains. What made the results particularly interesting was that these sites were not presenting themselves as Party Heaven mirrors. They carried entirely different names and branding:

  • syorb4**********************************************ccyd.onion Party Pharmacy – Where going to the pharmacy can be FUN
  • ipqqm**********************************************f2eid.onion Dope Temple – In Dope We Trust
  • h5jaug*********************************************rajqd.onion Party Paradise – Come and Join the Party :)
  • lkbp4**********************************************ja2ad.onion Fun Pharmacy – Everyone's Favorite Party Doc

The shared image was enough to put these storefronts on the investigative map, but there were other similarities worth noting. Their names followed a noticeably similar theme, while the storefronts themselves used familiar product-led layouts. Fun Pharmacy, for example, displayed 45 products through a Shop, FAQ, Cart and Checkout structure that closely resembled what had already been observed on Party Heaven. Its catalogue included products such as Generic Viagra and Adderall alongside other drugs and pharmaceuticals.

A second image pivot reinforced the pattern. The same morphine.jpg seen across these storefronts was searched by its exact file hash in StealthMole, which associated it with nine Tor domains. Among them were Party Heaven and additional instances of familiar brands:

  • efcygzbnh5fow3jl5gr6rudejbw7yabixe4c5ggo5iw2mnqlz3yxaqqd.onion Dope King – The King of Partying
  • sloxx2hmdsdme4lynn77old67f52nadaed4rpqbyjnyt54divsqny7id.onion Party Animals – Everything For Your Party Needs
  • yjzto6mzyns4wwwckdbjgdrp3nepbjv4wvm2knqzbx3ycx7udchhlbqd.onion Partylicious – The Party Pros

Together, the two image pivots showed the same product material recurring across differently branded storefronts. That was enough to widen the investigation, but not enough to establish common ownership. Product images and storefront templates can be copied or reused, so these domains were treated as content-overlap leads rather than Party Heaven mirrors.

The Wallet That Actually Moved

The first Bitcoin address provided little room to continue.

  • bc1q********************************lmt

Although the address had appeared directly on Party Heaven's checkout page as a payment option, checking its blockchain history showed no transactions. Whatever its intended purpose on the storefront, there was no financial activity to follow.

The second address told a very different story:

  • bc1q0********************************500lkr

Running it through StealthMole first produced another Party Heaven onion:

  • W543gjeqesapphdx7gtu7cepkp2i2k6cfmcvczt4au4szknsd6d7afid.onion

This domain was no longer active. Its association with the Bitcoin address nevertheless provided another route into Party Heaven's past and added a further onion address to the growing collection of storefront infrastructure uncovered during the investigation.

This time, however, the blockchain itself also had something to say.

StealthMole's Crypto Tracker showed activity associated with the wallet stretching across several years. The address first received Bitcoin on January 7, 2022, and its last recorded incoming transaction occurred on January 28, 2025. Outgoing activity began on March 25, 2022 and continued until May 18, 2025.

StealthMole's Crypto Tracker also flagged transaction relationships involving addresses attributed to Crypto.com Exchange and Paxos. These connections were useful investigative markers, but they did not identify whoever was behind Party Heaven. A blockchain interaction with an address associated with an exchange or financial service does not, by itself, establish that the Party Heaven operator personally maintained an account there, nor does it reveal the identity of an account holder.

The more consequential finding came from the inactive Party Heaven domain discovered through the wallet.

When w543gjeqesapphdx7gtu7cepkp2i2k6cfmcvczt4au4szknsd6d7afid.onion was examined further in StealthMole, it produced 25 Bitcoin addresses associated with its historical records.

That changed the scale of the investigation again. Until this point, the connections around Party Heaven had largely emerged through mirrors and reused product content. The new dataset provided something different: a collection of cryptocurrency artifacts that could each be followed independently.

Bitcoin Wallets and a Lot More Than Party Heaven

The 25 Bitcoin addresses associated with the inactive Party Heaven domain offered 25 possible directions for the investigation. Most did not provide meaningful blockchain activity, but searching the addresses through StealthMole produced something arguably more useful: several of them appeared alongside other dark web storefronts.

