
This approach appears to have made the flow of fullz from Kalashnikov to his club fairly stable.

You may never find a good source, or you may find a few."Īfter joining the club, a reseller will communicate with Kalashnikov via ICQ, a chat service that can be combined with an off-the-record encryption plugin. "Once you find a good supplier, in general terms you stick and work with them for a period of time. "Sourcing is sourcing," ThinkingForward said. If a reseller is lucky, this relationship will last for a while. Then the reseller, who will have a presence on one or more dark web markets, will sell the fullz off to individual customers at a profit. "So a source would prefer to split a 20k piece of data into 10 x 2k pieces of data." "If you get 10-20k worth of data, selling individually would take some time," ThinkingForward continued.

This is presumably an attempt to have their own listings appear when a customer searches for Kalashnikov's fullz.Ī simple sketch of the carding trade starts with a source, who, after gaining access to thousands or tens of thousands of identities, typically through spamming or hacking, will sell these off in chunks to a reseller. Notably, several other vendors have tagged their listings with "kalashnikov," even though they are not explicitly selling his product. "They are of high quality," alpha02, the administrator of AlphaBay, a recently launched dark web market, told me over encrypted messenger. When I sent an encrypted message to ThinkingFoward, a carder on dark web market AlphaBay who is advertising fullz of victims in the US, UK, Germany and other countries, and asked whether Kalashnikov's product was the best on the dark web at the moment, they said "You wouldn't know his name if they weren't :)" Kalashnikov's fullz also claim to come with the victim's Facebook profile, recently used IP address, and even what browser and operating system they use.Īt the time of writing, these are sold to customers by resellers for between $12 and $35 each on the dark web. Of course, all credit card details are included. On the digital side are their email addresses, passwords, and mother's maiden name to bypass the ubiquitous security question. Kalashnikov's product allegedly includes a victim's name, date of birth, home address, and billing telephone number.

Judging by interviews conducted over encrypted messaging with some of those sellers and other users in the carding community, as well as a survey of forums, Kalashnikov is one of the biggest fraudsters on the dark web right now. I first heard about this group from another carder who mentioned that Kalashnikov only sells to select individuals, who then advertise their product by blazoning the Kalashnikov brand in their listings, which are then purchased by customers with the semi-anonymous digital currency Bitcoin.
