Operation Bayonet (darknet) explained
Operation Bayonet |
Type: | Drug Enforcement |
Target: | Dark Markets: Alpha Bay Onion Service and Hansa Onion Service |
Executed By: | Canada, Germany, Lithuania, Netherlands, Thailand, United States |
Countries Number: | 7+ |
Date Begin: | 2016? |
Date End: | 2017? |
Operation Bayonet was a multinational law enforcement operation culminating in 2017 targeting the AlphaBay and Hansa darknet markets.[1] [2] [3] Many other darknet markets were also shut down.[4]
Methodology
Investigators from several law enforcement agencies including the FBI, DEA, and Europol located Canadian Alexandre Cazes, the alleged founder of AlphaBay, due to a series of operational security errors:
- About the time the service first began in December 2014, Cazes used his Hotmail address pimp_alex_91@hotmail.com as the 'From' address in system generated welcome and password reset emails, which he also used for his LinkedIn profile and his legitimate computer repair business in Canada.[5]
- Cazes used a pseudonym, Alpha02, to run the site which he had previously used (e.g., in carding and tech forums) since at least 2008, and variously advertised this identity as the "designer", "administrator" and "owner" of the site.[6]
- When Cazes was arrested, he was logged into his laptop performing an administrative reboot on an AlphaBay server in direct response to a law-enforcement-created artificial system failure; furthermore, encryption was wholly absent on that laptop.[7]
- Cazes' laptop reportedly contained an unencrypted personal net worth statement mapping all global assets across multiple jurisdictions, conveniently leading police to complete asset seizure.
- The servers were hosted at a company in Canada directly linked to his person.
- The servers contained multiple constantly open (unencrypted) hot cryptocurrency wallets.
- Cazes' flashy use of proceeds to purchase property, passports and luxury cars and frequent online boasting about his financial successes, including posting videos of himself driving luxury cars acquired through illegal proceeds, not only revealed his geographical location, but also made denying connection to the service impossible.
- Assets acquired through proceeds were held in a variety of accounts directly linked to Cazes, his wife and companies they owned in Thailand (the jurisdiction in which they lived), as well as directly held personal accounts in Liechtenstein, Cyprus, Switzerland and Antigua.
- Cazes' statements about the goal of the site - "launched in September 2014 and its goal is to become the largest eBay-style underworld marketplace" - helped to legally establish intent.
AlphaBay target
Law enforcement took at least one month to obtain a US warrant, then over one month to obtain foreign warrants, prepare for and execute searches and seizures in Canada and Thailand:
- Early May 2017: Law Enforcement verifiably active on the site since at least this period.
- 1 June 2017: Warrant issued by United States District Court for the Eastern District of California for racketeering, narcotics trafficking, identity theft and access device fraud, transfer of false ID, trafficking in illegal device making equipment, and conspiracy to commit money laundering.
- 30 June 2017: Warrant is issued for Cazes' arrest in Thailand at US request.[8] [9]
- 5 July 2017:
- Canadian police raid EBX Technologies in Montreal, Cazes' Canadian company and the reported location of the physical servers, as well as two residential properties in Trois-Rivières.[10]
- Cazes is arrested in Bangkok at his dwelling at Phutthamonthon Sai 3 Road in Thawi Watthana district which is searched by the Royal Thai Police, with the help of the FBI and DEA.
- 12 July 2017: Cazes' suspected suicide by hanging while in custody at Thailand's Narcotics Suppression Bureau headquarters in Laksi district, Bangkok, was reportedly discovered at 7AM. He was due to face US extradition.
- 16 July 2017: Cazes' wife was reported as having been charged with money laundering.[11] [12]
- 20 July 2017; U.S. Attorney General Jeff Sessions announces shutdown of the site.[13]
- 23 July 2017: Narcotics Suppression Bureau chief is interviewed and suggests that more suspects will be arrested soon.[14]
Hansa target
Hansa Investigation
Dutch police discovered the true location of the Hansa onion service after a 2016 tip from security researchers who had discovered a development version.[15] The police quickly began monitoring all actions on the site, and discovered that the administrators had left behind old IRC chat logs including their full names and even a home address, and they began to monitor them. Although the administrators soon moved the site to another unknown host, they got another break in April 2017 by tracing bitcoin transactions, which allowed them to identify the new hosting company, in Lithuania.
