From Lucky 47 to Luhansk Counter Kiev Partisans (Luckp 47): Mapping the Infrastructure Behind a Weapons Marketplace

Darkweb has long provided space for anonymous marketplaces selling weapons, forged documents, hacking services, and other illicit goods. But over the past few years, especially amid ongoing geopolitical conflicts, some of these platforms have started evolving beyond simple criminal storefronts. Instead of remaining hidden in the background, certain marketplaces now attempt to build recognizable identities through aggressive branding, ideological messaging, and carefully curated narratives designed to attract attention within underground communities.

During routine monitoring of weapons-related activity, StealthMole identified a marketplace operating through the Tor network under the name “Luckp 47 Shop.” At first glance, the platform appeared to be another weapons-focused onion service circulating within dark web ecosystems. However, several elements surrounding the marketplace, including its branding style, external references, and connected infrastructure, suggested there was a larger story behind the operation.

What followed was a broader investigation that moved far beyond a single onion domain. By tracing related infrastructure and examining references across underground platforms and Telegram-based communities, the investigation gradually exposed a wider ecosystem of interconnected services, wartime imagery, and overlapping narratives tied to the Luckp 47 operation. Rather than functioning as an isolated marketplace, the platform appeared embedded within a much broader underground environment shaped by conflict-driven themes and anonymous cross-platform promotion.

Incident Trigger and Initial Investigation

The investigation began while examining unrelated dark web infrastructure through StealthMole, during which an onion domain was identified. Although the marketplace was inactive at the time of access, archived snapshots preserved through StealthMole provided a clear view of the platform’s structure, branding, and operational claims.

  • luckp47hkr3te6v6uigtfma4jn5sdmjgsvy3kuf3hbg6uxm5bpti2tyd.onion

The marketplace operated under the name “Luckp 47 Shop” and presented itself as a weapons-focused storefront offering military-style firearms, launchers, suppressors, ammunition, grenades, and tactical accessories. Listings observed on the platform included RPG-series launchers, rifle optics, ammunition packages, and other combat-related equipment, with product pricing displayed in Euros. The site also claimed worldwide shipping capabilities and instructed buyers to provide delivery coordinates during the ordering process.

Additional details on the homepage suggested the operators were attempting to project legitimacy and operational reach. The marketplace claimed that inventory was stored within the European Union and promoted multilingual support in English, German, and Russian. Payment instructions directed users toward cryptocurrency transactions, primarily Bitcoin, and included a publicly visible BTC wallet alongside QR-based payment guidance.

While the storefront itself was already notable, several visual and operational details immediately stood out during the initial review. Product photographs across the marketplace contained handwritten “Lucky 47 Shop” markings, seemingly intended to reinforce authenticity or marketplace identity. At the same time, the platform’s design, terminology, and overall presentation differed noticeably from many low-effort darknet weapon listings commonly observed across Tor-based marketplaces.

Financial Infrastructure Linked to the Primary Luckp 47 Domain

Following the initial review of the Luckp 47 marketplace, the investigation shifted toward identifying additional infrastructure connected to the primary onion service:

  • luckp47hkr3te6v6uigtfma4jn5sdmjgsvy3kuf3hbg6uxm5bpti2tyd.onion

Using StealthMole’s Darkweb Tracker, the domain was found to be associated with multiple Bitcoin wallets beyond the single address publicly displayed on the marketplace homepage. In total, ten BTC wallets were linked to the domain:

  • bc1************************************xgd
  • bc1************************************xyg
  • bc1************************************g4h
  • bc1************************************hql
  • bc1************************************hca
  • bc1************************************fzf
  • bc1************************************uhu
  • bc1************************************lvs
  • bc1************************************ehw
  • bc1************************************03j

One of these wallets, bc1**********************03j, matched the Bitcoin address publicly visible within the marketplace payment instructions, helping validate the association between the domain and the identified wallet cluster.

Interestingly, several of the wallets showed no publicly observable transaction activity at the time of analysis. While inactive wallets alone do not confirm whether the marketplace was fully operational, the presence of multiple associated addresses suggested that the platform may have relied on rotating or pre-generated cryptocurrency wallets rather than a single static payment address.

