HomeWorldwideMiddle EastThe Many Faces of ModernStealer: How One Session ID Exposed a Possible...

The Many Faces of ModernStealer: How One Session ID Exposed a Possible Underground Military Data Network

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

The investigation, conducted using StealthMole’s intelligence platforms, began with a single post advertising an alleged confidential document concerning Türkiye-Pakistan defence cooperation and drone technology. It then followed a seemingly mundane digital artifact – a Session messaging ID – across multiple underground identities.

That trail eventually connected ModernStealer to other aliases, including Zu1f1q4r and PriorOps, as well as a Telegram identity known as Sassoon Don.

The findings do not prove that one person controls every account, nor do they independently verify the sensitive datasets advertised by the actors. But they do demonstrate something increasingly important for defenders and intelligence teams: underground identities can be far less useful for attribution than the persistent infrastructure and contact points behind them.

A defence deal becomes the starting point

The investigation began with a post on DarkForums attributed to ModernStealer and titled “[PK] TUR-PAK DEFENSE DRONE DEAL.”

The listing allegedly offered a 23-page confidential document relating to Türkiye-Pakistan defence cooperation, including references to Baykar Teknoloji and Pakistan’s National Aerospace Science and Technology Park (NASTP).

According to the seller’s description, the document covered subjects including unmanned systems, technology transfer, joint research and development, industrial cooperation, training, localisation and potential drone procurement.

The nature of the alleged document immediately raised the stakes. Defence-related information – particularly material involving military procurement and unmanned aerial systems – can have implications well beyond a typical data breach.

But there was an important caveat.

The listing alone did not establish that ModernStealer had breached a defence organisation or that the document was authentic. Underground markets frequently contain exaggerated, recycled, fabricated or misleading claims designed to attract buyers.

What made the post valuable from an intelligence perspective was not necessarily the material being advertised.

It was the contact information attached to it.

ModernStealer had provided a Session ID that could be followed across StealthMole’s indexed datasets.

That identifier became the thread connecting the investigation.

The pattern grows beyond one seller

A search for the ModernStealer name reportedly identified multiple listings between March and April 2026.

The alleged targets included organisations such as Pakistan’s Nuclear Regulatory Authority, Pakistan’s National University of Sciences and Technology and information purportedly linked to Lockheed Martin employees. Another listing referenced the Sri Lanka Air Force.

A separate search of government-related monitoring data produced additional listings associated with ModernStealer, including alleged material connected to the Bangladesh military, Pakistan’s SUPARCO and Ministry of Science and Technology, and references to organisations including the People’s Liberation Army, the CIA, the U.S. Department of Defense and DARPA.

The claims were wide-ranging.

So were the alleged targets.

Yet the same warning applies: the appearance of an organisation’s name in an underground listing is not proof that the organisation was breached.

For security teams, however, such listings still matter.

Threat actors can use alleged data to extort organisations, attract buyers, build credibility in underground communities or manipulate public perception. Even when a claim is false, it can trigger reputational damage, incident-response costs and unnecessary operational disruption.

The question, therefore, became less about whether every individual claim was genuine and more about whether the actor behind the listings was part of a larger underground operation.

The answer began to emerge from the contact infrastructure.

The Session ID that kept coming back

One listing allegedly involving the Pakistan Nuclear Regulatory Authority claimed that ModernStealer had compromised a mail server and obtained more than 60 databases, with 17 databases – totalling approximately 3.2 GB – offered for sale.

The listing claimed the data included information concerning nuclear reactor and chemical laboratory locations, employees, email addresses, sensitive documents and infrastructure.

Again, none of those claims could be independently confirmed from the listing alone.

But the same Session ID used in the earlier Türkiye-Pakistan drone deal appeared again.

That changed the investigation.

The identifier was no longer associated with just one post. It had become a persistent artifact that could potentially connect activity across multiple platforms.

A search of the identifier reportedly returned at least 30 indexed threads.

Among them was a Breached forum post attributed to Zu1f1q4r, advertising alleged information related to Pakistan’s military procurement and defence deals involving China and Türkiye.

The account used the same Session ID.

The connection was significant but not conclusive.

There are several possible explanations. The two identities could belong to the same operator. They could represent different members of a group. Or they could be separate actors sharing communication infrastructure.

That distinction is critical.

In cyber threat intelligence, association is not attribution.

Three aliases, one recurring communication trail

Further examination of Zu1f1q4r’s activity revealed additional posts involving alleged documents related to Pakistan’s Intelligence Bureau and Federal Investigation Agency.

The same Session ID and a Tox ID appeared repeatedly.