The full set identified from the Party Heaven domain was:

  • Bc1qj*********************************d5fe
  • Bc1ql*********************************lf4u
  • Bc1qr********************************cj640
  • Bc1qj********************************8z9ke
  • Bc1qw*********************************fy4m
  • Bc1q7*********************************yevk
  • Bc1qn*********************************q72q
  • Bc1q7*********************************z3ew
  • Bc1qn*********************************eeyv
  • Bc1qa*********************************gd7d
  • Bc1q3*********************************mfvc
  • Bc1qe*********************************j3a8
  • Bc1qc*********************************87s7
  • Bc1q8*********************************wuaf
  • Bc1q0*********************************0lkr
  • Bc1qp*********************************zs2p
  • Bc1qm*********************************q3uq
  • Bc1q3*********************************h775
  • Bc1qs*********************************z48y
  • Bc1q3*********************************h8nv
  • Bc1q2*********************************y342
  • Bc1q8*********************************dktk
  • Bc1qy*********************************pzjy
  • Bc1ql*********************************v9w2
  • Bc1qy*********************************0v0r

Several addresses immediately opened doors into storefronts carrying names that felt increasingly familiar.

The address bc1qly********************lf4u appeared in connection with an inactive shop called “Party Animals – Everything For Your Party Needs”:

  • Sloxx2hmmc7gdkzkzkkfsvicrrmibx6fxffckjzetlgesithy4mq7oad.onion

Another address, bc1q7dy**********************z3ew, led to “Dope King – The King of Partying”:

  • efcyaq3453xjisugllr4lazoedyo6pthhc4j5tpl5cyoihp6huscnpqd.onion

Then came Party Paradise. The address:

  • bc1qs************************************z48y

was associated with an inactive storefront titled “Party Paradise – Come and Join the Party :)” at:

  • H5jauggmlbo3ntusetik6uvylwckmjwixaab4htnddoy65qki7ibk2id.onion

Its archived storefront contained 36 products, with product names and imagery again resembling material encountered elsewhere during the investigation.

The same Bitcoin address also appeared in connection with another inactive onion titled Silver Magazine:

  • 7lr3qeslthipebdvn424wwvb272eowsrw33fracoqjpeohj66hvff3id.onion

That association was recorded, but deliberately not treated as evidence that Silver Magazine formed part of the same drug-storefront cluster. The nature of the site differed substantially from the other findings, and an indexed wallet relationship without further context was not enough to establish why the address appeared there.

Another unexpected result came from:

  • bc1q3****************************mh8nv

StealthMole associated the address with an inactive weapons storefront titled “Guns"R"Us – The 2nd Amendment Store”:

  • 7vugm3oxle3e6z5v2snu5fwvbgajqmt2hw3hgqviaafaqd2levfsubid.onion

Again, the finding was kept separate from the developing drug-storefront cluster. Without additional evidence explaining the relationship, folding an unrelated weapons shop into the network simply because an address appeared in both datasets would have gone beyond what the evidence could support.

Other pivots stayed much closer to the pattern already emerging.

  • bc1q8******************************dktk

led to “Drugazon – The Amazon of Drugs”:

  • 4wmicvgfw2nodbvlj7ovvfwyxr5guj64sqtnkvwhjtcmonc4ywabvoad.onion

StealthMole had first scanned Drugazon on March 10, 2025, with its last recorded scan on November 19, 2025. Its orange colour scheme distinguished it visually from Party Heaven, but underneath the different branding the similarities were difficult to miss. The archived shop displayed 40 products through the same familiar Shop, FAQ, Cart and Checkout structure, while numerous product photographs, names and prices closely resembled those already observed on Party Heaven.

Finally,

  • bc1ql****************************v9w2

surfaced another inactive storefront, Dopassic Park, at:

  • Hyzmpq2fo637gfuerzwtqzqcpgmu2kyhibd3kfx6aq2vgtniz3eu2rqd.onion

By now, the investigation had reached a very different place from where it started. A single Party Heaven domain had led to a historical mirror, that mirror had exposed a collection of Bitcoin artifacts, and those artifacts were repeatedly surfacing alongside differently branded dark web shops. Not every association carried the same weight, and some were intentionally set aside rather than forced into the emerging picture.

