Traps / Dossier 11 of 57

A domain that hosts a fake nexus market login

The wrong host under the right form

Nexus market mirrors, as published on this site

nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion

Published as supplied. This site does not probe an onion, so nothing here is a claim that a given address opens for you right now.

This is the dossier for the nexus market login trap where a page on a domain other than the real market presents a form dressed as the market login, and the credentials go somewhere else.

What it is

A nexus market login is a page on the onion the reader trusts. It is not a page on any other host. A page on any other host that draws itself as the market login is a copy of the layout without the underlying account system, so the credentials the reader enters land in the log of whoever runs the host, not in the account system of the market. The trap works because a login page is a small layout the eye recognises quickly.

The layout can be copied down to the last pixel. The wordmark can be lifted. The form field labels can be lifted. The captcha widget can be a working captcha widget that solves fine on the wrong host. The only field the trap cannot lift is the host itself, and the host is not a field on the form at all. It is the address bar above the form.

Where the domain comes from

A search for the phrase nexus market login is one origin. A short domain at the top of the results, with a landing page shaped like the market entrance, is a page a hurried reader may click. A short link in a chat message is the second, when the link was sent by a stranger or by a compromised friend.

A bookmark saved from a browsing session where the reader was not paying attention is the third. The bookmark now looks like the correct one. The saved address is the wrong one. The reader clicks the bookmark, sees the layout they remember and enters the credentials without a second thought.

Lifeline

  1. A layout copied from the real login
  2. A form served on the wrong host
  3. A login entered on the onion instead

How to catch it

The catch is a check of the address bar before the form is touched. A real nexus market login sits behind one of three onion strings this site publishes. The address bar shows those characters and ends with .onion. Any address bar that shows anything else is not the market login, no matter how the page below the bar is drawn. The layout below the bar is a persuasion tool. The address bar is the ground truth.

On the address bar
Read the whole string in the address bar. A .onion suffix that matches one of the three on the panel above is the market. Any other address is not.
On the form
A form on the correct login does not ask for information the real login does not ask for. A form that asks for extra fields is a form to walk away from.
On the URL of a click
Hover the click target and read the address the click will send you to. If the address does not match what the anchor promises, the anchor is not what it says.

What this card does not claim

  • It does not list any domain that has hosted this class of page. Naming one would send readers to it.
  • It does not say every fake login is a phishing page. Some are cache pages, some are proxies, some are old broken copies. None of them is the real login.
  • It does not say two factor makes the trap harmless. Two factor is a signal card, not a lock against a fake page.

The address bar as the check

The address bar is the check for this trap because the address bar is the field the trap cannot dress. The layout below can be identical. The wordmark above can be identical. The captcha in the middle can be identical. The address bar contains the ground truth, and the reader who has read the address bar has done the check.

The wordmark as bait

The wordmark of the market is the piece of the page most likely to be lifted onto a fake login. It is a small image, easy to save from the real page and easy to drop into any layout. A reader who recognises the wordmark on a fake page recognises it because the wordmark is real. What is not real is the page around it. The wordmark is not by itself a check on the identity of the host.

Every visual signal on the real market can be lifted the same way. The captcha, the layout of the form, the exact colour of the button, the exact wording of the labels. None of these signals catches this trap on its own. The address bar is the field that cannot be lifted, because the address bar is the browser reading the host.

A form the reader closes first

The safest response to a login form the reader is not sure about is to close the form before typing anything into it. The credentials cannot go anywhere if they are not typed. A reader who has closed a suspect form has spent nothing. A reader who has typed and pressed return may have lost the account before the return trip completes.

A reader who is closing a suspect form and wants to reach the real login can copy any of the three nexus market addresses from the panel above, open the tor browser fresh and paste. The panel above is a clean starting point that is not on a login form and cannot ask for credentials. That is why the panel above is on every page here.

Engagement

3onions on the panel where the real login lives
0clearnet domains this site treats as the login
1address bar to read before the form is touched
3related dossiers on this trap

Discover more

Every dossier on nexusmirrors.store