I. Anti-Fraud Systems: Information Collection and Analysis
I. Anti-Fraud Systems: Information Collection and Analysis
you should already understand that personal methods aren’t simply handed out, and public
methods are ineffective unless you know how to properly apply the insights gained from this
forum to innovate older methods. If you expect success without effort or assume that everything
will be laid out for you, you’re setting yourself up to be taken advantage of. This is a criminal
forum, not a hand-holding service. Come in expecting to be spoon-fed, and you’ll leave worse
off than you arrived.
I've distilled this information as concisely as possible without sacrificing critical details. If you
find it difficult to process or analyze even a basic research summary, then fraud simply isn’t for
you.
This post covers information and data on anti-fraud systems cache, techniques, 3DS, variables
processed, including the data they collect, common triggers and tactics used to flag suspicious
transactions, and details related to 3D Secure (3DS) authentication including why it might not be
triggered and what variables are processed by these systems.
---
Anti-fraud payment systems (Riskified, Accertify, ACI Worldwide, Experian, VISA, etc) use a
multifaceted approach to detect and prevent fraudulent transactions. They integrate data from
various sources and apply advanced analytics (machine learning, behavioral analysis, and rule-
based systems) to assess real-time risk.
A. Information Collected
- Transaction Details:
- Data Collected:
- Triggers/Examples:
- Unusually high amounts or rapid successive transactions that deviate from historical patterns
- Cardholder Information:
- Data Collected:
- Triggers/Examples:
- Device Information:
- Data Collected:
- Device type, operating system, hardware identifiers (device ID, IMEI, etc)
- Browser fingerprinting (user-agent, screen resolution, color depth, fonts, and plugins)
- Mobile app version, and specific device sensor data (e.g., screen brightness)
- Triggers/Examples:
- Network Information:
- Data Collected:
- Triggers/Examples:
- Behavioral Data:
- Data Collected:
- Anomalies in behavioral patterns (e.g., erratic login times) that differ from established habits
- Authentication Data:
- Data Collected:
- Triggers/Examples:
- Data Collected:
- Triggers/Examples:
- Inconsistencies between declared and actual environmental data or sudden changes in context
---
Anti-fraud systems employ a combination of real-time analytics, historical data comparison, and
external intelligence to trigger fraud alerts, common triggers include:
- Behavioral Anomalies:
- Unusual patterns in login frequency, session duration, or interaction metrics.
- Authentication Irregularities:
- Data Inconsistencies:
- Conflicts between the information provided during the transaction and data from public credit
records.
- Network Flags:
- Use of known high-risk IP addresses, proxies, or VPNs, and abnormal network latency or jitter.
- Environmental Mismatches:
- Differences in time zones, language settings, or device sensor data (e.g., screen brightness
variations) that do not align with the user’s profile.
---
How to lower our risk assessment?
---
3DS is a security protocol designed to add an extra layer of protection for online card
transactions. It involves the card issuer prompting the cardholder to authenticate the transaction,
typically through a one-time code, before the transaction is authorized (In other words, carders'
worst enemy nowadays).
- Merchant Exemption:
- Merchants with low fraud rates or specific risk profiles may be exempt from requiring 3DS.
- Transaction Amount:
- Low-value transactions may not trigger 3DS authentication to streamline the user experience.
- User Behavior:
- Consistent, low-risk transaction history may lead issuers to bypass additional authentication.
- Technical Issues:
- Occasional glitches or system errors can prevent the 3DS prompt from being displayed, though
such cases are rare.
---
Anti-fraud systems and 3DS implementations (such as those from Visa, VBV, AMEX, Discover,
and others) process a multitude of data points in real time. Key variables include:
- Merchant Data:
- Merchant ID, Merchant Name, Merchant Country Code, Merchant Category, DS URL, DS
Reference Number, 3DS Requestor URL, and Requestor Name
- Example Trigger: An unexpected merchant ID or country code mismatch may signal a risk.
- Cardholder Name, Cardholder Account Number, Card Expiry Date, Cardholder Account
Identifier, Billing Address, and Contact Information (email, home phone, mobile phone)
- Transaction Data:
- Purchase Amount, Currency, Purchase Date & Time, Transaction ID, Transaction Type, and
Frequency (Number of Transactions per Day)
- Example Trigger: A sudden shift in the device fingerprint or network location can indicate
fraud.
- 3DS Requestor Authentication Method, DS Reference Numbers, SDK Reference Number and
Version, SDK Encrypted Data, Ephemeral Public Key, and Message Categories/Types
(including extension types)
- Account Age, Recent Changes (e.g., Password Change, Address Change), Shipping Address,
and Order Information (e.g., Pre-order, Gift Card, Donation, or Hospital Payment Data)
- Example Trigger: Rapid changes in account information or behavior that doesn’t match
historical patterns.
- Time Zone, Language Settings, DS Reference Number, Acquirer BIN, and Data from credit
and fraud databases
- Example Trigger: Mismatches between expected and actual time zone or language settings can
trigger further verification.
The objective isn’t to perfectly mimic the target identity but to minimize your fraud score as
much as possible, reducing the chances of triggering 3DS or, worse, a full decline. Before
proceeding to payment, research your estimated fraud score using sources easily accessible on
the forum.
