2 more juicy vendor busts and what they did wrong

Over the holidays I found time to go through more than 100 pages of criminal complaints, indictments and other resources that described how the vendors Blime-Sub (a.k.a. BTH-Overdose) and CaliGirl got busted. Now what is different compared to the first two parts [#1 and #2] is that these two cases are described in great detail and walk the reader through the entire investigation step-by-step.

Since they are quite lengthy I outlined the important parts of the investigation and wrote down the mistakes that the vendors did which eventually led to their bust. While the Blime-Sub bust is quite fresh [just 2 months ago], the CaliGirl case dates back to the good old SR days. However it is one of the best documented ones and many of the investigation techniques are still used today. In this edition we have some classic pitfalls like getting identified while buying the postage or leaving a detailed money trail but also some new ones, that have not been mentioned in the previous two parts.

I strongly encourage every vendor to read through these notes and analyse their own operation so they do not make the same mistakes that their colleagues/competition did. In the end it is not only your own future that is at risk but also the one of your customers. Please read the whole post because it not only includes stupid vendor mistakes that you probably would never make, but also some tricky pitfalls which you would miss out if you just skim the post.

Before I come to the busts themselves I want to briefly talk about some aspects that are so important that I think they deserve a specific mention:


Bust #1: CaliGirl [Matthew Jones]

sources:

https://www.justice.gov/sites/default/files/usao-mdfl/legacy/2014/05/30/20140530_Jones_Complaint.pdf

https://www.reddit.com/r/DarkNetMarkets/comments/2c2i3f/caligirl_criminal_complaint_excerpts/

notes:


Bust #2: Blime-Sub a.k.a. BTH-Overdose

sources:

https://www.justice.gov/usao-edca/pr/fentanyl-and-heroin-sold-dark-web-marketplace

https://www.justice.gov/usao-edca/press-release/file/918811/download

discussion link:

https://www.reddit.com/r/DarkNetMarkets/comments/5imn2j/blimesub_arrested_according_to_press_release/

I also wrote an article on deepdotweb about this bust using these notes, so if you read it you can skip the following notes. /u/deepdot can you please post a short 'confirmed' comment so that people know that I am not bullshitting?

notes:


That is it for now, if you know other busts that could provide useful information or additions to the summarized ones please leave a comment here.

One last shameless self-promotion: I developed an Addon for Firefox [also compatible with the Tor browser] which lets you view selfposts of NSFW subs [like this one] without having to enable JavaScript. The source code is of course publicly available, so check it out if you want to boost your opsec: https://www.reddit.com/r/DarkNetMarkets/comments/5ek0lm/a_present_for_the_lurkers_on_here/


Comments


[209 Points] cidilicious:

Wow. I don't know who I am more impressed with, the agents that made the busts or your time investigating and summarizing it all. Leaning towards you actually.


[78 Points] bmoreproduct1:

Your synopsis of Caligirl should be one bullet: he allowed a customer to deposit directly into his personal bank account.


[41 Points] ahismyidol:

Can you do something like for buyers?


[31 Points] AlpraKing:

Both of these are idiots.


[31 Points] deepdot:

can you please post a short 'confirmed'

Confirmed :)


[21 Points] None:

or his next undercover order [undercover purchase #8] the TF agent claimed to be short on bitcoins and CaliGirl provided him with a contact [name, telephone number and local bitcoins username] that could sell him bitcoins for cash -> that contact [Jones] was CaliGirl himself

Ouch. He was making a ton of drug money and had to make some money selling BTC on the side too.


[20 Points] SketchyyG:

This was mad interesting and a good read


[18 Points] Immaloner:

the agent got a response from the lab on November 10, 2016, which stated that it was a mix of heroin and fentanyl

Fuck this guy for selling dope laced with fent. Too bad they can't tie any deaths to him.

the US postal inspector was able to conduct comparative analysis of these parcels to identify who purchased the postage for UC parcel #1. Due to the Postage Validation Imprinter (PVI) the US postal inspector was able to see that the postage was bought on September 18 2016 at 4:03 PM via a Self-Service Kiosk (SSK) 0.7 miles away from Babadjov's known address

So I've seen this on some other recent busts including the big meth bust in Arkansas and the kid you gave up $1.7 million in proceeds. The postage kiosks take the photo os every customer. They used that to definitively tie them to the packages being mailed...well, that and the fingerprints.