This strengthened the connection between Zu1f1q4r’s various activities but still did not, on its own, prove that Zu1f1q4r and ModernStealer were the same individual.

The investigation then moved beyond underground forums.

A search of the Session ID in Telegram data reportedly identified a message from an account known as Sassoon Don. The user was seeking classified documents related to Ukraine and five Central Asian countries, apparently on behalf of a potential Chinese buyer, and provided the same Session contact.

At this point, the investigation had identified three distinct identities:

  • ModernStealer
  • Zu1f1q4r
  • Sassoon Don

All were connected through the same persistent Session identifier.

The significance was not that three usernames had appeared in the same dataset.

It was that the same contact infrastructure kept resurfacing as the identities changed.

For threat intelligence analysts, that is often a more valuable lead than a username.

The strongest link: ModernStealer and Sassoon Don

The investigation later uncovered a more direct connection.

In a ModernStealer post advertising alleged classified Pakistani military documents, the actor reportedly listed both the Session ID and a Telegram username associated with Sassoon Don.

The same pairing allegedly appeared in another ModernStealer post advertising military material from several countries and regions.

This created a stronger operational association.

Unlike the earlier ModernStealer-Zu1f1q4r connection, which relied primarily on the shared Session ID, the ModernStealer-Sassoon Don relationship was reinforced by the direct use of the Telegram account as a contact channel in ModernStealer’s own posts.

That still does not prove that one person controlled both identities.

Underground operators often work in teams. Shared accounts and communication infrastructure are common. A seller may also outsource customer communications or use a partner’s account.

But from an intelligence standpoint, the relationship had become difficult to dismiss.

The investigation had moved from a possible infrastructure overlap to a documented operational association.

Enter PriorOps

The Telegram username provided another avenue for investigation.

A search reportedly identified a Breached.live thread attributed to another actor, PriorOps, advertising an alleged database involving People’s Liberation Army personnel.

The post claimed to contain information such as ranks, positions, dates of birth, education, career histories, operational specialties and contact details.

The claims themselves remain unverified.

But the contact information again became the important clue.

PriorOps reportedly listed the same Telegram username associated with Sassoon Don.

That created another link in the chain:

ModernStealer → Sassoon Don → PriorOps

Combined with the earlier Session ID connection:

ModernStealer → Session ID → Zu1f1q4r

The resulting picture is not proof of a single threat actor.

It is something more nuanced and potentially more useful.

The evidence suggests an operationally connected cluster in which different identities appear to share communication infrastructure or contact points.

Whether that cluster represents one individual, a small team or a broader underground network remains unresolved.

A second “ModernStealer” raises more questions

The investigation also found a Telegram account using the ModernStealer name.

At first glance, that might appear to solve the attribution question.

It does not.

The account was associated with a unique Telegram User ID and had reportedly changed usernames multiple times. Historical records showed previous identities, including Myles and Haven, as well as the username @Mirage2022.

One historical message, posted in February 2026, reportedly asked:

“Who knows where I can get drone leaks and blueprints”

Given that the investigation began with ModernStealer advertising alleged drone-related defence material, the overlap was notable.

But notable is not the same as conclusive.

The investigation did not identify the same Session ID or the Sassoon Don Telegram account connecting this Telegram profile to the stronger ModernStealer cluster.

That leaves two possibilities.

The account could represent another identity connected to the operation.

Or it could simply be an unrelated user who adopted the ModernStealer name and happened to express interest in similar material.

Without a persistent identifier linking the account to the established cluster, merging the two would risk over-attribution.

And that is precisely where responsible cyber intelligence differs from speculation.

Why this matters beyond the dark web

The ModernStealer investigation offers a broader lesson for cybersecurity professionals.

Threat actors are increasingly fluid.

They change usernames. They move between forums. They use Telegram and encrypted messaging services. They create new identities when old ones become compromised or lose credibility.

For defenders, this creates a problem.

Traditional monitoring based on usernames, aliases or keywords can generate too much noise or miss important connections entirely.

A threat actor who appears as one person on a dark-web forum may use a completely different name on Telegram. The name may change again next month.

The infrastructure may not.

A messaging ID, cryptocurrency wallet, email address, PGP key, Telegram account, malware signature or reused handle can become the connective tissue that exposes relationships between apparently unrelated activities.

This is why modern cybersecurity and threat intelligence programmes need to move beyond simple keyword monitoring and incorporate broader identity and infrastructure correlation. Organisations looking to strengthen their security posture can work with specialist providers such as Saintynet Cybersecurity to build capabilities around threat intelligence, monitoring, incident response and risk management.