Keep in mind that certain cards and shops will always prompt 3DS verification, so always use
fresh, active cards. I highly recommend sourcing your own cards through phishing or spamming
for better success rates. (I may consider creating a post on obtaining cards.)
Develop the ability to conduct your own research and identify high-risk shops for carding, i.e.
google dorking, forums, etc.
If your setup relies on proxies or RDP, ensure that your residential proxy is within a 30-mile
radius of the CH’s location and that your sources are reliable to avoid unnecessary red flags.
p.s. modern anti-fraud systems may seem daunting, though; knowledge is the antidote to fear and
the tool to overcome AFDS.
Remember, fraud isn't a get-rich-quick scheme. It takes brains, hard work, and dedication
once again, never buy your cards from vendors unless you know an exclusive spammer. If not
the ladder, you should be spamming/phishing your own ccs!! 99% vendors you come across are
frauds, and you're going to end up wasting your money and quitting. If you want to make real
money with carding, learn to spam your own cards!!
cheers
u/zankyu
11 comments
Comments
Sort comments by
Top
/u/zlxjy75iuxkulewbh
1 points
2 days ago
Let's say customers pays with a Visa for item on a market like Amazon. Before the payment
request even gets to Visa, it is processed by, at least, the market, the individual merchant,
merchant's payment processing company (i.e. Square, etc), murchan't acquiring bank. Then the
acquiring bank asks Visa if it's possible to get some money from issuing bank. Visa asks Issuing
bank. Issuing bank may say "yea ok" and put a hold on the funds. Right? All that takes 30
seconds max.
It would be very interesting to know which facets of the anti-fraud are performed by which
entity. To guess that we can think of who has direct access to what information. For example
only the market has access to browser telemetry. And only Visa and issuing bank have direct
access to card holders behavioral history across many vendors.
So at which point do the anti-fraud providers inject themselves into this orchestration? How do
they get all this info that OP described from all the different players? Are there regulations
mandating the process of info sharing or is it subject o adhoc agreements among them? Does
each of the players have their own anti-fraud? If so, how do they make a collective decision?
Any ideas?
/u/Platinum1
1 points
2 days ago
Each player has their own anti-fraud except the scheme (e.g. Visa). The schemes are providing
the framework between the merchant + acquirer to the issuing bank. They charge the issuing
bank and acquirer for everything (AVS checks, Tokenization, 3DS etc). So it's essentially the
acquirer and the issuer who decide their fraud checks. So some banks may not bother CVV
checks for some BINs as they know the cost of the scheme charging for that check is more than
the risk they would face from declines. It's all optimization and to ensure acceptance rates are
high with minimal cost and fraud
/u/zlxjy75iuxkulewbh
1 points
2 days ago
So you're saying that the analysis to determine if the user's mouse movement had any anomalies
or if a char drawn on the HTML5 canvas was a pixel off is done at at the two banks? How do
they get that information? It's alot of super technical work to simply collect the data for analysis
described by OP so that it's usable for machine learning. It must be astronomically expensive.
Who pays for it?
/u/zankyu 📢
1 points
2 days ago
To piggyback off what /u/Platinum1 mentioned, when you visit a target platform or store, the
website immediately collects your browser fingerprint along with other behavioral metrics, such
as time spent on the site, navigation patterns, geolocation, and device details.
This data is used to calculate a risk score the moment you enter the website. when you proceed to
checkout, this risk score is transmitted to both the merchant and the payment processor, helping
them decide whether to allow, flag, or require additional authentication for the transaction.
once you've identified your target processor/store, you can conduct in-depth research to pinpoint
the specific data that the provider caches.
/u/zlxjy75iuxkulewbh
1 points
2 days ago
" learn to spam your own cards!!"
Can you point us in the direction of a good resource to learn spamming our own cars?
/u/zankyu 📢
1 points
2 days ago
There's plenty of information on dread about spamming/phishing, you just need to take the time
to search. I may post a detailed guide in the future, depending on the engagement this post
receives.
(the search function is one of your most valuable tools; learn to use it effectively.)
/u/zlxjy75iuxkulewbh
1 points
1 day ago
"go look it up". that can be said about anything. you posted this wonderful message to save us
time so we don't have to read 20 books. Thank you. But you won't belabor the most important
point of your message by saving us time reading 120 crap tutorials?
As far as engaging, I don't know about anybody else, I find this fascinating. I actually have many
more directions I'd like to talk about this post. But I'm holding back as to not overhelm you with
attention ;)
/u/zankyu 📢
1 points
1 day ago
Once again, nothing will be presented to you on a silver platter. The search function remains
your most precise and valuable resource.
I'm happy to answer any well-thought-out questions, provided you have conducted preliminary
research.
/u/Shabz5297 🍼
1 points
1 day ago
Nice guide, really descriptive and helpful thanks for taking the time to write.
- If you must use proxies , I'd go for EDU / Verizon Biz or Business type proxies I've had luck with those
Lastly, AFAIK most well-known proxy services dont give you the option to change or spoof os
fingerprint..