Beyond the financial infrastructure, archived marketplace images also revealed repeated use of handwritten “Lucky 47 Shop” markings placed directly onto firearm photographs featured within the storefront. Although such imagery does not independently confirm ownership of the weapons displayed, the repeated branding suggested an effort to establish marketplace identity and visual consistency across the platform’s listings.

Expanding the Investigation Through Contact Infrastructure

After documenting the wallet infrastructure tied to the primary Luckp 47 domain, the investigation shifted toward the marketplace’s publicly listed contact information. The homepage of the original onion service referenced the email address:

  • l*****7@b****mail.net

When the address was pivoted through StealthMole, the investigation rapidly expanded beyond the original storefront. Multiple additional onion domains were identified as being associated with the same contact infrastructure, including both active and inactive marketplace deployments.

The following domains were linked to the email address during the investigation:

  • luckp47s6xhz26rn.onion
  • luckp4k5jzwsofw6dulfvmc5clj75ww2ysgcwvj7yfunnc2i7terp4qd.onion
  • luckp4z2byqzvsweqzrtlkffob7wxhdnmcno7tv7wxrnuik5euje4cqd.onion
  • luckp***********************************************igyd.onion
  • 27b**************************************************ryd.onion
  • 27b**************************************************6id.onion

Although the domains did not all use identical branding, several shared noticeable similarities in structure and presentation. Archived snapshots revealed overlapping product categories, reused weapon imagery, similar payment instructions, and repeated marketplace layouts across multiple storefronts. Some domains continued operating under the “Luckp 47 Shop” identity, while others appeared under the name “Freedom Shop.”

The “Freedom Shop” marketplaces were particularly notable because, despite the branding differences, they displayed strong visual and operational overlap with earlier Luckp-related infrastructure. Similar storefront structures, repeated product imagery, and connected cryptocurrency infrastructure suggested that the domains were likely part of a broader interconnected marketplace ecosystem rather than unrelated standalone sites.

The investigation also revealed signs of long-term infrastructure persistence. Older domains used shorter legacy Tor v2 onion addresses, while newer deployments transitioned toward modern v3 onion services. This gradual migration indicated that the infrastructure was repeatedly redeployed and maintained over time rather than abandoned after a single operational period.

Marketplace Evolution and Operational Patterns

As the investigation expanded across the newly identified domains, a recurring operational pattern began to emerge. Several Luckp- and Freedom-related onion services contained large clusters of associated Bitcoin wallets, many of which showed no publicly observable transaction activity. This behavior appeared repeatedly across different marketplace deployments and suggested that the infrastructure relied on rotating or pre-generated wallet pools rather than a single long-term payment address.

For example, the domain:

  • 27bpw*********************************xryd.onion

was associated with ten additional BTC wallets. However, analysis of those wallets showed no recorded transaction activity.

  • bc1************************************w4j
  • bc1************************************hmn
  • bc1************************************4s2
  • bc1************************************x87
  • bc1************************************k2w
  • bc1************************************rrk
  • bc1************************************ese
  • bc1************************************uur
  • bc1************************************g5n
  • bc1************************************3jn

Similar inactive wallet clusters later appeared across multiple other Luckp-related domains, including:

  • luckp42********************************************xigyd.onion
  • luckp4z2byqzvsweqzrtlkffob7wxhdnmcno7tv7wxrnuik5euje4cqd.onion
  • luckp4k5jzwsofw6dulfvmc5clj75ww2ysgcwvj7yfunnc2i7terp4qd.onion

While many of these wallets remained inactive, other parts of the infrastructure displayed clearer signs of operational use. One of the more significant findings emerged from the domain:

  • 27bpwhs**************************************66id.onion

where the following Bitcoin wallet showed observable transaction activity over time. Further investigation revealed that the same wallet also appeared on a separate underground platform identified as “Bitstore,” where it was referenced as an escrow wallet. Although the overlap did not conclusively establish common ownership between the platforms, it demonstrated that parts of the financial infrastructure were circulating across multiple underground services rather than remaining isolated to a single marketplace.

