[Breaches](/breaches)

Dead Drop: Inside a Russian Narcotics-as-a-Service Platform

[Blog](/blog)[Breaches](/breaches)[Resources](/resources)[News](/news)

# Dead Drop: Inside a Russian Narcotics-as-a-Service Platform

##### [Greg Pollock](/team/greg-pollock)

Published Sep 28, 2026

##### Join 27,000+ cybersecurity newsletter subscribers

## The Courier

The job is easy as long as you don't think about it. Pick up a package, drop it in the woods, take a picture. Like the ad said, you're just a courier. The package might hold 3 grams of mephedrone, the jobs come from a Telegram bot, and the payouts are in crypto before you cash out to Ukrainian hryvnia, but you try not to worry about that. At least the war has kept the police distracted.

You send the picture of the drop back through Telegram, where the bot forwards it through a labyrinth of channels until it lands on the phone of the buyer. Orchestrating that double-blind communication is a software platform for darknet drug sales as a service. That platform also exposed its logging database to the internet, where UpGuard Research found it on 14 July 2026.

Along with application logs documenting the operation of the bot system, the data contained unauthenticated URLs for around 500 photos taken by couriers. Each photograph represented the final thing actually sent by the platform to the buyer: an image with the location of a small package of drugs, findable by the latitude and longitude combined with a picture of it in situ. Between the logs and the photographs, this dataset documents both the digital and physical sides of darknet drug sales as it matures into a franchising business.

## The Operator

The job is easy as long as you don't think about it. On one monitor you have a dozen Telegram channels, on the other a console to jump in when the bots get stuck. Your job is a mix of customer support and IT, handling complaints, out of stock goods, and application errors. Now you don’t even sell narcotics — you sell a platform to the people who do. The prison sentence in Russia for selling drugs over an information-telecommunications network is five to twelve years, but you try not to worry about that. It’s only the couriers that get caught.

With that level of technological sophistication, it’s no wonder businesses like this dominate dark web transactions. Russian-language darknet markets take in [more than 90% of all the money moving through darknet markets globally](https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report) — $1.6 billion of the $1.7 billion those markets received in cryptocurrency in 2025. It is a small narcotics market by global standards — Americans spend [around $150 billion a year](https://www.rand.org/pubs/research_reports/RR3140.html) on cocaine, heroin, meth and cannabis, and the European retail market is [roughly €30 billion](https://www.euda.europa.eu/publications/technical-reports/estimating-size-main-illicit-retail-drug-markets-Europe_en) — but the Russian operating model is without parallel for its share of money moving through the dark web.

The Telegram distribution channel runs on orchestration instead of trust. As an orchestration problem, it naturally tends toward software automation. Personally managed Telegram channels become a network with support tools; the support tools become a product other people can rent. The leaked database is the back end of a product that builds and operates storefronts for paying tenants, turning every hand-off into a digital or physical dead-drop. It is a technique first developed as espionage tradecraft to escape counter-surveillance. The omnipresence of the Russian police state made it into a way of life.

## The Platform

Two days of logs contain 462 distinct Telegram bots spread across sixteen tenant accounts, of which about ten are live businesses. The platform advertises under the name AUO with pricing and feature lists that could belong to any other SaaS company: free trial, first invoice after ten days, 3% of crypto turnover, nine supported currencies, twelve interface languages. The list of accepted traffic types swerves into unfamiliar territory with "аптека, нарко" — pharmacy, narcotics — offered without euphemism. Its footer claims continuous operation since 2022. 

‍

The exposed dataset shows how the illicit activities of the narcotics trade can be translated into a structured event stream. The list of events reads like any e-commerce backend: orderPlaced, reserve\_stock, upload\_stock, SiteLogin, addingSalary. The largest customer of the AUO platform is a Polish shop trading as Macv24. They have twelve named staff and 310 bots in the two days of logs, with a recorded payroll of 13,047 złoty. The functional roles that different members of a drug gang might have are here expressed in the IT ops language of RBAC: couriers who upload photos and draw pay, middle-managers who are paid for work other than uploading photos, and the two super admins who never touch a package, one of who signs in through a Tor exit node.

For smaller sellers — the one person owner-operators — those tiers collapse. The Ukrainian, Turkish and Kyrgyz shops in the data have no couriers, because the owner is the courier: one person doing the drops, answering the support messages and logging into the admin panel from the same account. 

Both models have their benefits. By licensing access to AUO’s Telegram automation, individuals can go from a street dealer to the first employee of a nascent enterprise. Larger organizations get the benefit of labor specialization. The busiest courier in the data set uploaded 149 stashes in two days, for which the payroll records 2,680 Polish złoty. For each package that’s about eighteen złoty, or four and a half dollars, in the same ballpark as [what Russian courts reported for courier piecework](https://zona.media/number/2020/01/14/228-1) there. 

## Death of a Salesman

In this dataset we see couriers lit by the flash of system events, visible when they receive a package or send a photo. More typically we learn of couriers when they are arrested, a proverbially common occurrence in Russia. Article 228 of the criminal code, the possession statute, is known as народная статья — the people's article — for the sheer number of ordinary people it puts away. Together with 228.1, which covers sale, it produced [69,900 convictions in 2024](https://www.kommersant.ru/doc/8272083), 13% of every criminal conviction handed down in Russia that year. [Roughly a quarter of the country's prison population](https://enforce.spb.ru/images/Knorre_Drug_crimes_in_Russia.pdf) is serving a drug sentence. 

Those arrests fulfill a vital function in Russia: they fill police arrest quotas for an institution that has “[struggled to gain legitimacy with the public in the post-Soviet period](https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/RAD-151-5-8.pdf).” Russian police operate under a quota-driven performance system (the "stick system", палочная система), and drug possession is the cheapest possible case to close. While system operators are not granted any formal immunity in Russia, the incentives don’t make them worth pursuing. Low-level drug couriers without money or connections, arrested for a crime without public sympathy, are an easy way for a politically powerful interest group to achieve its performance goals. 