Your tcp os fingerprint maybe different from your host machine , that's a big red flag for any modern AI
You have a android tcp os fingerprint and you are using a Windows computer - - - Red flag
Most carders are unaware of this small detail , search on google what "TCP OS Fingerprint" is if you need
to know more
If the site you are carding doesn't have a anti-fraud system in-place , using anti-detect browser for
multiple accounts is fine.
For instance , I recently came upon a few sites that only have braintree payment processor on the site
with no real anti-fraud in place.
Braintree payment processor does have a few fraud checks, but its not that hard to bypass when they
only check the basic stuff like proxy usage , velocity checks, avs check, etc...
Tip /Tricks: Find sites that don't have any modern ai system in-place and are poorly designed .
Gold / Bullion / Gold coins sites are somewhat pretty lax , their order verification is not hard to pass..
Good luck !
keyboard- make sure language is cc owner country language(like for usa keyboard be English us)
2 never copy paste cc info and billing address but manually type it out
4 check for DNS leak(if you have them then change socks5 you are using)
6 for picking cc you can check the zipcode of cc beforehand on the autoshop(you can crosscheck the
household income of diff zipcodes on unitedstateszipcodesdotorg)
7 for grabbing otp/codes you can use otpbots(dont work everytime but you can try)
10 never share your bins and buy from autoshops for getting cc at cheap
/u/disofa
1 points
3 weeks ago
Understood, what would be the most optimal way to cash out? I've seen shopify and moonpay
are big ones
/u/bangbang999
1 points
3 weeks ago
buy bitcoin from any exchanger (binance , coinbase , kraken ..) with your legal documents
then go to infinity exchanger or coinswap , there you can buy xmr (monero) anonymusly and
then transfer to the markets
But the reason I am carding is for money, therefore my question is should I try carding this
necessity?
Additional questions:
I use Qubes OS's disposable qube which comes prebuilt with firefox, with a proxy from
premsocks for carding, is that atleast close to an antidetect browser? or is this a weak setup for
carding.
I also have been browsing carding forums and they recommend premium cards, for this I
personally use bclub; should I be using another site such as russian market or stashpatrick?
I in no way shape or form advanced at carding, I have recently had success rates of 2/3
cards, and I would like to go for bigger things ordering from designer brands, stockX, goat
and more. I am asking for assistance from others and I am not strictly asking for tips
regarding the questions above, I would like all guidance possible, aswell as guidance for my
opsec.
Thank you.
4 comments
Comments
Sort comments by
Top
/u/trippinonacid
1 points
3 weeks ago
try carding crypto sites
/u/Flamezdknt
1 points
3 weeks ago
Hello Champ, i would love to ask few questions as well, please.
/u/Ciame1980 📢
1 points
3 weeks ago
go right ahead
/u/Flamezdknt
1 points
3 weeks ago
Thanks Champ. Please, how best do i go about carding? I am an ebayer, but getting accounts to
sign in on ebay these days isn't easy at all, so i thought about adding CC to the accounts just to
make an outright purchase, but then again, i need to do that the proper way or another way.
Active at markets-
BlackOps
Nexus
Darkmatter
Drughub
MGM
Torzon
POSITIVE FEEDBACK 95 %
8 Years of experience
Please specify if you are interested in Credit or Debit card. Otherwise you get random one.
FREE CASHOUT TIPS inluded with each order, so you dont have to worry about getting them until you
leave positive feedback, as other vendors do.
I am sending orders manually, so you always get fresh card. Delivery time less than 24 hours
Data format:
number:expirydate:cvv2:holder:address:city:zip:SOMETIMES ALSO Email or
Phone
1. I am selling 100 % live cards with balance on them. The thing you must
understand is that many times people think that problem is in their card,
not in their skills.
Many cards sold here on Darkmarkets are LIVE with decent amounts on them. People
just struggle to card the right way or dont have the right strategy and
carding setup for a specific site they are aiming.
But on the other hand, here also are sold used cards, refurbished, and
thats why im coming with this listing, to give you a 100 % working card.
2. I suggest to not go for more than 7-10 % from the balance available in
one transaction. 10 % is the maximum limit i recommend, better less. Again,
if you are not a beginner, you know that big transactions trigger bank
antifraud systems and they cancel your card and call the card holder,
especially if cardholder makes online payments very rare. If on card is
only 3500 $ available credit for example, than you can go for a 600-700 $
transaction
which is more than 10 %. But if on cards are 50k $, a 5000 $ purchase may
kill the card. Hope you get the idea.
3. Always use with HQ socks5. Public IP fraud score should be less than 10 points. And be sure to use
quality antibrowser - dolphin, linkensphere works fine. Check your public ip score at scamalytics site and
consistency of browser fingerprint at pixelscan.
required things:
live credit card w ssn n dob of cc owner
card valet app on android/ios
moonpay acc w 2 transaction history(1-2 week old)(gotta be level 2 account)
socks5
step1 - buy credit card from any vendor or autoshop you got (dont go w debit card)
step2 - do the lookup on cc owner(easily can be done using tele bot/pls dont text me asking for
bot/also watch for scams on tele/prefer using escrow!)
step3 - go to card valet or card nav app here you gotta enroll the cc
for enrolling you need to first create outlook on cc owner name n enter the card details n other
shi like SSN n DOb
once you done w this step then you will have full access to the card and you can look at the
transaction, raise limits n remove limits etc
step4 - get fresh proxy of cc owner city n try buying crypto on moonpay account through website
dont spam transaction like crazy but do $200-500 multiple transaction n youll be good
(try using geelark or android studio while carding n make sure you on browser not the moonpay
app while carding)
to get over this whenever you login you use different broswer
lets say you login into moonpay on chrome then dont login again in chrome use brave or any
different browser n keep changing browser
here if it says level 2 then you gucci and if it says level 1 then click on get more buying power
ENJOY
34 comments
Comments
Sort comments by
Top
/u/RichDad
1 points
1 month ago
you know the working bin??