  • 1KpBj*******************9gz

The same domain also introduced Ethereum-based payment infrastructure through the wallet:

  • 0xf5f********************************de0

Unlike earlier Luckp-related domains that primarily relied on Bitcoin, this deployment showed signs of broader cryptocurrency usage. StealthMole tracking linked the Ethereum wallet back to the same onion infrastructure, while associated pages revealed references to external services and hidden wiki-style navigation structures embedded within the marketplace environment.

Another notable development appeared during analysis of:

  • luckp42mxih5kz4hswcfmzllgrm5a6vn463pmssk5fxpuo2dz7xszjqd.onion

which introduced Monero payment support through the wallet:

  • 85PKg**********************************************Epa

Unlike earlier storefront snapshots, this domain exposed portions of the marketplace ordering workflow itself. Archived pages displayed shipping information forms, order identifiers, cryptocurrency payment instructions, and checkout-related infrastructure integrated directly into the platform. The use of Monero, a cryptocurrency heavily associated with privacy-focused transactions, marked a noticeable shift from the earlier BTC-centric deployments observed during the investigation.

Uncovering the Meaning Behind “Luckp”

For much of the investigation, the term “Luckp” appeared to function as little more than marketplace branding. Earlier storefronts alternated between names such as “Luckp 47 Shop” and “Lucky 47 Shop,” while associated Telegram mentions and underground references often used the terms interchangeably. At that stage, the marketplace primarily appeared to be another weapons-focused onion service operating within a crowded dark web ecosystem.

That changed during analysis of the older onion domain:

  • luckp47s6xhz26rn.onion

Unlike several of the newer domains identified earlier in the investigation, this marketplace preserved older archived content that exposed additional branding and narrative elements not immediately visible within the more recent infrastructure. One of the most significant discoveries was the appearance of the phrase directly alongside the Luckp branding.

  • Luhansk Counter Kiev Partisans

The wording provided the first clear indication that “Luckp” was likely being used as an acronym rather than a randomly selected marketplace name. This substantially shifted the context surrounding the operation. What initially appeared to be a conventional darknet weapons storefront now carried explicit wartime and conflict-oriented messaging tied to the Russia-Ukraine conflict narrative.

The marketplace itself reinforced this positioning visually. Archived snapshots featured militarized imagery, references to the “Ukrainian War,” and branding themes centered around conflict, insurgency, and resistance-style symbolism. Compared to many generic darknet marketplaces that rely on minimalist storefront designs, the Luckp infrastructure appeared intentionally curated to project a distinct identity rather than functioning solely as an anonymous transaction platform.

At the same time, the investigation did not uncover definitive evidence linking the marketplace to any verified militant organization or real-world armed faction operating within the conflict zone. The branding may have reflected ideological positioning, deliberate marketing, or an attempt to build legitimacy within underground communities already focused on wartime narratives and weapons trafficking.

However, the discovery fundamentally changed the direction of the investigation. The case was no longer centered purely on identifying a darknet marketplace selling weapons. Instead, the infrastructure increasingly appeared to be combining illicit commerce with conflict-oriented branding designed to embed the platform within the broader symbolism and online narratives surrounding the ongoing war.

Transactional Activity and Wallet Rotation Patterns

While the ideological and wartime branding surrounding the Luckp infrastructure became clearer through archived marketplace content, the financial activity tied to the older domains revealed another important layer of the operation. Unlike many of the newer Luckp-related onion services that were associated with inactive Bitcoin wallets, the older infrastructure showed sustained transactional behavior spanning multiple years.

StealthMole identified fourteen BTC wallets associated with:

  • luckp47s6xhz26rn.onion

The wallets included:

  • 1Nkm6B************************Hbze
  • 1ANsmz************************H2aU
  • 3BPtF8************************wnxa
  • 3GNrNc************************QW8b
  • 3N5wGK************************Lsv4
  • 3M8NGA************************mkJX
  • 342bk7************************18NT
  • 3Codt5************************Zfve
  • 3BpHnZ************************ybGL
  • 3LWZed************************i9Yu
  • 329NN8************************cXsh
  • 3Cm8s9************************uKDX
  • bc1qwl************************yzvl
  • 3HLoqZG************************uomS

Several of these wallets displayed observable transaction activity between 2017 and 2023, making this one of the most operationally active parts of the ecosystem uncovered during the investigation.

