2026-07-04

ALERT: Phishing Wave Targets Nexus Market — Verify Before You Click

BY XU LIANG // Intel
ALERT: Phishing Wave Targets Nexus Market — Verify Before You Click

Security researchers have identified a coordinated phishing campaign impersonating Nexus Market, one of the more active darknet marketplaces currently operating on the Tor network. The campaign, which escalated over the past week, uses fraudulent mirror links and cloned login pages designed to capture user credentials and cryptocurrency deposits. According to analysts tracking the campaign, dozens of spoofed domains have appeared since the wave began, with new variants surfacing daily.

How the Campaign Operates

The phishing operation relies on links distributed through forum posts, direct messages, and search engine advertisements that mimic legitimate Nexus Market URLs. Users who click the links are redirected to near-identical copies of the marketplace’s interface, where entering a username and password transmits the credentials directly to operators of the scam. Some variants go further, requesting a cryptocurrency deposit during a fake “verification” step before allowing access to the marketplace.

Researchers note that the cloned pages replicate the layout, vendor listings, and even the support ticket system used by the real Nexus Market. The level of fidelity suggests operators had sustained access to design assets or scraped the marketplace repeatedly over time. Several of the spoofed domains resolve through bulletproof hosting providers commonly associated with other darknet-related fraud, according to infrastructure analysis shared by independent investigators.

Background on Nexus Market and Phishing Risk

Nexus Market operates as a Tor-hidden service and has positioned itself among a smaller set of active darknet marketplaces following the takedowns and exit scams that reduced the field over the past several years. Like other markets in its category, Nexus facilitates listings spanning controlled substances, fraud-related services, and digital goods, operating primarily on Monero and Bitcoin rails. Its continued operation depends on a distributed infrastructure of mirrors and rotating onion addresses that legitimate users must track carefully.

Phishing has long been the dominant attack vector against darknet market users. The 2022 takedown of Hydra Market, once the largest Russian-language darknet platform, displaced millions of users toward successor markets and created an opening for large-scale impersonation schemes. Similar waves followed the closures of other major platforms, with scammers registering lookalike domains within hours of seizure announcements. The current campaign targeting Nexus fits a familiar pattern observed across multiple marketplace lifecycles.

Verification Steps for Users

Security researchers recommend several precautions for anyone attempting to access Nexus Market. PGP-signed mirror lists published by verified vendor accounts remain the most reliable method for confirming legitimate URLs. Users should never trust links shared in unverified channels, including Telegram groups, Reddit threads, or search engine results, all of which have been used to distribute phishing links during this campaign.

Browser-based warnings about certificate errors, unexpected captcha behavior, or prompts for additional cryptocurrency deposits outside the normal escrow flow are common indicators of a spoofed page. Researchers also advise against reusing passwords across darknet services and recommend hardware-based two-factor authentication where supported. Several community-run verification portals have published updated lists of confirmed mirrors and flagged known phishing domains since the campaign began.

Community Response and What to Watch

Forum moderators on darknet-focused communities have pinned warnings about the campaign and are removing posts containing suspect links. Some vendors on Nexus have updated their profile pages with PGP-signed notices directing customers to verified mirrors only. Independent researchers continue to monitor the infrastructure behind the campaign and have signaled that additional takedown requests are pending with hosting providers and domain registrars.

The campaign’s scale and persistence suggest it will continue evolving, with operators likely rotating domains and adjusting tactics as identified pages are removed. Users who suspect they have entered credentials on a phishing site should treat associated cryptocurrency wallets as compromised and move funds immediately. As long as active darknet markets draw new users, phishing operations targeting those marketplaces are expected to remain a persistent threat.

Submit Response

REQUIRED FIELDS ARE MARKED *

Tor List – Darknet Markets

LAST REVIEWED: 2026-09-17
Research Disclaimer

This directory is provided strictly for informational and research purposes. DarkScope does not host, operate, or maintain any marketplace. No links on this site lead to illegal content. All .onion addresses are presented as redacted reference data for academic and journalistic research into darknet infrastructure patterns.

Notice

This archive provides no direct links to illegal services, does not facilitate any transactions of any kind, and does not enable access to listed platforms. Address tokens are placeholders for verification reference only. Users are solely responsible for their own actions and jurisdictional compliance.

TOR LIST - DARKNET MARKETS // VERIFICATION ARCHIVE // 2026