/u/MoonpayGooner
1 points
1 month ago
I have 30 bins that are tried & work on MoonPay, Coinbase, Kraken & Robinhood
All enrolls.
/u/RichDad
1 points
1 month ago
can you share?
/u/MoonpayGooner
1 points
1 month ago
I can, what can you do for me?
/u/Johanlamperouge 🍼
1 points
4 days ago
send you 30buks against 30 bins that work on MoonPay, Coinbase, Kraken & Robinhood
/u/RichDad
0 points
1 month ago
butter trade
/u/1312im 🍼
1 points
3 weeks ago
can you write me on tg? i have many logs
/u/manghalo
1 points
1 month ago
wdym lookup on cc owner
/u/shukorino1
1 points
1 month ago
Looking up the cc owners fullz
/u/manghalo
1 points
1 month ago
can u guide me towards a site for ccs n fullz, cant find any trustworthy ones
/u/Dani126
1 points
1 month ago
If i understand right, its not a problem if the card holder and the moonpay account holder(the guy
how did the verification) is different, right?
/u/trippinonacid 📢
1 points
1 month ago
the name dont really matter
/u/trikko P
1 points
1 month ago
Can you clarify how this works when the account holder and the cardholder are different people?
From my understanding, MoonPay doesn’t verify a card if the name doesn’t match the account
holder. Are there any key nuances that make this method successful or not? Have you personally
done this before, and if so, how did you handle the mismatch in details and what amount did you
use?
/u/trippinonacid 📢
1 points
1 month ago
the name dont really matter tbh
/u/anastasiachocolate
1 points
1 month ago
what u mean by usa method, won't it work if im outside US?
/u/trippinonacid 📢
1 points
1 month ago
man gotta be usa acc
/u/fullzzss
1 points
1 month ago
[removed]
/u/trippinonacid 📢
2 points
1 month ago
http://dumpliwoard5qsrrsroni7bdiishealhky4snigbzfmzcquwo3kml4id.onion/image/
4f9d3a80d9087569.jpeg
/u/1312im 🍼
1 points
3 weeks ago
woo can you help me
/u/MoonpayGooner
1 points
1 month ago
Need moonpay accounts with 1 transaction, aged 1 month at least.
Paying good money or loading your accounts for %.
/u/trippinonacid 📢
1 points
1 month ago
i need too bro
/u/1312im 🍼
1 points
3 weeks ago
can you write me in tg? @jamesbongg
/u/hushpova
1 points
1 month ago
who else have tried this method and if there is succes in it where to get the usa moonpay account
from?
/u/barthelemystkitts985
1 points
3 weeks ago*
been killing MoonPay EU for months, but now it’s way harder to open with docs. Need real
people/heads now, which is 1) hard to find and 2) got percentage issues. Guessing they tightened
the algo or switched up their policy
http://dumpliwoard5qsrrsroni7bdiishealhky4snigbzfmzcquwo3kml4id.onion/image/
2dd6a0b864f26272.jpeg
http://dumpliwoard5qsrrsroni7bdiishealhky4snigbzfmzcquwo3kml4id.onion/image/
29cc6c7215b5d50c.jpeg
/u/1312im 🍼
1 points
3 weeks ago
WTF G AHAHAHA can you write me on tg? @jamesbongg
/u/trippinonacid 📢
1 points
3 weeks ago
same but i do kyc myself
i got app for taking over phone camera and making selfie vids using ai
/u/barthelemystkitts985
1 points
3 weeks ago
very old
/u/distillatedirect
1 points
3 weeks ago
hey bro, would you be willing to share the app? Need amazon seller accounts :)
/u/trippinonacid 📢
1 points
3 weeks ago
i have posted advertisment on fraudship for selling this app for $125(escrow +)
/u/sadhubaba 🍼
1 points
2 weeks ago
I have moonpay accounts can you load them
- Learning OPSEC has had its ups and downs. I currently have Mullvad VPN aswell as the free
VPN Proton. I know that carding with just a VPN would be silly, but cant seem to grasp an
understanding of proxies. Finding residential proxies has been a challenge, especially since im
low on crypto. I managed to deposit around $10 on premasocks. When buying proxies, should I
look for solely residential? And what sites have good residentials?!
- PROXY HELP: After purchasing a few proxies (which I believe are data center proxies), I dont
quite understand how to run proxies. Ive read that I should be using a software such as
"proxifier" but ive also seen people use the proxy configure in their windows settings. After
trying both, the proxies were kinda boof and didnt seem to work. I'm not sure what i'm doing
wrong.