Early Wallet Activity and Transaction Volume

The older wallets generally showed larger transaction values and more consistent movement compared to the newer infrastructure observed elsewhere in the investigation. Examples included:

  • 1Nkm6***********************Hbze Received approximately 1.527 BTC between 2017 and 2018.
  • 3BPtF**************************Dwnxa Received approximately 1.501 BTC during 2019.
  • 3N5wG***************************Lsv4 Recorded approximately 0.838 BTC in activity during 2020.
  • 342bk*****************************18NT Showed approximately 0.459 BTC in observed transactions.

Several additional wallets also displayed smaller but recurring payment activity over time. Although blockchain analysis alone cannot determine whether the payments were directly tied to successful marketplace transactions, the repeated financial movement across multiple marketplace-linked wallets strongly suggested that at least parts of the infrastructure were operational rather than purely decorative or inactive storefronts.

Repeated Wallet Rotation Behavior

One of the clearest patterns observed throughout the wallet analysis was the short operational lifespan of many addresses. Rather than relying on a single long-term treasury wallet, the infrastructure repeatedly cycled through multiple payment addresses over time.

Across several wallets, the same sequence appeared repeatedly:

  • Wallet receives incoming BTC transactions
  • Funds remain temporarily within the wallet
  • Wallet balance is later drained or reduced to near-zero
  • Activity declines or stops entirely

This behavior appeared across multiple years of activity and was especially visible within the earlier Luckp infrastructure. In many cases, the wallets eventually showed:

  • zero remaining balance,
  • zero unspent outputs,
  • or no further transactional activity after earlier payment periods.

The repeated receive-and-drain pattern suggested that the infrastructure may have relied on compartmentalized payment handling rather than maintaining large long-term wallet balances. Whether this behavior reflected operational security practices, manual fund consolidation, or short-term receiving wallets could not be independently confirmed. However, the consistency of the pattern across multiple addresses indicated that the wallet activity was unlikely to be random.

Gradual Decline in Financial Activity

Another noticeable trend emerged when comparing older wallet activity with newer Luckp-related infrastructure uncovered later in the investigation. Earlier wallets generally handled larger BTC volumes and showed clearer transactional patterns, while later deployments increasingly relied on inactive or near-empty wallet clusters.

Some of the newer wallets associated with later domains received extremely small amounts of Bitcoin or showed no observable activity at all. This contrasted sharply with the older Luckp infrastructure, which demonstrated more sustained financial movement between 2017 and 2020.

The shift may suggest several possibilities:

  • operational decline,
  • fragmentation of the marketplace ecosystem,
  • migration toward alternative payment methods,
  • increased use of privacy-focused cryptocurrencies,
  • or repeated redeployment of partially inactive mirror infrastructure.

Although the exact reason could not be conclusively determined, the financial behavior observed across the investigation indicated that the Luckp ecosystem evolved significantly over time rather than remaining operationally static.

Infrastructure Persistence and Identity Continuity

As the financial analysis expanded across older and newer Luckp-related domains, another pattern began emerging beneath the rotating wallets and changing storefronts: despite repeated infrastructure shifts, several core identifiers remained surprisingly consistent over time.

One of the clearest examples involved the marketplace’s contact infrastructure. The earliest domains identified during the investigation used the email address:

  • luc****7@b****ail.net

However, as additional onion services were uncovered, the investigation revealed that the operators or at minimum the infrastructure behind the marketplaces, continued reusing the “luckp47” identifier across multiple encrypted email providers.

Additional addresses identified through StealthMole included:

  • lu***7@dnmx.su
  • LU***7@DNMX.SU
  • lu****7@sa******l.net
  • lu****7@sa******l.com

The repeated reuse of the same naming convention across separate providers strongly suggested long-term continuity in branding and operational identity. While the surrounding infrastructure evolved over time, the “luckp47” label itself remained persistent across multiple marketplace generations.

