2026-06-18

Torzon Phishing Wave Targets Users with Fake Mirrors — Security Researchers Issue Warning

BY TOMAS WIDER // Intel
Torzon Phishing Wave Targets Users with Fake Mirrors — Security Researchers Issue Warning

Security researchers monitoring darknet infrastructure have identified a coordinated phishing campaign targeting users of Torzon Market, with dozens of counterfeit mirror domains appearing across Tor and the clearnet since early June 2026. According to analysts tracking the activity, the fake mirrors are designed to harvest login credentials, mnemonic phrases, and cryptocurrency deposits from users attempting to access the marketplace through unofficial links.

The campaign was first flagged on June 11, 2026, when researchers at TorNews documented an unusual spike in domain registrations mimicking Torzon’s branding. Within 72 hours, more than 40 phishing domains had been identified, with new variants appearing daily. The scale of the operation suggests an organized effort rather than opportunistic copycats, according to the researchers.

How the Fake Mirrors Operate

The phishing sites replicate Torzon’s visual layout with high fidelity, including product categories, vendor listings, and search interfaces. Researchers note that several mirrors include working captchas and PGP verification prompts, features typically associated with legitimate darknet markets. The added polish is intended to lower user suspicion during the login process.

Once a victim enters credentials, the fake mirror either displays a generic error message or silently redirects to the genuine Torzon URL, creating the impression that the initial failure was a routine connectivity issue. In parallel, several identified mirrors request a 12-word recovery phrase under the pretext of “session verification,” a tactic that allows operators to drain associated wallets before the user realizes the compromise.

Background on Torzon and Mirror-Based Attacks

Torzon Market emerged in late 2024 as a mid-tier marketplace specializing in digital goods and software, according to historical listings tracked by Tor List. Like other darknet markets, it relies on rotating onion mirrors to maintain availability during DDoS attacks and law enforcement seizures. The practice of publishing mirror lists through third-party directories has long been exploited by phishing operators.

Mirror-based phishing is not unique to Torzon. In 2025, similar campaigns targeted users of Nexus and DrugHub, with researchers documenting hundreds of fake domains impersonating those platforms. DarkMatter, another marketplace active during that period, also saw its branding weaponized in credential-harvesting schemes. The recurring pattern indicates that phishing operators view marketplace impersonation as a scalable, low-cost attack vector.

Identifying Legitimate Mirrors

Researchers recommend several verification steps before entering credentials on any Torzon-related domain. First, users should obtain mirror links exclusively from Torzon’s signed vendor announcements or from directories that verify PGP-signed mirror lists. Unsolicited links shared on forums, Telegram channels, or search engines should be treated as suspect.

Second, the PGP key fingerprint associated with the marketplace should be cross-checked against multiple independent sources. Legitimate operators publish consistent fingerprints across their communications; mismatches are a strong indicator of impersonation. Third, users should avoid entering recovery phrases or private keys on any web form, since legitimate markets do not require this information for routine access.

Community Response and Ongoing Monitoring

Torzon’s verified administrator account posted a brief advisory on June 12, 2026, acknowledging the campaign and urging users to verify mirrors through the platform’s signed announcement channel. The post did not estimate the number of compromised accounts but confirmed that the marketplace had rotated its primary mirror infrastructure in response.

Independent analysts continue to track new phishing domains, with several hundred additional variants under observation as of June 13, 2026. Researchers emphasize that the campaign’s scale and technical sophistication suggest it will persist for weeks, particularly as long as users continue to click on unverified links. Community-run blocklists have begun incorporating the identified domains, though the operators behind the campaign are expected to rotate infrastructure as quickly as it is flagged.

What to Watch Next

Security researchers expect the phishing operators to expand their targeting to adjacent marketplaces, including Nexus and DrugHub, as Torzon users become more cautious. The use of signed mirror verification is likely to face renewed scrutiny, with some analysts calling for marketplaces to adopt hardware-based authentication or on-chain mirror attestation to reduce reliance on PGP-signed announcements.

For users, the immediate priority is verifying any Torzon link currently in use against the platform’s official PGP-signed mirror list and rotating credentials if exposure is suspected. Cryptocurrency deposits made to any unverified mirror should be considered compromised, and associated wallets should be treated as burned.

Submit Response

REQUIRED FIELDS ARE MARKED *

Tor List – Darknet Markets

LAST REVIEWED: 2026-09-17
Research Disclaimer

This directory is provided strictly for informational and research purposes. DarkScope does not host, operate, or maintain any marketplace. No links on this site lead to illegal content. All .onion addresses are presented as redacted reference data for academic and journalistic research into darknet infrastructure patterns.

Notice

This archive provides no direct links to illegal services, does not facilitate any transactions of any kind, and does not enable access to listed platforms. Address tokens are placeholders for verification reference only. Users are solely responsible for their own actions and jurisdictional compliance.

TOR LIST - DARKNET MARKETS // VERIFICATION ARCHIVE // 2026