/u/djdubai7
1 points
1 month ago
If your end goal is to make actual money and not just burn bread to learn a few things on carding
and opsec then you definitely should do banks instead, easy to get going with better profits.
/u/voose 📢
0 points
1 month ago
Im not really into the whole bank stuff. I have 2 paypal logs but have no clue how to configure
my proxies. I keep getting an error and cant use the internet. Im curious on how people use the
cards online because isnt it super unsafe?? Like what do u buy ONLINE with your dumps/fullz
etc.
/u/Riv
1 points
1 month ago
Yo bro can i ask where u got ur paypal logs from and also if you just use data or a burner phone
you wont get caught.
/u/RichDad
1 points
1 month ago
okay a little about proxies, you can run socks5 on chrome, firefox, you just have to use the right
extensions and settings, i recommend pia s5, try that, beware or phising link, can do that if you
need
/u/voose 📢
1 points
1 month ago
Where can i find Pis s5?
/u/RichDad
1 points
1 month ago
you buy
/u/ethylphen1
1 points
1 month ago
definitely making a smart choice with the proxies. i've had the best luck with residential proxies,
but in my experience finding a good source for proxies is the most important. i've been sold
proxies that have been burned or were also being used by other people at the same time that were
sold to me as new. so just make sure you're sourcing your stuff properly. if you, or anyone else
for that matter are curious about good sources for literally anything related to carding properly
like numbers, software, or other things i've gathered over the years just reach out. i'm not
gatekeeping this info like a lot of people do. it took a lot of trial and error to learn, so maybe it
won't be the same for you lol.
/u/trippinonacid
1 points
1 month ago
get proxy of same city as cc owner
/u/lameassnigga
0 points
1 month ago
I got a dedicated proxy but that was slow as hell. Site wasn't even loading up
/u/trippinonacid
1 points
1 month ago
lol get good proxy
/u/lameassnigga
1 points
1 month ago
Thanks for suggesting bro. Read your another comment about geelark. Thanks for suggesting
that too.
/u/trippinonacid
1 points
1 month ago
dont thank me jus pay forward tbh
/u/bsmt1
1 points
1 month ago
Hello, how to create flair escrow link ? Secondly, how can i know the verified vendor what is the
catiria to have certitude that is the right vendor
Vendors who can prove to moderators of various subs, including /d/Fraud, that they are running
a arguably stable business on reputable markets only. They do this by providing the moderation
team with PGP confirmation and proof in the form of good reviews. The criteria can be different
per subdread.
All that the vendor gets is some "flair" behind their name (similar to my "⊹𝒇𝒂𝒏𝒄𝒚⊹ MOD")
indicating they are a established vendor. Here in this sub that does exempt them the
advertisement rule.
/u/bsmt1
1 points
1 month ago
Thanks, but still now I haven't understood well your advice I'm trying to get them well and
properly but if u can be more specific I will be proud of your modesty , i need to open i trade on
fair trade with someone how to run that sorry is better to understand or learn.
They have a subdread, but as impartial moderator I can't link to them. Try and guess it, I'd say.
/u/QuickQuestions
1 points
1 month ago
I will keep it simple.
Check Fraud is where you, with a already bought drop account (a bank account created with fake
info from Fullz), load a check that was previously bought too, usually that checks are real ones
that has been edited with photoshop.
Logs is where you login in a existing and real bank account, with a owner, and drain the funds, is
harder because you need to be quick or at least not get caught by the owner, otherwise you will
get log out the account. But, is less complicated than Check Fraud.
If you are in the states physically then I would say checks are the way to go!
Its weird you are mentioning that you won't ask a questions yet you do. You know there is a
SEARCH button and you can find whatever you want. From there gather your knowledge and
BOOM. Try and Error until you perfect your method!
/u/flypayments
1 points
1 month ago
So if you purchase logs you just log into a bank account and drain the funds that's it? Do you get
access to a card with a bank log, and if so can you make a payment or is the only method of
draining to load another account?
If it was as easy as you described everyone would be doing it. Not saying its not easy but you
need a good setup and a ways of cashing out!
/u/419yahooboy
1 points
1 month ago
dont do purchases with logs. do an emt or wire. just get a cc or fullz if u want to do a purchase.
/u/EdwardYayden
1 points
4 weeks ago
can u elaborate more on this pls
/u/Faraday7
1 points
1 month ago
[removed]
/u/419yahooboy
1 points
1 month ago
to get otp?