Hansa Seizure
On June 20, 2017, German police arrested the administrators (two German men) and the Dutch police were able to take complete control of the Hansa site and to impersonate the administrators. Their plan, in coordination with the FBI, was to absorb users coming over from the upcoming AlphaBay website shutdown. The following changes were made to the Hansa website to learn about careless users:
- All user passwords were recorded in plaintext (allowing police to log into other markets if users had re-used passwords).[15]
- Vendors and buyers would communicate via PGP-encrypted messages. However, the website provided a PGP encryption convenience feature which the police modified to record a plaintext copy.[15]
- The website's automatic photo metadata removal tool was modified to record metadata (such as geolocation) before being stripped off by the website.[15]
- Police wiped the photo database, which enticed vendors to re-upload photos (now capturing metadata).[15]
- Multisignature bitcoin transactions were sabotaged, which at shutdown would allow police to confiscate a larger amount of illicit funds.[15]
- Police enticed users to download a Microsoft Excel file (disguised as a text file) that, when opened, would attempt to ping back to a police webserver and unmask the user's IP address.[15] [16] [17]
Service Shutdowns
Per the plan, AlphaBay was shut down on July 4, 2017, and as expected a flood of users substituted to the Hansa marketplace, until its subsequent shutdown on July 19/20 2017. During this time, law enforcement allowed the Hansa userbase (then growing rapidly from 1000 to 8000 vendors per day[18]) to make 27000 illegal transactions in order to collect evidence for future prosecution of users.[15] [19] Dutch local cybercrime prosecutor Martijn Egberts claimed to have obtained around 10,000 addresses of Hansa buyers outside of the Netherlands.[20]
After the shut down of Hansa, the site displayed a seizure notice and directed users to the Operation's onion service[21] to find more information about the operation.
Participating law enforcement agencies
Most of the involved countries are part of the Virtual Global Taskforce (VGT), however additional law enforcement agencies played a role.
- The server where Alphabay was located was traced back to Lithuania, leading to the Lithuanian law enforcement's involvement in the operation.
- The founder of the site, Alexandre Cazes, was arrested in Thailand, which resulted in the Thai police involvement.
List
See also
Notes and References
- Web site: Illegal-Goods Website AlphaBay Shut Following Law-Enforcement Action. McMillan. Robert. Viswanatha. Aruna. 13 July 2017. Wall Street Journal. 11 March 2018. 24 September 2020. https://web.archive.org/web/20200924020456/https://www.wsj.com/articles/illegal-goods-website-alphabay-shut-following-law-enforcement-action-1499968444/. live.
- Web site: Dark Web drug marketplace AlphaBay was shut down by law enforcement. Statt. Nick. 14 July 2017. The Verge. 11 March 2018. 15 July 2017. https://web.archive.org/web/20170715042453/https://www.theverge.com/2017/7/14/15975140/alphabay-dark-web-drug-marketplace-police-shutdown-silk-road. live.
- Global Police Spring a Trap on Thousands of Dark Web Users. Greenberg. Andy. 20 July 2017. WIRED. 3 March 2018. 24 September 2020. https://web.archive.org/web/20200924020503/https://www.wired.com/story/alphabay-hansa-takedown-dark-web-trap//. live.
- News: Massive blow to criminal Dark Web activities after globally coordinated operation. 20 July 2017. 20 July 2017. 24 September 2020. https://web.archive.org/web/20200924020505/https://www.europol.europa.eu/newsroom/news/massive-blow-to-criminal-dark-web-activities-after-globally-coordinated-operation/. live.
- Web site: 20 July 2017 . Forfeiture Complaint . Justice.gov . 27 . 23 July 2017 . 23 September 2020 . https://web.archive.org/web/20200923012828/https://www.justice.gov/opa/press-release/file/982821/download . live .
- Web site: Cox . Joseph . Alleged Dark Web Kingpin Doxed Himself With His Personal Hotmail Address . . . https://web.archive.org/web/20201109025104/https://www.vice.com/en/article/zmv535/alleged-dark-web-kingpin-doxed-himself-with-his-personal-hotmail-address . November 9, 2020 . July 20, 2017 . live.
- Web site: McCarthy . Kieren . Alphabay shutdown: Bad boys, bad boys, what you gonna do? Not use your Hotmail... . . Situation Publishing . https://web.archive.org/web/20170720214112/https://www.theregister.co.uk/2017/07/20/alphabay_hotmail_fbi/ . July 20, 2017 . July 20, 2017 . live.
- News: Dead Canadian fugitive lived in Thai luxury . . July 14, 2017 . live . October 15, 2021 . July 14, 2023 . https://web.archive.org/web/20230714191946/https://www.bangkokpost.com/thailand/general/1285923/dead-canadian-fugitive-lived-in-thai-luxury .
