Operation Lobos (Portuguese: Operação Lobos), also known as Operation Wolves, was a Brazilian-centered 12-country multinational operation to target the operations of a TOR onion service known as Baby Heart. Additional objectives and targets of the joint operation were the deanonymization of the TOR host servers, TOR administrators, and TOR users associated with the target website and several other targeted websites/chat-sites that were alleged to contain or be used to traffic illegal images of child sexual abuse materials (CSAM) and other categories of legal nude and non-nude images of persons under 18. As of February 2024, the complete list of target websites/chat-sites involved in this operation has not been released by any government; however, the primary targets appeared to be the following: Baby Heart, Hurt-meh, Boyvids 4.0, Anjos Prohibidos (BR)/Forbidden Angels, and Loli Lust. Court documents have indicated that there were at least two other websites/chat-sites that were targeted; however, the names of the websites/chat-sites have not been made public. For information on the named operations associated with the searches, seizures, prosecution, and litigation of the leads generated from Operation Lobos 1, see the country specific summary below.
Investigative history The multinational joint investigation (Operation BabyHeart) that led to Operation Lobos was started as early as August 2015, when the Onion Service Bulletin Board Baby-Heart was originally brought online.
October 2016 Sworn testimony by HSI agent Greg Squire states that the U.S. joined the joint investigation at this time. Describing it as HSI Boston, HSI Philadelphia, and law enforcement abroad. March 2017, Australian Police purportedly relayed information to Portugal's Judiciary cybercrime unit "UNC3T." May 2017, Australian police sent UNC3T more information obtained from the arrest and seizure of another suspect in Australia. May 2017 HSI Special Agent Greg Squire conducted four searches in California in connection with Operation Babyheart. The tip was provided by a foreign law enforcement agency after the arrest (believed to be associated with the Portugal and Brazil arrest only 2 months prior) which led to 4 arrests. Leading up to 20 June 2017, collaboration with the United States Immigration and Customs Enforcement provided criminal intelligence analysis by their experts, along with Europol and Interpol. 20 June 2017, two of the board's administrators (Twinkle aka XXX and Forgotten) were arrested in Portugal and later sentenced on 23 January 2020. Twinkle was caught "in the act" of producing CSAM, and he then assisted the Portuguese law enforcement in apprehending Forgotten. The arrest of Twinkle and Forgotten preceded the arrest and criminal complaint against another Baby Heart site administrator located in Recife/Pernambuco State (PE) of Brazil. This website administrator in Recife purportedly yielded an "award winning collaboration agreement/plea-deal" with the Brazilian Federal Public Prosecutor's Office, also known as the Ministerio Publico Federal (MPF). The administrator turned informant alleged to have an important relationship through the Tor web with the administrator of the Baby Heart Tor onion service (and other onion services). The existence and importance of the information about the Target Website server administrator were allegedly verified between the Brazilian MPF and the United States Federal Bureau of Investigation (FBI). At the time, the FBI alleged that this one person was maintaining 70% of all CSAM content on the Tor Network. Fact-checking this statistic makes the statement of 70% improbable or misleading, as multiple press releases published subsequently, during, and after the operation of those specific onion services indicated numbers greater than 30% for any given set of services. An example is the statistical information provided by the U.S. government about the Korean site "Welcome to Video" (see Welcome to Video case). Most of what is known about the operation was gathered as a result of Portuguese and later Brazilian authorities conducting press conferences and issuing press releases boasting about their success and participation in what Brazilian authorities described as an "unprecedented" joint operation with the United States (US) Federal Bureau of Investigation (FBI) and the United Kingdom's (UK) National Crime Agency (NCA).
Methods
Initial investigation One tool used was Europol's Trace an Object (objects, backgrounds, and garments identified on the net in child abuse) with photos from social networks. Another tool used to identify suspects was Portugal's Polícia Judiciária Scientific Police Force (LPC) by creating palmar impressions from the images, which included a view of the suspect's hands (the suspects never showed their faces in the uploaded images). An arrest of one of the onion service administrators from Recife/PE, Brazil, yielded a plea deal whereby the administrator would act as an informant to obtain information about the server administrator.
The operation start Under the terms of a judicially authorized warrant and through the information obtained from the informant, the Brazilian authorities worked with the FBI to obtain the Internet Protocol (IP) address for the server. A subpoena to the Internet Service Provider (ISP) associated with the suspect IP address was issued, and the ISP provided the physical street address and account information associated with the IP address. The physical address, also known as the target address given, was an address in Recife, PE, Brazil.
First traffic interception and analysis A warrant was granted to intercept the data stream between the ISP and the suspect's target physical address. The intercepted data was monitored with support from the United Kingdom's National Crime Agency (NCA) as part of Project Habitance. They confirmed that 85.53% of the internet traffic corresponded to TOR traffic. The fact that 374 terabytes (PB) of data flowed through the connection for the duration of the analysis gave law enforcement the suspicion that the target was a TOR server node or Tor relay node.
Judicial authorizations from first interception The information obtained from the first period of data interception was used to obtain an additional series of warrants.
… excerpt ends here. Continue reading the full article.

