News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

DNMLinks.org is Serving Reverse Proxies, Not Mirrors | Major Phishing Risk : ImpactMarket | Torhoo darknet markets

We’ve come across a site: https://dnmlinks.org/ that's hosting multiple marketplace URLs, similar to what tor.run and tor.watch do. But here’s the catch the links on this site aren’t just simple mirrors. They’re acting as reverse proxies, which means they forward traffic to real markets without replicating the whole site. Instead, they intercept and route all your traffic directly to the legit backend.

Sounds harmless? It’s not. A reverse proxy can see everything you send usernames, passwords, messages all in plain text.

Shoutout to https://torhoo.cc/go.php?u=TDNVdmNYVmhjbXM9# for catching this we were already drafting a warning when his post went up. Crazy timing. These proxy based attacks are sneaky and hard to detect, especially when the setup closely mimics legit infrastructure. Props to https://torhoo.cc/go.php?u=TDNVdmFHVnJkRzl5# as well, who’s been fighting phishers with his self signed cert detection method.

We’re actively working on a security update to help guard against these stealthy but low effort attack vectors. In the meantime, protect yourself:

  • Enable 2FA on your accounts
  • Add your PGP key to your profile


That’s your best defense for now. Stay sharp and stay safe.

We have researched and found multiple market phishing links there, we are not the only ones!

https://torhoo.cc/go.php?u=TDJRdllXSmhZM1Z6YldGeWEyVjA=# - https://torhoo.cc/go.php?u=TDNVdlZtbDBidz09#
https://torhoo.cc/go.php?u=TDJRdlFteGhZMnRQY0hNPQ==# - https://torhoo.cc/go.php?u=TDNVdlFteGhZMnREWld4cw==#
https://torhoo.cc/go.php?u=TDJRdmIyMWxaMkU9# - https://torhoo.cc/go.php?u=TDNVdmNYVmhjbXM9#
https://torhoo.cc/go.php?u=TDJRdmFXMXdZV04wYldGeWEyVjA=# - https://torhoo.cc/go.php?u=TDNVdlNXMXdZV04wVFdGeWEyVjA=#
https://torhoo.cc/go.php?u=TDJRdlJHRnlhMDFoZEhSbGNrMWhjbXRsZEE9PQ==# - https://torhoo.cc/go.php?u=TDNVdmNYVmhjMkZ5TVE9PQ==#
https://torhoo.cc/go.php?u=TDJRdlJXeDVjMmwxYlUxaGNtdGxkQT09# - https://torhoo.cc/go.php?u=TDNVdlJXeDVjMmwxYlUxaGNtdGxkQT09#
https://torhoo.cc/go.php?u=TDJRdmNISnBiV1Z0WVhKclpYUT0=# - https://torhoo.cc/go.php?u=TDNVdllXTmw=#
https://torhoo.cc/go.php?u=TDJRdlpXMWhjblE9# - https://torhoo.cc/go.php?u=TDNVdlpXMWZZbXgxWlE9PQ==#
https://torhoo.cc/go.php?u=TDJRdlRXRnljMDFoY210bGRDOD0=# - https://torhoo.cc/go.php?u=TDNVdlQyeGxaMDFoY25NPQ==#
https://torhoo.cc/go.php?u=TDJRdlFYZGhlbTl1VFdGeWEyVjA=# - https://torhoo.cc/go.php?u=TDNVdlFYZGhlbTl1#
/u/coincidencedetector
2 points
1 month ago
Why do you post this and ping the entire DNM landscape like this was a groundbreaking discovery?
This is a years old technique.
We are raising awareness that their sites are being targeted by phishing attacks, and thanks to this post, at least our marketplace phishing url has been taken down.
/u/treblex
1 points
1 month ago
2fa can still be bypassed by mitm proxy as the customer provide the pgp authentication code too.
You need some sort of "fill the missing characters from the onion link" captcha type with pgp signed message to authenticate the onion and warning if the link doesn't match the address bar to exit.
/u/coincidencedetector
1 points
1 month ago
That's why ASNT didn't add a 2FA code but a 2FA link with a real mirror.
/u/treblex
1 points
1 month ago
and it all comes down to the moment when the customer need to have the market's pgp pre-saved. Unfortunately all customers are lazy to do so, that is why they rely on index pages like tortaxi and similar to obtain their links.
/u/Hektor
1 points
1 month ago
There are no vortex links i see
Yes, and I'm glad you are somewhat safe from these types of attacks thanks to your forced ssl forwarding as it redirects anyway which makes reverse proxy attacks ineffective. Until they start to running their own ssl connection.
/u/Hektor
1 points
1 month ago
Is not that. Found the links btw, all the job is done by antiphishing code, ssl just helps getting better refs
Understood, I would say your setup is solid.
/u/TorDotRun
1 points
1 month ago
this phishing technique isn’t new very familiar sites exist: https://torfish.net/, https://dakr.fail doing similar stunts
Yes, I agree with your point. These types of attacks are not new, and there is no single straightforward solution for reverse proxy based phishing attacks. Users need to be more cautious that’s the only effective countermeasure at this point.
/u/Hektor
1 points
1 month ago
torfish right now is the only one still working for vortex, it will last 2 more days probably till i block again. Search any vortex phishing to find a surprise (try getting to login)
Enabled anti-phishing to fight these mf.
/u/Hektor
2 points
1 week ago
2FA is useless against MITM phishing.
Yes! These guys are so useless, it's unbelievable.
/u/Hektor
0 points
1 week ago
Update for Vortex, no more working links exist since weeks.
Btw, we’ve also introduced a new system to detect phishing urls. Check it whenever you have time.
/u/Hektor
1 points
1 week ago
Send me a phishing link of impact in messages if you have one