Party Paradise Opens Another Ledger

Party Paradise was worth examining more closely because the connection no longer rested on product imagery alone. The domain had already surfaced through a Bitcoin address found within the Party Heaven-associated dataset, giving the investigation a financial artifact that could be tested from the other direction.

The storefront in question was:

  • H5jauggmlbo3ntusetik6uvylwckmjwixaab4htnddoy65qki7ibk2id.onion

When this domain was investigated independently in StealthMole, Darkweb Tracker returned 21 Bitcoin addresses associated with its historical records:

  • Bc1q**********************************h8nv
  • Bc1q8*********************************wuaf
  • Bc1qy*********************************nphx
  • Bc1q8*********************************sgya
  • Bc1qn*********************************eeyv
  • Bc1qc*********************************87s7
  • Bc1q3*********************************mfvc
  • Bc1qa*********************************gd7d
  • Bc1q7*********************************z3ew
  • Bc1qe*********************************j3a8
  • Bc1q**********************************xayr
  • Bc1q**********************************7jja
  • Bc1q**********************************ejmg
  • Bc1q**********************************u69a
  • Bc1q**********************************jkxj
  • Bc1q**********************************aaf6
  • Bc1q**********************************yevk
  • Bc1q**********************************z48y
  • Bc1q**********************************cvat
  • Bc1q**********************************4rce
  • Bc1q**********************************lyzl

The list became much more interesting when it was compared with the 25 addresses previously surfaced from the Party Heaven-associated onion. Ten Bitcoin addresses appeared in both datasets:

  • Bc1q************************************h8nv
  • Bc1q************************************wuaf
  • Bc1q************************************eeyv
  • Bc1q************************************87s7
  • Bc1q************************************mfvc
  • Bc1q************************************gd7d
  • Bc1q************************************z3ew
  • Bc1q************************************j3a8
  • Bc1q************************************yevk
  • Bc1q************************************z48y

This was a more meaningful overlap than the visual similarities that had first drawn attention to the other storefronts. Party Paradise and the Party Heaven-associated domain were not connected by a single address appearing somewhere in StealthMole's historical data. Nearly half of the Bitcoin artifacts identified for this Party Paradise instance were also present in the Party Heaven-derived set.

Conclusion

What began as a closer look at a single drug storefront ultimately revealed a much broader collection of relationships. Party Heaven appeared across multiple onion addresses, while pivots through its cryptocurrency artifacts and product imagery repeatedly surfaced differently branded shops such as Party Paradise, Party Animals, Dope King, Drugazon, Dopassic Park and others.

The strongest indication of a deeper connection came from the cryptocurrency data. Party Paradise independently surfaced 21 Bitcoin addresses, ten of which overlapped with the 25-address dataset associated with a Party Heaven domain. Combined with recurring product imagery, similar storefront structures and multiple instances of the same brands, the findings suggest these sites were not simply isolated shops encountered by chance.

What the evidence does not establish is equally important. It cannot confirm that every storefront identified in the investigation was operated by the same individual or group. Some relationships were considerably stronger than others, and shared content or indexed cryptocurrency artifacts alone cannot prove common ownership. What StealthMole did reveal, however, was a persistent and interconnected footprint surrounding Party Heaven that extended well beyond the single active storefront where the investigation began.

Editorial Note

Dark web investigations rarely produce absolute answers, particularly when storefronts change domains, reuse content, rotate cryptocurrency addresses, or disappear altogether. The connections identified in this investigation should therefore be understood according to the strength of the underlying evidence rather than treated as proof of common ownership.

The Party Heaven case demonstrates how StealthMole can help navigate that uncertainty by bringing historical Tor records, cryptocurrency artifacts, archived storefronts and recurring digital content together, allowing relationships to emerge that would be difficult to see from any single data point alone.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com




Labels: ,

From Alias to Identity: Following the Digital Footprints Behind a Telegram Drug Seller

Telegram has become an increasingly convenient marketplace for illicit drug sellers. The same features that make the platform useful for ordinary communication, including public channels, direct messaging and easy-to-create accounts, also allow dealers to advertise products, reach potential buyers and operate behind usernames that reveal very little about who is actually running them. Cannabis sellers are particularly easy to come across, with accounts openly posting photographs of marijuana, prices and contact details while maintaining little obvious connection to a real-world identity.