The lesson is particularly important for organisations operating in sensitive sectors.

Defence contractors, aerospace companies, government agencies, research institutions, financial organisations and critical infrastructure operators are attractive targets not only because of the information they hold, but because the information can have strategic value.

A single compromised account may offer an attacker an entry point into a much larger ecosystem.

The MEA angle: intelligence knows no borders

The investigation’s geographic footprint also highlights why this issue matters to security leaders across the Middle East and Africa.

The alleged listings referenced organisations and institutions across South Asia, Europe, North America and East Asia. The activity was not confined to one country or one regional underground market.

For governments and businesses in the Middle East and Africa, that matters.

The region is investing heavily in defence technology, smart infrastructure, artificial intelligence, aerospace, digital government and critical infrastructure. These sectors generate valuable intellectual property and sensitive information that can attract both financially motivated criminals and actors interested in strategic intelligence.

The growing use of cloud platforms, remote access and third-party suppliers also means that a threat actor may not need to compromise a government agency directly. A smaller contractor, technology provider or service company could potentially provide the initial access needed to reach a more valuable target.

That makes third-party risk and supply-chain security increasingly important.

It also reinforces the value of security awareness and specialised training. Organisations should ensure that employees, contractors and privileged users understand how attackers exploit credentials, social engineering and exposed information. Dedicated cybersecurity training and awareness programmes can be explored through Saintynet’s cybersecurity training and awareness resources.

For African organisations seeking greater international investment and stronger digital trust, cybersecurity is also becoming part of the investment equation. A company or government that can demonstrate mature security controls, strong incident response and effective data protection is better positioned to build confidence with international partners.

Ten actions security teams should take now

The ModernStealer investigation is ultimately a threat intelligence story, but its lessons are practical. Organisations should consider the following measures.

1. Monitor leaked credentials and data

Use reputable threat intelligence and dark-web monitoring services to identify exposed corporate credentials, domains and sensitive information.

2. Track infrastructure not only threat actor names

Threat actors frequently change aliases. Monitor persistent indicators such as email addresses, messaging accounts, cryptographic keys, wallet addresses and other infrastructure.

3. Protect privileged accounts

Enforce phishing-resistant MFA for administrators and other high-value accounts. Review privileged access regularly and remove unnecessary permissions.

4. Reduce exposed services

Continuously scan internet-facing systems for vulnerable applications, exposed management interfaces and misconfigured cloud resources.

5. Strengthen third-party security

Assess suppliers, contractors and technology partners that have access to sensitive systems or data. Require appropriate security controls and incident-notification procedures.

6. Protect sensitive defence and intellectual property

Classify sensitive information and limit access based on business need. Apply encryption and strong access controls to confidential documents and research.

7. Build an incident-response plan

Prepare clear procedures for investigating suspected data exposure, including escalation paths, legal considerations, communications and evidence preservation.

8. Correlate threat intelligence internally

Connect external intelligence with internal telemetry. A leaked credential or threat actor reference becomes far more useful when correlated with authentication logs, endpoint activity and network data.

9. Train employees and contractors

Security awareness should cover phishing, credential theft, social engineering and the risks of sharing sensitive information through unauthorised channels.

10. Treat underground claims as leads not facts

A threat actor’s claim should trigger investigation, not immediate conclusions. Validate alleged breaches through internal logs, forensic evidence and trusted intelligence sources before making attribution or public statements.

The bigger lesson: follow the artifact

The ModernStealer case is compelling not because it proves the existence of a single underground mastermind.

It does not.

Instead, it demonstrates how a seemingly minor digital artifact can reveal relationships that usernames alone would conceal.

One Session ID appeared in multiple places. A Telegram account surfaced as a contact point. Different aliases emerged around the same communication channels. What initially looked like separate actors began to resemble a connected operational cluster.

But the final answer remains deliberately unresolved.

ModernStealer, Zu1f1q4r, PriorOps and Sassoon Don may represent one operator using multiple identities. They may be members of the same group. They may be independent actors sharing infrastructure.

The available evidence does not conclusively establish which explanation is correct.

That uncertainty is not a weakness of the investigation.

It is the reality of attribution.

The most responsible threat intelligence work does not force a conclusion simply because the evidence appears to point in one direction. It distinguishes between what is known, what is strongly suggested and what remains unproven.

And in this case, what is known is already significant: the same persistent identifiers can expose relationships hidden behind constantly changing underground identities.

For defenders, that is the real takeaway.

The next threat actor may change their name tomorrow.

Their infrastructure might not.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img