CREDIT CARDS DATA - USA, EU ,LATINO ,ASIA + FREE CASHOUT TIPS + VIDEO
by /u/procarder2 • 1 month ago in /d/nexus
0 comments
Commented on: Tips and Tricks to get better at carding
/u/miklo1 • 1 month ago in /d/Carding • 1 points
Thank you for the advice
1
CREDIT CARDS DATA - USA, EU ,LATINO ,ASIA + CARDING GUIDE CC/CVV TO
CRYPTO + VIDEO
by /u/procarder2 • 1 month ago in /d/DrugHub
0 comments
2
CREDIT CARDS DATA - USA, EU ,LATINO ,ASIA + CARDING GUIDE CC/CVV TO
CRYPTO + VIDEO
by /u/procarder2 • 1 month ago in /d/BlackOps
0 comments
3
CREDIT CARDS DATA - USA, EU ,LATINO ,ASIA + CARDING GUIDE CC/CVV TO
CRYPTO + VIDEO
by /u/procarder2 • 1 month ago in /d/Carding
39 comments
-1
[SELL] CREDIT CARDS DATA - USA, EU ,LATINO ,ASIA + CARDING GUIDE CC/CVV
TO CRYPTO + VIDEO
by /u/procarder2 • 1 month ago in /d/fraudship
3 comments
Commented on: Tips on cash out
/u/cashlord56 • 1 month ago in /d/fraudship • 1 points
If you have Name and Address included, the only way of cashing them out is through check
without that, you could use the Account an Routine Number to pay balance owed on Credit Card
-1
cc to crypto no clickbait :p(USA moonpay method)
by /u/trippinonacid • 1 month ago in /d/Carding
34 comments
Commented on: Brand new to carding. Need tips/Advice
/u/trippinonacid • 1 month ago in /d/Carding • 1 points
dont thank me jus pay forward tbh
you can use proxy in antidetect or you can use proxy in computer directly search for proxy in
settings
Commented on: Brand new to carding. Need tips/Advice
/u/ethylphen1 • 1 month ago in /d/Carding • 1 points
definitely making a smart choice with the proxies. i've had the best luck with residential proxies,
but in my experience finding a good source for proxies is the most important. i've been sold
proxies that have been burned or were also being used by other people at the same time that were
sold to me as new. so just make sure you're sourcing your stuff properly. if you, or anyone else
for that matter are curious about good sources for literally anything related to carding properly
like numbers, software, or other things i've gathered over the years just reach out. i'm not
gatekeeping this info like a lot of people do. it took a lot of trial and error to learn, so maybe it
won't be the same for you lol.
Commented on: Brand new to carding. Need tips/Advice
/u/Riv • 1 month ago in /d/Carding • 1 points
Yo bro can i ask where u got ur paypal logs from and also if you just use data or a burner phone
you wont get caught.
Commented on: Brand new to carding. Need tips/Advice
/u/RichDad • 1 month ago in /d/Carding • 1 points
you buy
Commented on: Brand new to carding. Need tips/Advice
/u/voose • 1 month ago in /d/Carding • 1 points
Where can i find Pis s5?
Commented on: Brand new to carding. Need tips/Advice
/u/RichDad • 1 month ago in /d/Carding • 1 points
okay a little about proxies, you can run socks5 on chrome, firefox, you just have to use the right
extensions and settings, i recommend pia s5, try that, beware or phising link, can do that if you
need
[b] if you have a credit card info (& the owner's address) what is the best setup to use it (milk
card, sell card, use it in small amounts monthly,etc
by /u/elpath01 • 2 months ago in /d/Carding
Idk why I can't seem to figure out a good setup to do this.. But it's a simple task, I'm just trying to
see what the standard is. Using a VM (usb Whonix probably the best generally or usb Tails ),
VPN with a state select option for the owner's real address (paid through crypto, & other opsec
standards), public wifi ?, etc.
The setup does depend on the use objective you would be using the card for. What setups,
software/tools, would be ideal for withdrawing/spending (milking) the card to it's limit? Or just
using the card occasionally without drawing attention to the owner? I've heard this was the best
long-term plan, as you can get the most out of it. Buying anything on e-commerce sites isn't a
great idea as the shipping address will be saved, making it easy to track. So, buying crypto,
withdrawing small amounts through platforms that don't require any identity info/etc.
What other ways can someone anonymously remove the funds from credit cards? I usually only
see people seeing cards, which imho isn't a greaet idea, as the authenticating part for the buyer
takes a while.. Even with escrow , idk how that would work. Most buyers would just get ripped
off or if they buy from a high rated vendor it might work I just don't know how someone could
continuously get credit cards from people without getting caught. seems like a honeypot.
*Can someone please share some ideas/tips about this quesiton? Specifically the general setup/s,
the tools/software used for specific tasks, and the platforms where people remove the money
from the cards.
Please forgive me if this isn't a knowledgeable question, I've researched this topic a good deal,
but you run across so much trash or repetitive posts/comments. Where people/bots ask the same
questions, or complete noob questions that seem to be 12 year olds, et cetera
*if this isn't the correct subdread let me know. And if there are more serious forums (whether on
dread or another site/platform lmk via dm) & subdreads lmk in messages. Dread seems to mimic
reddit in terms of sub-forums with high subscribers being less serious & less knowledgeable. I
don't know if subdreads allow for private entry like subreddits do
5 comments
Comments
Sort comments by
Top
/u/dollar7
1 points
2 months ago
have you thought of casinos
/u/bananabread15
1 points
2 months ago
the basic tools are socks5 proxy, with an anti fingerprint browser/browser extension. your goal is
to look like the card holder
/u/lahlah23
1 points
2 months ago
pretty sure vms can be detected you should buy an rdp and a socks proxy as close too owners
address as possible
/u/thebeast666
1 points
1 month ago
What if i already live in the same city as my target? Do i really need a RDP? If i understand
correctly, the only reason for an RDP is so that i can pretend im the target since the RDP
connection would be close to where my target lives which would mimic him and his connection.