But an alias is only as anonymous as the digital history behind it.

This investigation began with one such Telegram-based drug seller. At first glance, there was little to distinguish the account from countless others advertising cannabis through the platform. Rather than treating the visible Telegram profile as the end of the trail, the investigation used StealthMole to look beyond what was currently available and examine the historical traces surrounding the account.

This report follows that investigation from its starting point, showing how a trail scattered across Telegram history, leaked data and other online records was pieced together one artifact at a time.

The Account That Started It All

The investigation began with a deliberately broad search. Using StealthMole’s Telegram Tracker, we searched for “weed dealer” to see whether an openly advertised drug-selling account could be taken beyond what was immediately visible on Telegram. The query returned 14 user records and approximately 80 messages, providing several possible starting points.

One account stood out almost immediately. It appeared in the results under the name Weed Dealer | UG 🆓 🌱SEED 🐦 🍅 🐾/WAVE 🌊, with the Telegram username @tieuho****0. Unlike accounts that merely mentioned cannabis or appeared in conversations about drugs, this profile was notable because it presented itself directly as a weed dealer. That made it a more relevant target for examining whether an apparently pseudonymous Telegram seller could be followed through StealthMole’s historical data.

Looking at the account as it exists more recently, however, revealed surprisingly little. The profile displayed the name Tiêu Hồ, carried no profile photograph, and offered few obvious clues about the person behind it. Searching the account itself in Telegram Tracker changed that picture.

StealthMole associated the account with the persistent Telegram ID 1068143976 and preserved 25 historical name records, showing that its visible identity had changed repeatedly over the years. The historical snapshots were considerably more revealing than the current profile. Earlier versions contained multiple photographs of what appeared to be the same individual, while other snapshots shifted toward cannabis-related imagery and drug-oriented profile names.

Some of those historical photographs also exposed details that would no longer be apparent from viewing the account today. In a snapshot dated 22 December 2022, the individual was photographed standing in front of a dark vehicle with the registration plate 79A-2******8 clearly visible. Another snapshot, dated 28 February 2023, showed him alongside a white Mercedes-Benz displaying a second plate, 79A-3*****7.

The first plate offered an immediate external point of comparison. A search for 79A-2******8 produced an exact match on PlatesMania, where an independently photographed dark Lamborghini Urus, first generation (2018–2022) carried the same registration. The listing identified the plate as Vietnamese, registered in Khánh Hòa Province, and placed the photographed vehicle in Phước Long, Nha Trang. The image had been posted by a contributor using the name Bún bò on 17 January 2025 at 1:08:27 PM.

A Wallet That Wasn’t a Wallet

With the profile history offering several clues but no clear identity, the investigation moved to another artifact associated with tieuho****0: an Ethereum address.

  • 0x09c*****************************638

At first, the address looked like a promising cryptocurrency lead. If it belonged to the seller, its transaction history could potentially reveal another part of the account’s digital footprint. Consequently, the address was searched further in StealthMole’s Telegram Tracker.

The search returned several user records and messages mentioning the address. Among them was one result that could be tied directly back to the account being investigated. On 13 May 2023, Telegram ID 1068143976, appearing at the time as Seller | UG//@tieuho****0, had posted the address in a channel. The message read “Happy mother's day”, followed by the Ethereum address and an attached photograph.

The direct match confirmed that the address had indeed been shared by tieuho****0, but a closer examination changed what the artifact meant. Etherscan identified it not as a personal Ethereum wallet, but as a smart contract associated with the ERC-20 token mother (MOTHER). At the time of examination, the contract showed 1,436 transactions. Other Telegram results provided further context, including a message from the 0xGemi channel that referred to the same address as “Mother Contact” while discussing the token.

A search through StealthMole’s Dark Web Tracker produced another apparent lead. The contract address appeared within an indexed onion page containing Polygon ERC-1155/NFT transaction data. The record included Polygon transaction:

  • 0x09************************************************3a43

and was indexed from:

  • 3xplor3****************************************xyd.onion

One Alias, More Than One Footprint

After investigating the cryptocurrency, the investigation returned to the simplest artifact available: tieuho****0. This time, instead of looking at Telegram, the username was searched through StealthMole’s Dark Web Tracker to determine whether it had surfaced in previously leaked or indexed data.