[12 Points] roare:

Lolololol, Mateo Jones


[11 Points] Florida51:

We need to drop some btc for this guy doing this... for real


[10 Points] blackhand25:

Jesus Christ. Sometimes I start reading these summaries and find myself getting a sick feeling in my gut that I haven't been careful enough and then I see Caligirl giving his bank account information to a "customer" and I am relieved to realize that there is fruit this low hanging out there


[8 Points] None:

[deleted]


[7 Points] murderhomelesspeople:

YUMMY YUM YUM u/wombat2combat vendor bust posts :D please get in my mouth these are always so fucking delicious


[7 Points] None:

[deleted]


[8 Points] None:

A+ work. Wish I could upvote more than once


[2 Points] XxExpansionxX:

So informative. I hope that vendors learn from busts like this. It would be interesting to hear about some buyer busts as well.


[2 Points] thascarecro:

Damn BTH was big time. I googled him and found he was a really credible investor. Guy was obviously already making big money but the easy money was too hard for him to turn down. FTP.

Always find it cool to see what these guys talk and sound like. At first i didnt think it could be this Emil, but it looks like it is the same guy.


[2 Points] Trinklefat:

Question: Using handwriting is supposedly bad. Fair enough, makes sense.

But can the printer you use to make labels and shit be traced with the little yellow dots, etc?


[2 Points] BGFlyingToaster:

Fantastic work. Thanks!


[2 Points] Nurah:

Does this kind of thing happen to rc vendors? Since rcs are kinda legal.

I'd hate to purchase something someday, only to go to prison for years.


[2 Points] mattelwensh:

I love how coinbase just gives out all information. This is why you should use Electrum.

Stupid ass coinbase.


[2 Points] MollieIsYourFriend:

I like how you use the word "Scope". I always think of mouth wash when I hear this word but I found your expanded use of it rather refreshing as well.


[1 Points] ishq:

Thanks for the post


[1 Points] crystalizedpoundz47:

seriously thanks for putting this together, very useful and informative!


[1 Points] hhayn:

Very helpful post. Everyone should read this, even if it is just a reminder of what is. +1 for the write up best of 2017 shit


[1 Points] _Thunder_Child_:

This is more entertaining than the police procedurals on TV!


[1 Points] Selectivescammer1:

I remember a big vendor back in Agora's day was a group of people i believe called Budwerkz, or something like that, budworkz... They got busted, were based in Ireland i think, were the Ganeshuk of their day selling loads of different drugs


[1 Points] Udaypbuh:

I firmly believe you need to have someone on the inside feeding you information or you won't last in the drug game. Whether it's selling in real life or on the DNM.


[1 Points] Derrick4Real:

Excellent contribution. We all appreciate your efforts!


[1 Points] regulardoobage:

fucking coinbase..


[1 Points] TheBitterBuffalo:

Jesus this makes being a vendor sound impossible to do. How the fuck are you supposed to send the product if you can't use random/business/fake addresses.


[1 Points] throwahooawayyfoe:

Blime-sub

Blime

emilB

Emil B.

DON'T. USE. YOUR. FUCKING. NAME. IN. YOUR. FUCKING. HANDLE.


[1 Points] python134r:

Great Thread, years ago in ancient times 70-80'S if one was working with contraband, similar rules applied, difference was electronic paper trails, smarter law enforcement(hmm, oxymoron) and keeping your mouth shut and not associating with those who do. The world is so much smaller now, one cant earn without losing some anonymity for 20 years now.

Opsec, tradecraft must always be followed all the time, the one time you do not, could be 20 years in a FCI, I was lucky only 8 for me.


[1 Points] LibertyDNM:

So vendors remember to take a break once in a while and enjoy the reward of your hard work instead of ruining everything you have worked for in the past years by vending until you get busted

I can't help but to think about HumboldtFarms. Seriously, that fucker has been around since at least March 2015, and he has close to 60,000 transactions on AB alone! I always had good experiences with him, but I stopped using him because he's grown too big. The beast is bound to fall sometime.


[1 Points] Kofeb:

You should look up Aaron Shamo out of Utah who was arrested a few months ago. Should be an interesting case as well.


[-1 Points] AutoModerator:

/u/deepdot - You have been summoned in the thread /r/DarkNetMarkets/comments/5lo7ir/2_more_juicy_vendor_busts_and_what_they_did_wrong/ by /u/wombat2combat.

This convenience is brought to you by AutoMod. Submissions do not automatically summon users like comments do. AutoMod is trying to be helpful.

For others, it should no longer be necessary to summon the referenced user in a comment any more. AutoMod has done the heavy lifting for you. You're welcome. Bow before me.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.


[-1 Points] Razbonez:

Monero as unit of money is only way to handle drug transactions anonymously. Please everyone look into this cryptocurrency!