/u/lahlah23
1 points
1 month ago
yea but the problem with vms is its drivers can be detected as a vm and the transaction wont
work js spend the 15$
I've been active on Dread for a while now and I start to learn more and more thanks to this
community!
The thing I am struggling with is OPSEC. I want my OPSEC to be a 10/10! Sure there is always
risk involved but I want to decrease the risk with my OPSEC.
Hardware OPSEC:
I bought a used laptop online and payed for it with cash so that it can't be traced back to me. I
haven't connected it to my own wifi to avoid being tracked to this adress.
Wifi: I am thinking about 2 things for my wifi. I'll either buy a burner phone with cash, free sim
cart and prepaid on the sim to make a hotspot for my carding or I'll keep going to different public
wifi spaces. What would work best?
Software OPSEC:
So for my software OPSEC I have the following software:
RDP: Should I use the default from Windows or should I go with Anydesk to connect to another
PC?
Socks5: Protect myself
VPN: Protect myself
Am I still missing something in my OPSEC or is there something that can be changed to reduce
risk?
I know that with the help of RDP, Socks5 and VPN I can log into a bank log (include email
access).
When I am logged in, should I transfer everything, 50% or somewhere in the middle? When
transfering the funds from the log I could send it to a bank drop (Or straight to crypto?). After a
few days the money will be on the bank drop but how can I transfer it into crypto? I'm thinking
about making a fake account on coinbase or another CEX, to a DEX, mix it a few times with
Monero and back into the wallet I really want it to be in (Ledger wallet).
When logging into these crypto accounts I should use a burner phone with free sim and prepaid
to get on 3G / 4G / 5G?
/u/velli71
1 points
2 months ago
baby bottle here.
i been lurking and learning for a little bit over here and one thing i have been seeing is to stay
away from anything windows. so the default windows rdp is probably a no go.
/u/bananabread15
1 points
2 months ago
you cant card on anything other than a windows profile, whether its spoofed or your real OS :)
/u/BlueJayBaby
1 points
2 months ago
what about virtualization? im tryna put it together but im not sure if windows on a vm will cause
red flags
/u/bananabread15
2 points
2 months ago
if you have to use a VM just spoof the mac inside of the VM
/u/silversurfaa
1 points
2 months ago
facts
/u/silversurfaa
1 points
2 months ago*
It wont, if you harden it down to reg, and (pro tip* for the creative, you can card a license for the
windows on the vm) *it as well as other systems will think its all the way real machine*
/u/BlueJayBaby
1 points
2 months ago
wym by this? im running qemu + kvm do i need more?
/u/silversurfaa
1 points
2 months ago
not true bro. windows can be vuln, but is still most used in the world. you can blend in the herd,
as well as use "obfuscation tools".. search that
/u/velli71
2 points
2 months ago
appreciate all the guidance & tips here. about to look into all of this
/u/silversurfaa
1 points
3 weeks ago
alil appreciation goes along way.. feel free to hit me. s/o to the seekers
/u/bananabread15
1 points
2 months ago
shouldn't mix RDP and socks5
/u/silversurfaa
1 points
2 months ago*
false, its how you order it..
Your Welcome..lol
-Surfs Up
/u/bananabread15
1 points
2 months ago
it depends if the RDP has a residential IP or a data center IP
/u/silversurfaa
1 points
2 months ago
False, but i'm not gonna just hand the answer
-Surfs Up
/u/bananabread15
1 points
2 months ago
why would you need to pair a proxy with a dedicated windows profile that already has a
residential IP located in the card holders area?
/u/trojanhorse_404 📢
1 points
2 months ago
So go to a public wifi space, windows machine (burner) with VPN, RDP, socks5? Also, is it
good to get a burner phone, burner sim and some prepaid and do a 3G / 4G / 5G hotspot so I can
stay in 1 place for the carding?
/u/silversurfaa
1 points
2 months ago
you can, but dont have to..(if you know what your doing).. rn im at home eating a pb&j. (study
alil networking..routers&firewalls).. ive done phone hotspots & dedicated mobile hotspots from
carriers. Both will burnout fast but will work for a one off..kind of on the fly scam/ if you you
need 1 or 2 on the go.. not feasible for daily fraud.. note a mifi will do okay for a week or 2 but
most limit at 100gb a month..
/u/trojanhorse_404 📢
1 points
2 months ago
I know that it is possible to use my own network but I think it is kind of scary to use because I
don't know if I do the right thing or not and because I will be using RDP on windows I think it is
not really worth the risk. Any tips on what I can look for? And for carding, is it better to use a
burner laptop with RDP or tails on main machine / burner with RDP?
/u/silversurfaa
1 points
2 months ago
study until your confident. bcuz what sounds crazy is..you wanna do fraud, you want the money,
but are fearful of takin a risk??and also unsure/unaware of the risk your taking? but wont
research and want shortcut answers? i cant do it for you... y'all always make me stop talkin lol.. i
dont wanna play no more lol smh have a nice day
/u/infiniitty
1 points
2 months ago
hey there,your opsec is very good, but what i would recommend is getting good operational
system, like qubes os and installing it on your burner laptop, if it has at least 16gb of ram
but anyways i wish you good luck and let me know how it goes
i understand you get log in info to a paypal account. but the description gives no detail on the
amount in acc., how much crypto, etc.. and with a bank drop, is that like the acc and routing
number? and would it all be the same person? and any hints to where i could find and read about
what to do with that info once you have it. i am also curious how you know if it would be a good
and legit purchase. the example is off of a market place. this one costs $300, so i would assume it
has potential to be a payout for a lot more, but how do you know and understand the potential of
the account? many similar accounts offered dont provide hardly any detail, so i feel like there is
something i dont see or understand. any tips or advice i am grateful for.
