
In part one of this article we covered the following points:
- What is a mirror? Why create mirror sites?
- How do you spot mirror sites?
- What are the mirrors for?
- A closer look at how mirror sites evolved
Several possible hypotheses
The most likely hypothesis is impersonation: the mirrors would have been created by someone outside the original sites. By making copies on their own account, the impostor can harvest the logins and passwords of users who believe they are signing in to the genuine site. Where a marketplace is impersonated, the impostor can even collect payment for transactions made on the decoy site.
In 2019, someone who had created more than 800 decoys boasted of having made over 200 bitcoin — around 1.5 million euros at the time — using this technique. They revealed the fraud on the home page of their decoy sites before disappearing.

A large share of the mirrors on the dark web are therefore, very probably, the work of one or more impostors. This proliferation of decoy mirrors is a concern for the dark web’s various directories: to be visible and reachable, those decoys need to be listed on the sites that catalogue dark web domains. Some directories therefore try to put strategies in place to identify booby-trapped sites and stop listing them. Some go on intuition, others on user feedback through voting.

Example of an assessment based on intuition

Example of an assessment based on votes
Real or fake Scam List of Tor?
In November 2018, an internet user who had been defrauded six times by decoy mirrors set about building a blacklist of impersonating sites. The site, called Scam List Of Tor, lets users report suspicious sites (‘Submit a scam site’). Users can also clear sites wrongly added to the blacklist (‘Report false listing’).

The initiative did not go unnoticed by the makers of booby-trapped sites. A year later, the first malicious mirror of Scam List Of Tor appeared. As the creator of the original site points out on his page, the fraudsters copied his site but added an extra section: verified sites. That section, supposedly listing trustworthy sites, redirects users to decoys.

Since then the site has been replicated 1,440 times over, every copy malicious. As a final refinement, whoever created these dark web ‘tourist traps’ took the trouble this time to have a large share of their sites reference one another, creating the illusion of greater credibility. A user wanting to check the site’s authenticity might well be tempted to cross-check several versions of Scam List Of Tor. Since the decoys reference each other, the user is caught as in a spider’s web. In a sense, this is an inverted web of trust.
The networks of fake Scam List of Tor
The graph below illustrates both the persistence of the makers of malicious mirrors (the red circles) and the relative weight of the original site (the blue triangle). We can see two heavily interconnected networks and three smaller ones. On the largest network, four nodes act as references — their size is proportional to the number of links pointing to them.
Here we see the irony at work on the dark web. Not only is a large part of its total mass made up of sites defrauding people who believe they can carry out fraudulent operations in complete confidence, but the sites meant to expose the deception are themselves impersonated. None of which should obscure how real and serious another part of the dark web is. Alongside these mirrors, several thousand sites remain — a substantial volume, which we will survey shortly.

Interconnected decoy mirrors