2026-06-22

ALERT: Drughub Market Phishing Campaign Targets Users — Protect Your Crypto Now

BY RAJAN MEHTA // Intel
ALERT: Drughub Market Phishing Campaign Targets Users — Protect Your Crypto Now

Security researchers identified an active phishing campaign on June 12, 2026, impersonating Drughub Market, one of the better-known storefronts on the Tor network. The campaign uses cloned login pages and mirror domains to harvest cryptocurrency deposits and account credentials from buyers and vendors, according to alerts circulated by darknet-focused threat intelligence feeds.

How the Campaign Operates

The fraudulent infrastructure relies on onion mirror addresses that differ by only a single character from the genuine Drughub URL. Researchers tracking the campaign report that the cloned interfaces replicate the market’s vendor listings, escrow flow, and support ticket system with enough fidelity to pass a casual inspection. Once a user enters credentials or initiates a deposit, the site captures the input and either forwards the funds to attacker-controlled wallets or sells the credentials on secondary markets.

Several of the phishing mirrors also distribute a fake “security update” prompt that requests a user’s two-factor authentication seed. According to the alerts, victims who comply lose access to their accounts within minutes. Researchers note that the campaign’s wallet infrastructure has received at least 4.2 BTC across the addresses tracked so far, though the true figure is likely higher given address rotation.

Background on Darknet Phishing Tactics

Phishing on the dark web has long mirrored techniques used on the clear web, but with higher stakes and fewer recourse options for victims. Common variants include counterfeit exchanges promising favorable rates, fake wallet services that harvest seed phrases, and impersonation pages for markets that have been seized or relocated. The H25 darknet fraud guide published on June 10, 2026, catalogs these patterns and warns that scammers frequently cycle domains after takedowns, re-registering under similar names within hours.

Drughub itself has gone through multiple address changes since its emergence, a pattern common among long-running markets alongside DarkMatter, Nexus, and Torzon Market. Each migration creates an opening for operators of phishing kits, who register lookalike addresses before the community migrates en masse. Researchers describe this as a “land grab” period that typically lasts 72 hours after any official address announcement.

Community Reaction and Researcher Guidance

Threat analysts have urged users to verify any Drughub address through at least three independent sources before logging in, including PGP-signed announcements from known vendor accounts and community-maintained directory mirrors. The recommendation echoes broader guidance from security firms: hardware wallets such as Ledger or Trezor should hold any balance not actively in trade, and seed phrases should never be entered into any web form regardless of how legitimate the page appears.

Forum moderators on several English-language darknet discussion boards have begun pinning warnings and removing posts that reference the suspect mirrors. According to one moderator post reviewed by researchers, the campaign appears to have peaked between June 11 and June 13, 2026, with new mirror registrations tapering off as registrar-level takedown notices propagate.

What Users Should Do Now

Anyone who has entered credentials into a Drughub-branded page since June 1, 2026 should treat the account as compromised. Recommended steps include moving remaining balances to a fresh wallet, rotating any API keys or PGP keys associated with vendor accounts, and reviewing transaction histories for unauthorized withdrawals. Two-factor seeds entered into any web form should be considered burned and reissued from the authenticator app rather than restored from backup.

Researchers continue to monitor the wallet clusters associated with the campaign and expect additional mirror domains to surface through the end of June. The episode fits a broader pattern observed across 2026, in which phishing operators have shifted focus from clear-web exchange users toward darknet market participants, where victims face additional barriers to reporting theft and recovering funds. Until the genuine Drughub operators publish a verified address through their established PGP-signed channels, the safest assumption is that any unsolicited link claiming to be the market is hostile.

Submit Response

REQUIRED FIELDS ARE MARKED *

Tor List – Darknet Markets

LAST REVIEWED: 2026-09-17
Research Disclaimer

This directory is provided strictly for informational and research purposes. DarkScope does not host, operate, or maintain any marketplace. No links on this site lead to illegal content. All .onion addresses are presented as redacted reference data for academic and journalistic research into darknet infrastructure patterns.

Notice

This archive provides no direct links to illegal services, does not facilitate any transactions of any kind, and does not enable access to listed platforms. Address tokens are placeholders for verification reference only. Users are solely responsible for their own actions and jurisdictional compliance.

TOR LIST - DARKNET MARKETS // VERIFICATION ARCHIVE // 2026