2 comments
Comments
Sort comments by
Top
/u/FraudBay
2 points
2 months ago
Usually what you get with such package is:
Paypal log+password
Email log+password
Cookies (or RDP with login history).
Plaid account with connected bank (connected to paypal).
If you are looking for fully verified paypal accounts with BTC purchase available, i have plenty
in stock with 150$ pricetag.
Cheers
/u/AutoModerator M
1 points
2 months ago
Go to /d/carding to discuss credit cards
/u/disofa
1 points
3 days ago
do ya know a simple setup for iphone?
Also i've been seeing more and more posts about phishing about cards. How in the world do I
start, what direction would I even take.
/u/Tu_Padr1n0 🍼
1 points
3 days ago
what he said X2
/u/moundreaper 📢
1 points
2 days ago
1. you cant really do much opsec wise with a iphone, if you want to hit easy I would get a cc
from your state/city go to best buy and do a pick up they will ask you for a DL if your order is
over like $500 or something so beware
2. Start learning how websites are made ( HTML / CSS ) then learn PHP it's really not that hard
/u/Denofthieves
1 points
2 days ago
This is a half truth , most vpns get detected way faster than any socks 5. just find the right socks5
provider
/u/CryEngineX
1 points
2 days ago
Exactly.... and using free socks5.. Brother eeww
like it's the best way to get caught
/u/moundreaper 📢
1 points
1 day ago*
Any website can run a port scan on you and find out you are using socks5, it does not matter
where you get socks5 all providers sell the same thing! This is might only be for carding tho, like
I don't think you would have a problem using socks5 when opening a bank drop or sum
/u/Denofthieves
1 points
1 day ago
interesting what do you suggest we use then bc ive heard a low fraud score socks 5 is perfectly
fine
/u/moundreaper 📢
1 points
1 day ago
did you read my post? HTTP/HTTPS
/u/paulricky
1 points
3 days ago
Idk about those but I have a couple good ones and a method I can share with you if you have a
method you can share with me
/u/JaxsonW14 🍼
1 points
3 days ago
I got a 3ds payment portal you could use
/u/sadhubaba 🍼
1 points
3 days ago
Sure I have a 2d method I can share
/u/Vader101 🍼
1 points
1 day ago
Hey men I’ll like to trade methods also if you don’t mind I also have a couple of questions if you
don’t mind
3.1 Use 100% Accurate Personal Data also in the Account Creation
Input the name, email, phone number, and any other personal information exactly as it
appears on the
cardholder's file.
Address: Here you can put an adreess to receive your products.
Register the account using the email and name matching the credit card holder.
Avoid using disposable or suspicious-looking emails. Use legitimate services like Gmail.
IP Testing: Use tools like “whoer.net” to verify that your browser fingerprint, IP, and
geolocation
match the desired setup.
Avoid Suspicious Activity: Do not log in to multiple accounts or perform excessive actions
from the
same IP or session.
Backup Profiles: Save profiles in Linken Sphere to replicate successful configurations
easily.
By combining the SHEIN method with proper anonymity practices, SOCKS5 proxy use,
and browser
configuration, you can maintain a low-risk profile and improve the success rate of
transactions.
been doing my research but i want to make sure before i start with carding to get carding right.
the most imoportant thing is ur ospec (setup) ik that
laptop/Pc setup
i understand i need
cc
website
antidectect browser
ip \ and fraud checker
CC cleaner
rdp
SOCKS5
MAC adress changer
VM? ( i heard that this might kill the CC but i might be worng lmk thx)
vpn? (optinal i dont really use it i feellike it would ruin my carding )
is this the right set up or right direction with it lmk thx and would this work when i log into
accounts obv these are to make it seem like im the card holder if im missing anything lmk thx
process
activate phone
would probaly need to jail break it ? ( idk if im worng just lmk)
this is osmething i dont know about if their is a forum or if sombody has info thx
plug in proxy
go to website and do the steps above
and cash out ?
( for carding )
now i know this was a bit long but i want to know if my set up and process is in the right
dircetion for carding and fraud ospec is ur bestfriend in this game and im trying to make it im
good any advice or anthing ill appericate it
precaite ur time
get money
2 comments
Comments
Sort comments by
Top
/u/Beelz_
1 points
1 week ago
Can you explain exactly wym with CC Cleaner and Fraud Checker?
/u/KnoM00 📢
1 points
4 days ago
a CC cleaner is a type of software where it cleans out any temp files,clears clutter ( log
files,cookies) and broswer history on your computer its a good tool for carding and the fraud
checker is to check the proxy when doing a play thats the ip adress and so th proxy is not flagged
so ur card wont brun during carding