- News: Ngamkham . Wassayos . Canadian drug suspect found hanged in cell . . July 12, 2017 . live . October 15, 2021 . July 14, 2023 . https://web.archive.org/web/20230714191913/https://www.bangkokpost.com/thailand/general/1285758/canadian-drug-suspect-found-hanged-in-cell .
- Web site: RCMP's 'Dark Web' investigation leads to searches in Montreal, Trois-Rivières . . . https://web.archive.org/web/20170705202538/https://montrealgazette.com/news/local-news/rcmps-dark-web-investigation-leads-to-searches-in-montreal-trois-rivieres . July 5, 2017 . July 5, 2017 . live.
- News: Swenson . Kyle . Suspected AlphaBay founder dies in Bangkok jail after shutdown of online black market . . https://web.archive.org/web/20170720163236/https://www.washingtonpost.com/web/20170720163236/https://www.washingtonpost.com/news/morning-mix/wp/2017/07/18/suspected-alphabay-founder-dies-in-bangkok-jail-while-online-black-market-remains-closed/?utm_term=.8e027c89a50a . July 20, 2017 . July 18, 2017 . live.
- Web site: Thailand seizes $21 million in assets from dead founder of dark net marketplace AlphaBay . . . https://web.archive.org/web/20180609131648/https://www.reuters.com/article/us-thailand-drugs/thailand-seizes-21-million-in-assets-from-dead-founder-of-dark-net-marketplace-alphabay-idUSKBN1A90ZE . June 9, 2018 . July 24, 2017 . live.
- News: Sessions on dark web Alphabay and Hansa shut down . . . July 20, 2017 . https://web.archive.org/web/20170723064752/https://www.bbc.com/news/av/world-us-canada-40674838/sessions-on-dark-web-alphabay-and-hansa-shut-down . July 23, 2017.
- News: July 24, 2017. 9 nations join probe into 'darknet' site. Bangkok Post. NSB poised to pounce on more suspects. live. July 24, 2017. July 14, 2023. https://web.archive.org/web/20230714191913/https://www.bangkokpost.com/thailand/general/1292635/9-nations-join-probe-into-darknet-site.
- 2018-03-08 . Operation Bayonet: Inside the Sting That Hijacked an Entire Dark Web Drug Market . Wired . 2024-03-12 . 2024-03-12 . https://web.archive.org/web/20240312213539/https://www.wired.com/story/hansa-dutch-police-sting-operation/ . live .
- Web site: Cox . Joseph . August 25, 2017 . This Is How Cops Trick Dark-Web Criminals Into Unmasking Themselves . . March 12, 2024 . March 12, 2024 . https://web.archive.org/web/20240312213539/https://www.thedailybeast.com/this-is-how-cops-trick-dark-web-drug-dealers-into-unmasking-themselves . live .
- News: pxx51092 . July 25, 2017 . DON'T open the xlsx locktime file, beacon image confirmed in it with Hansa's server IP address . . https://web.archive.org/web/20171009150823/https://www.reddit.com/r/DankNation/comments/6pi0et/dont_open_the_xlsx_locktime_file_beacon_image/ . October 9, 2017.
- Web site: 20 July 2017 . Underground Hansa Market taken over and shut down . Politie (Dutch Police) . 21 July 2017 . 21 July 2017 . https://web.archive.org/web/20170721082011/https://www.politie.nl/en/news/2017/july/20/underground-hansa-market-taken-over-and-shut-down.html . dead .
- Web site: Riggs . Mike . 2017-07-26 . Five Lessons from the Hansa and AlphaBay Busts . 2017-07-26 . Reason Hit&Run . 2017-07-29 . https://web.archive.org/web/20170729073202/http://reason.com/blog/2017/07/26/five-lessons-from-the-hansa-and-alphabay . live .
- Web site: Satter . Raphael . Bajak . Frank . 2017-07-21 . Dutch 'darknet' drug marketplace shut down . 2017-07-22 . Portland Press Herald . 2017-07-22 . https://web.archive.org/web/20170722015522/http://www.pressherald.com/2017/07/21/dutch-darknet-drug-marketplace-shut-down/ . live .
- News: DeepDotWeb . 31 October 2016 . Dutch National Prosecution Service and police launch Hidden Service in global Darknet enforcement operation . dead . 26 July 2017 . https://web.archive.org/web/20161101124749/https://www.deepdotweb.com/2016/10/31/dutch-national-prosecution-service-police-launch-hidden-service-global-darknet-enforcement-operation/ . 1 November 2016.