← All talks

Tracking Russian Cyber Criminals Through Drug Buys #shorts

BSides Frankfurt1:45482 viewsPublished 2025-12Watch on YouTube ↗
About this talk
Solaris, a Russian dark web drug market, let us track cybercriminals' locations. They buy drugs near home, reusing nicknames, linking their online identities to real-world locations. #bsidesfrankfurt #bsides #bsidesfra #alexholden #Cybercrime #DarkWeb
Show transcript [en]

Solaris is illegal drug market within Russia. It actually was established by a guy named Zanzi um in 2017 and Zanzi is um infamous for creating number of different um illegal drug marketplaces in Russia. Um it uh at its height uh it operated over a thousand shops uh on the dark web in different cities of uh Russia selling illegal drugs electronically to um the drug users uh of uh Russia. And this is a whole big microeconomy that Solaris had. But it was a separate marketplace, separate um um forums, se separate um uh shops and full supply chain for the drug dealers. So we decided to take out um Solaris and the reason why we have visibility into

Solaris is that because uh we have as a cyber threat intelligence uh company, we have great interest in illegal uh drug trade in Russia. Not because we actually um care about that part because uh it's a job of Russian government to stop their illegal drug trade. But it's actually a very interesting thing that um the drug dealer drug users in Russia some of them very infamous uh cyber criminals tend to buy their drugs next to their home. So they live nearby where they buy their drugs. And because uh the cyber criminals on dark web tend to reuse their nicknames and identity, we can actually trace them down to their physical location within Russia where they're buying their drugs. So we

actually tracking where they are based on their geio locations and where they are buying their illegal drugs.