[Ninety-four percent of people convicted of distribution under 228.1 go to prison](https://www.rbc.ru/society/30/11/2023/656655999a79471ec1e8aad8), and [more than half of them are under 29](https://zona.media/number/2020/01/14/228-1) — recruited off social media ads, working a month or two before they are caught. The sentences start at four to eight years, with an aggravating clause for selling over an information-telecommunications network that lifts the range to five to twelve. Since essentially every retail drug sale in Russia is now arranged online, the aggravated tier is the ordinary tier. 

## Borders and Barriers

Operators in Russia, on the other hand, are much less commonly caught. [One shop owner interviewed by researchers](https://globalinitiative.net/wp-content/uploads/2024/11/Max-Daly-Patrick-Shortis-Breaking-Klad-Russias-dead-drop-drug-revolution-GI-TOC-November-2024.pdf) estimated that police take down five or six of the thousands of Russian darknet shops in a year, and that owners are almost never arrested at all. 

The brazen clear web marketing presence of AUO speaks to just how little operators fear prosecution. Despite the severe penalties for selling drugs, they can advertise with an impunity that is unheard of in the North American or European markets where penalties are less severe.

Franchising the last-mile distribution work to customers in other countries not only relieves them of the courier work, it relocates that risk into less punitive areas where the danger to couriers is lower. While the platform itself is Russian in origin, the end users are distributed across Ukraine, Poland, Türkiye, and Kyrgyzstan. 

For a traditional drug ring primarily concerned with trafficking, this kind of geographic spread would erode the group cohesion vital to organized crime. For dark market franchising, that dispersion becomes a virtue. With operators working in Russia and couriers in Ukraine, national cooperation between police is unlikely. Preferred drug products are synthetics manufactured locally rather than imported. National borders become a barrier to the police rather than the dealers. 

Nor are language barriers a problem. Free, instantaneous translation is simply a given at this stage of history. Telegram and cryptocurrency provide globally accessible communication and payment channels. There is nothing to prevent dark market operators from selling their platform across the globe, [spreading the technology developed to survive the Russian police state to less hardened territories](https://www.trmlabs.com/resources/blog/how-russian-style-dead-drops-are-transforming-online-drug-sales). 

‍

## Conclusion

None of those structural protections — Telegram, lenient policing, national boundaries — exempt dark market operators from the need for operational security. After the Russian invasion of Ukraine, for example, a Ukrainian security researcher leaked [a trove of internal chat logs from the Conti ransomware group](https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-i-evasion/). Leaky databases are another constant risk, affecting organizations around the world. That is one problem, at least, where the operator bears the exposure.

‍

## Protect your organization

Get in touch or book a free demo.

[Contact sales](/demo)

[Free demo](/demo)

## Related breaches

Learn more about the latest issues in cybersecurity.

[](/breaches/cyber-risks-of-the-2026-world-cup)

#### [Own Goal: Inside the Cyber Risks of the 2026 World Cup](/breaches/cyber-risks-of-the-2026-world-cup)

Free World Cup streams and black-market betting sites are leaking fan data. UpGuard research reveals the hidden cyber risks of the 2026 tournament.

[](/team/greg-pollock)

[Greg Pollock](/team/greg-pollock)

June 30, 2026

[](/breaches/social-insecurity-billions-of-social-security-number-and-passwords)

#### [Social Insecurity: Billions of Social Security Number and Passwords](/breaches/social-insecurity-billions-of-social-security-number-and-passwords)

UpGuard research found a trove of sensitive information in an exposed Elastic database. Getting to the bottom of what it meant led us down an interesting path.

[](/team/greg-pollock)

[Greg Pollock](/team/greg-pollock)

February 18, 2026

[](/breaches/angelsense-data-leak)

#### [Sixth Sense: GPS and AI Data Exposed for Assistive Devices](/breaches/angelsense-data-leak)

UpGuard can now report that it has secured an Elasticsearch database for AngelSense, a GPS tracker for children and adults with special needs.

[](/team/upguard)

[UpGuard Team](/team/upguard)

January 30, 2025

[](/breaches/pta-database)

#### [Stolen Data: National PTA Database Available on Dark Web](/breaches/pta-database)

On May 13th, UpGuard discovered a new set of data recently posted on a prominent dark web forum, this time allegedly belonging to the National Parent Teacher Association.

[](/team/upguard)

[UpGuard Team](/team/upguard)

May 14, 2024

[](/breaches/smarterselect)

#### [Student Applications: How an Education Software Company Exposed Millions of Files](/breaches/smarterselect)

UpGuard can now report that a public Google Cloud Storage bucket containing approximately 1.5 terabytes of data used to administer funding programs for college students has been secured. The bucket belonged to SmarterSelect, a company that provides software for managing the application process for scholarships, grants, and awards. The more than 2.8 million files included documents like transcripts, resumes, personal essays, tax returns, and invoices for approximately 1.2 million applications to funding programs.

[](/team/upguard)

[UpGuard Team](/team/upguard)

November 22, 2021

[](/breaches/power-apps)

#### [By Design: How Default Permissions on Microsoft Power Apps Exposed Millions](/breaches/power-apps)

38 million records were exposed in multiple data leaks resulting from misconfigured Microsoft Power Apps portals. Data included sensitive information such as COVID-19 contact tracing data, COVID-19 vaccination appointments, social security numbers for job applicants, employee IDs, and millions of names and email addresses.

[](/team/upguard)

[UpGuard Team](/team/upguard)

August 23, 2021

[View all breaches](/breaches)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