One leaked document contained a record for tieuho****0 that matched the same Telegram ID 1068143976 already established through Telegram Tracker. That match was important because it provided continuity between the Telegram profile and the newly discovered record. More importantly, the entry contained several fields that had never been visible from the Telegram account itself:

  • Telegram Username: tieuho****0
  • Telegram ID: 1068143976
  • Referrer Username: thuytienbtc
  • Referrer ID: 5071132186
  • Invited: 0
  • Tokens: 2000
  • Email: tieuho****0@gmail.com
  • Wallet: 0xdFc**********************************695
  • Twitter: https://mobile.twitter.com/tieuho****0
  • Review: https://twitter.com/AirdropDet/status/1509606654905421833

The wallet field was more immediately actionable. Unlike the MOTHER contract encountered earlier, the record explicitly labelled the new ETH wallet as associated with the tieuho****0 entry. The combination of the exact username and Telegram ID made this a substantially stronger lead, although the leaked dataset alone could not establish that the person controlling the Telegram account also controlled the address.

  • 0xdFc******************************695

The wallet was therefore checked independently. Etherscan showed an address with 165 transactions, rather than another token contract. It held no ETH at the time of examination and approximately $0.07 across 18 token holdings, while its historical activity showed both incoming and outgoing transactions. Etherscan also indicated that the address had originally been funded by Binance 17.

StealthMole’s Wallet Risk Check provided a different view of the same activity. The address was flagged as Medium Risk. Of the 147 transactions analyzed by the platform, 22 were flagged as suspicious, representing 15% of the analyzed transactions and approximately 6.7% of the analyzed ETH volume. No blacklisted contacts were identified.

The behavioral indicators were more notable. StealthMole flagged Abnormal Relaying, Abnormal Mixing, and Relaying and Mixing, alongside a dormant transaction status. The last transaction recorded by the platform was dated 18 April 2025.

The transaction graph also showed how widely the address had interacted across the cryptocurrency ecosystem. Labeled nodes included Binance Exchange, Bitget Exchange, Bybit Exchange, MEXC Global Exchange, OKEx Exchange, Uniswap, Orbiter Finance Bridge, MetaMask-related contracts and routers, and a Binance User Wallet.

None of those labels, or the Medium Risk score itself, demonstrated that the wallet had been used to receive proceeds from drug sales. Likewise, StealthMole's detection of mixing and relaying patterns should not be treated as proof of money laundering. What the analysis established was narrower but still valuable: a wallet explicitly attributed to tieuho****0 by a leaked record had an extensive transaction history and displayed several behaviors that StealthMole considered worthy of additional scrutiny.

The leaked record had also introduced something the blockchain could not answer: an email address. That provided the investigation with a completely different route away from cryptocurrency and toward the identity behind the account.

The Password That Connected Two Identities

The email tieuho****0@gmail.com found in the leaked record opened a different line of investigation. Instead of looking for more blockchain activity, the next step was to determine whether tieuho****0 had appeared in credential data indexed by StealthMole.

A search in Combo Binder returned 63 results. tieuho****0@gmail.com appeared with several variations of the same password, built around Ban*****5, including versions with different capitalization and special characters.

Rather than treating the credential itself as the finding, the password became another search term. Searching the exact leaked password in Combo Binder produced a second email address:

  • ban*******5@gmail.com

This was more interesting than a simple similarity between usernames. Both tieuho****0@gmail.com and ban*******5@gmail.com appeared in compromised credential data with the same exact password. The ban******5 identifier was also embedded directly in the password family repeatedly associated with the first email address.

With ban*******5@gmail.com now providing a second account to examine, the investigation moved beyond leaked credentials to see what was publicly associated with the two email addresses. Checking the addresses through Google produced profile photographs for both accounts. The profile associated with tieuho****0@gmail.com displayed a photograph of a man, while ban*******5@gmail.com displayed a photograph of a woman.

The second image was particularly important because it introduced uncertainty rather than resolving it. Although ban*******5@gmail.com shared the exact leaked password associated with tieuho****0@gmail.com, its Google profile did not provide additional evidence that the address was controlled by the same individual. Instead, it reinforced the need to treat the email as a connected account or investigative lead rather than automatically assigning ownership to the person behind tieuho****0.

