June 2026 Torzon Phishing Spike
Coordinated lookalike domains and fake mirrors targeting Torzon users. How the campaign behaves and how to refuse it.
From early June 2026, infrastructure monitors described a sharp rise in domains and onions mimicking Torzon branding. Reporting around mid-June put newly spotted lookalikes in the dozens within days — enough to treat as an organized wave, not one-off typos.
Attack pattern
- Clearnet domains that only exist to push a “working onion”
- Onions that differ by one or two characters from a real mirror
- Login pages that harvest passwords, then redirect or sit idle
- Secondary forms asking for seeds, “wallet repair,” or 2FA reset codes
Defense that scales
- Compare against this directory’s Torzon list
- Confirm the anti-phishing phrase you set on a previously verified session
- Ignore DM “new mirrors” and search ads
- Assume any “urgent migration” story after downtime is hostile until proven
Same wave logic applies to Nexus branding — see brand phishing overview.