How a fake mirror works

The target is your password, and everything you deposit while you believe you are home. The weapon is fifty six lowercase characters in an address bar, where one wrong letter is a different site and the difference is invisible at reading speed.

Mirror addresses · 3

same market · no ranking
ONIONtail dpsdad
blackops27m32abqvbhnyswgazqawxqbznbzkkkv5sjo7gve2ndpsdad.onion
ONIONtail r67hid
blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion
ONIONtail ak4dqd
blackops6kignp3eddmvqcfkjzf6qr6haxbmkypc2xtqlnhuu4ak4dqd.onion

Copy one address, paste it into the Tor Browser, and compare the last six characters against what landed in the address bar. If one will not connect, build a new circuit and take the next. Why an onion refuses to load.

Five patterns, all real

The market runs a public list of confirmed phishing addresses on its Dread board, updated as they are caught. The patterns it documents, in order of how often they appear:

  1. The impostor prefix. blackopy instead of blackops. Letter seven, one character, the eye never goes back to check. It is the pattern that gets the most first logins.
  2. The character swap with a wrong tail. A real prefix, one letter changed in the middle, and the ending is .xyz instead of .onion. The middle change hides in the noise; the ending is the whole tell, and it takes one glance to see.
  3. Nothing recognizable at all. A valid 56 character address that shares nothing with the market. These work by being presented, not by being believed: a link you were sent, a "temporary" address during "maintenance," a re verification page.
  4. The clearnet twin. A normal website, .org or .net or .taxi, wearing the market's name and its login page. It can render the market pixel for pixel, because it is the market, proxied through a machine that keeps a copy of everything you type.
  5. The link directory. A site whose entire product is "verified" links. Some are honest, some are the scam, and the scam ones are placed where the honest ones gave the whole page its credibility.

The reverse proxy, in one paragraph

The advanced version does not build a fake page. It sits between you and the real market and forwards your traffic, reading it on the way. Every element you see is the real element. The captcha is real. The login form is real. Your password reaches the real market, so the login succeeds, which is the confirmation the scam needs. The only thing that is not real is the address in your bar, and the proxy cannot reach it, because it is not part of the page. This is why the address check is not a paranoid ritual. It is the only check the design of the scam leaves open.

How a fake reaches you

Notice what none of these are: the characters. A link you were handed is never evidence. A badge is never evidence. The 56 characters are the only evidence, and they cost ten seconds to read.

The checklist

Before every login, once, at the start. After that it runs on autopilot in about ten seconds.

  1. Count is 56. Nothing more, nothing less, before the dot.
  2. It ends in .onion. Nothing else qualifies.
  3. It starts with blackops. Check letter seven out loud.
  4. The last six characters match the list above. Read them, do not scan them.
  5. A person or a message sent you here? Verify anyway. The sender was phished too, and they are now a delivery channel.
Found one?

The market's Dread board is where confirmed fakes are posted, and a PGP message to support is where the unconfirmed ones go. A fake that is reported becomes a line in the list, and the list is what the next person finds first.

And the uncomfortable corollary, stated plainly: every mirror directory, including the careful ones, is a surface a phisher wants. The pages that list addresses are the pages that rank for "blackops market link." That is the business, and it is why the check lives in your hands and not in the list. The signature check adds a second layer that a directory, honest or not, cannot fake by itself.