When the Alias Finally Had a Name

The search for tieuho****0@gmail.com in Dark Web Tracker produced another leaked CSV record. Unlike the earlier dataset, which had mainly exposed online identifiers, this entry contained information that appeared to move the investigation much closer to a real-world identity.

The matching record contained:

  • Location: Khánh Hòa
  • Name: Hồ Quốc Thanh
  • Email: tieuho****0@gmail.com
  • Phone: +84*********39
  • User/Record ID: 60e****************48
  • Code: qeabag8
  • Related ID: 60e06f9e9c9bb00d4bbc9ae2
  • Related Name: Lê Xuân Ngọc
  • Related Number: 382966254
  • Related Code: ykbpyy6
  • Status: NO

For the first time, Hồ Quốc Thanh appeared directly alongside the email address that had already been connected to tieuho****0 through the previous searches. The record also introduced a Vietnamese phone number and listed Khánh Hòa as the location.

The location was particularly notable in light of an earlier, completely different part of the investigation. The two vehicle plates visible in the historical Telegram photographs carried the 79 Khánh Hòa registration code, and the independent PlatesMania sighting of 79A-2******8 had placed that Lamborghini Urus in Phước Long, Nha Trang. Now, a leaked record connected to the account's email independently pointed to Khánh Hòa as well. Neither finding proved where the individual lived, but the same region emerging through unrelated artifacts made the geographic connection harder to dismiss as incidental.

The more immediate question was whether Hồ Quốc Thanh existed elsewhere in StealthMole's indexed data.

Searching the name in Dark Web Tracker produced a social-media record for the Twitter account:

  • https://twitter.com/ban*****5

The account was indexed under the name Hồ Quốc Thanh, with the Twitter ID ban****5 and email address:

  • ban*******5@gmail.com

That result brought the investigation back to an identifier discovered through an entirely different route. ban*******5@gmail.com was the same second email uncovered when the leaked credential associated with tieuho****0@gmail.com was pivoted through Combo Binder.

The connection had therefore come together from two directions. Credential data had linked tieuho****0@gmail.com and ban*******5@gmail.com through exact password reuse. Separately, Dark Web Tracker associated tieuho****0@gmail.com with the name Hồ Quốc Thanh, while another indexed record associated ban*******5@gmail.com and Twitter ID ban******5 with that same name.

Conclusion

What began as a broad search for a weed dealer on Telegram eventually moved far beyond the profile that first appeared in the results. Historical Telegram data exposed earlier photographs and vehicle registrations, cryptocurrency artifacts opened additional investigative paths, and leaked records introduced identifiers that were no longer visible from the account itself. Some of those leads went nowhere, while others became more meaningful only when they appeared again through a completely different source.

The strongest point of convergence was Hồ Quốc Thanh. The name appeared in a leaked record alongside tieuho****0@gmail.com, while the same email had already emerged through the investigation of the Telegram account and compromised credential data. A separate record then associated the same name with the ban******5 Twitter identity and ban*******5@gmail.com, an address independently connected to tieuho****0@gmail.com through exact password reuse. The geographic evidence added another layer: the leaked record placed Hồ Quốc Thanh in Khánh Hòa, the same province indicated by both vehicle registrations recovered from historical Telegram photographs.

Together, these findings provide a credible basis for assessing Hồ Quốc Thanh as a likely real-world identity associated with tieuho****0, but they stop short of definitive attribution. The investigation does not establish ownership of the photographed vehicles, prove that the attributed cryptocurrency wallet received proceeds from drug sales, or demonstrate that every connected email and social-media account was controlled by the same individual.

That distinction matters. The value of this investigation was not simply finding a name at the end of a search. It was seeing how an account that currently reveals very little had accumulated enough fragments across Telegram history, leaked databases, credentials, cryptocurrency records and other online sources for an alias to gradually become much less anonymous.

Editorial Note

Attribution in underground ecosystems is rarely absolute. Usernames change, infrastructure is shared, and associations do not always imply common ownership. This investigation shows how StealthMole's historical records and cross-source pivots can help navigate that uncertainty, connecting activity across changing identities while keeping the line between what the evidence establishes and what remains unknown.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com









Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report