The transition between providers was also notable in its own right. Earlier infrastructure relied on Bitemail, while later deployments shifted toward DNMX and Safe-mail services — platforms frequently observed within underground and privacy-focused communities. The migration appeared gradual rather than abrupt, suggesting infrastructure evolution over time instead of a single isolated redeployment.

The onion infrastructure itself reflected a similar pattern of continuity. Older Luckp-related domains used legacy Tor v2 onion addresses, while newer deployments transitioned toward longer v3 onion services introduced after Tor deprecated v2 support. This migration indicated that portions of the infrastructure were actively maintained and adapted across multiple years rather than abandoned after initial deployment.

Additional linked domains continued surfacing throughout the investigation, including:

  • luckp42mxih5kz4hswcfmzllgrm5a6vn463pmssk5fxpuo2dz7xszjqd.onion
  • luckp43xq757gh5w2udd4rl6fqwtie3hab57uwk5bywga4t5x5yxqjqd.onion
  • luckp4bbg3jjytiao7ibd556dvs2fkpfbzcl74my6ku3omweoscmm6ad.onion

Some of these domains were inactive at the time of analysis, while others appeared partially operational or redirected toward related marketplace infrastructure. Despite differences in branding and accessibility, many retained overlapping marketplace structures, recurring imagery, and similar payment workflows.

The investigation also identified traces of the Luckp identifiers outside the onion ecosystem itself. The addresses luc***7@sa****l.net and lu**7@sa***l.com were both observed within leaked files indexed through StealthMole. While the leaked references alone did not independently establish ownership or attribution, they demonstrated that the Luckp identity extended beyond isolated Tor infrastructure and appeared across additional underground data sources.

Telegram Mentions and External Visibility

The investigation later expanded beyond the Tor ecosystem itself after StealthMole’s Telegram Tracker identified references to Luckp-related infrastructure circulating through Telegram-based underground communities.

One of the identified mentions referenced the domain within a Telegram message posted in the channel titled Mundo Dos Hackers.

  • luckp47s6xhz26rn.onion

The message appeared to function as a directory-style post containing multiple onion links tied to underground marketplaces and services. Within the listing, the Luckp infrastructure was referenced under the name:

  • Lucky 47 Shop

The Telegram reference was particularly notable because it demonstrated that the marketplace was not relying exclusively on Tor-based discovery. Instead, links to the infrastructure were also circulating through external messaging ecosystems commonly used to distribute dark web resources, marketplace directories, and underground service references.

The naming convention used within the Telegram message also reflected an interesting shift in how the marketplace was being referenced externally. While archived infrastructure later revealed the meaning behind the “Luckp” acronym, the Telegram ecosystem appeared to use the simplified “Lucky 47 Shop” branding instead. Whether this reflected deliberate simplification, informal renaming by third-party users, or broader recognition of the marketplace under a more accessible label could not be conclusively determined.

Conclusion

What began as the discovery of a single inactive onion marketplace gradually expanded into a broader investigation involving linked onion services, recurring cryptocurrency infrastructure, evolving marketplace branding, and years of observable operational activity.

Through StealthMole pivots across wallets, domains, Telegram references, and contact infrastructure, the investigation revealed that the Luckp ecosystem extended well beyond one storefront. Older domains showed sustained Bitcoin activity and clearer operational behavior, while newer deployments increasingly relied on rotating mirror infrastructure, inactive wallet clusters, and alternative cryptocurrency support such as Monero.

The investigation also revealed how the marketplace evolved its identity over time. What initially appeared as “Lucky 47 Shop” later exposed deeper conflict-oriented branding tied to “Luhansk Counter Kiev Partisans,” demonstrating how underground marketplaces can combine weapons trafficking narratives, wartime symbolism, and anonymous infrastructure to build long-term visibility within dark web ecosystems.

Editorial Note

Investigations involving dark web infrastructure rarely produce absolute answers. Marketplaces frequently rotate domains, reuse identifiers, abandon infrastructure, and blur the line between operational activity, propaganda, and reputation-building. StealthMole helped connect fragmented indicators spread across onion services, cryptocurrency wallets, Telegram references, and leaked data, allowing a broader infrastructure picture to emerge from what initially appeared to be an isolated marketplace listing.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report