Directory online · July 2026 Mirrors listed under Markets

June 2026 Torzon Phishing Spike

Coordinated lookalike domains and fake mirrors targeting Torzon users. How the campaign behaves and how to refuse it.

From early June 2026, infrastructure monitors described a sharp rise in domains and onions mimicking Torzon branding. Reporting around mid-June put newly spotted lookalikes in the dozens within days — enough to treat as an organized wave, not one-off typos.

Attack pattern

  • Clearnet domains that only exist to push a “working onion”
  • Onions that differ by one or two characters from a real mirror
  • Login pages that harvest passwords, then redirect or sit idle
  • Secondary forms asking for seeds, “wallet repair,” or 2FA reset codes

Defense that scales

  1. Compare against this directory’s Torzon list
  2. Confirm the anti-phishing phrase you set on a previously verified session
  3. Ignore DM “new mirrors” and search ads
  4. Assume any “urgent migration” story after downtime is hostile until proven

Same wave logic applies to Nexus branding — see brand phishing overview.