Full Report
What HappenedNemesis Dark Web Drug Dealers ArrestedOn 14 May 2026, two Cambridgeshire drug dealers were sentenced after being arrested in July 2024 by the Eastern Region Special Operations Unit (ERSOU).ERSOU officers recovered Royal Mail parcel labels, order lists, Gorgonites-branded packaging, and a USB memory stick containing login credentials for multiple dark web marketplace accounts.The dealers reportedly used the dark web to supply heroin, cocaine, and amphetamine to hundreds of users across the UK.The drug deals were initially arranged via a Telegram channel under the handle Gorgonites, which was linked to at least 570 individual sales on Nemesis Market since September 2023.AEGIS Dark Web Drug Market SeizureOn 17 March 2026, the London Metropolitan Police’s Cyber Crime Unit announced the seizure of AEGIS Marketplace.In June 2025, the Met Cyber Crime Unit became aware of AEGIS Marketplace, which was a site where individual sellers could market drugs for sale to users who could make purchases using cryptocurrency.By March 2026, the website had 30 active sellers and was estimated to have generated 10,000 drug sales in ten months, leading to an estimated annual turnover of almost £2 million.Officers from the Met managed to infiltrate the site, retrieving server data that led to the identification of administrators, sellers and customers.Online Killers Marketplace (OKM) Admins ArrestedOn 19 January 2026, two suspects were arrested in Romania as part of an ERSOU investigation into a bogus ‘harm-for-hire’ website which offered services including murder.The arrests were connected to a dark web scam website called Online Killers Marketplace (OKM), which purported to facilitate criminal activities including the hiring of hitmen and extortion.ERSOU noted that even though none of the services OKM offered were genuine, successful prosecutions have previously been pursued by police forces of individuals attempting to use it to cause harm to others.The investigation led to the seizure of US crypto currency worth at least $600,000, as well as cash which included almost €50,000 Euros, and around £48,000 worth of Romanian Leu.Analyst CommentThe anonymity and connectivity of encrypted messaging apps, the Tor network, cryptocurrency, and online marketplaces makes it nearly impossible to prevent such crime. However, law enforcement can achieve strategic containment by targeting specific infrastructure for seizure and individuals for arrest. These activities support the overall strategy for national law enforcement agencies is to deter criminals from being active in their country.Telegram is increasingly used as a front-end service for all sorts of cybercrime activities. As seen in the Nemesis investigation, the dealers operated a Telegram channel under the handle Gorgonites to coordinate and funnel buyers toward more secure transactions. It is an easy-to-use mobile application that makes access to such illicit services simple for buyers. It is more accessible than having to download the Tor browser and use a desktop or laptop browser. Many of these illicit services also would not exist without cryptocurrency. The ability to send funds via peer-to-peer networks and obfuscate transactions continues to be the main enabling factor for most cybercrime operations. Interestingly, the sole administrator of Nemesis Market was sanctioned in March 2025 by the US Treasury OFAC department. The admin was an Iran-based individual named Behrouz Parsarad. Prior to its takedown by law enforcement in March 2024, Nemesis had over 30,000 active users and 1,000 vendors and facilitated the sale of nearly $30 million USD worth of drugs around the world between 2021 and 2024.Defensive TakeawaysBlockchain Analytics: While cryptocurrency provides a layer of perceived anonymity for illicit markets it also leaves a permanent, public ledger. Law enforcement and threat intelligence firms, such as TRM Labs and Chainalysis, can leverage blockchain analytics to follow the money and deanonymise the administrators. By mapping transaction inputs and outputs, investigators can trace mixed funds, identify exchanges used to cash out into fiat currency, and map the financial infrastructure of a marketplace.Breach Data Pivoting: To catch these cybercriminals, threat intelligence analysts can use historical breach data repositories to pivot from a known dark web alias or leaked credential to find a real-world identity. If an administrator used the same password or a variation of a username on a compromised gaming forum ten years ago, that footprint can blow their operational security (OPSEC).Profile Scraping: Dark web vendors and market admins often leave massive digital footprints across forums, marketplaces, and messaging apps like Telegram. Continuous profile scraping can be achieve via automated bots to collect vendor profiles, feedback ratings, PGP keys, styles of writing (stylometry), and active hours. By aggregating this data over time, defenders can create a comprehensive profile of a target and identify them.Dark Web Market Sock Puppet Accounts: Law enforcement and threat intelligence analysts can deploy sock puppets accounts, which are undercover, synthetic personas, into these dark web ecosystems. These accounts are kept for long periods of time and actively posting in an attempt to build trust within the cybercrime underground. Investigators can use them to buy products, interact with admins, and gain access to private vendor portals or escrow systems to support evidence gathering for a takedown.Infrastructure Analysis: As dark web markets rely on servers, hosting providers, DNS, and Tor is is possible to analyse these attributes and look for configuration mistakes. This can include exposed IP addresses, trackable X509 certificates, or open port banners that reveal the true location of a hidden service. Once a server's true IP is uncovered, law enforcement can issue subpoenas to hosting providers or execute physical raids to seize the hardware and unmask administrators, vendors, and buyer databases.Relevant Sourceshttps://www.rocu.police.uk/news/2026/may/dark-web-was-used-to-supply-heroin-and-cocaine-to-hundreds-of-users-across-uk/https://web.archive.org/web/20260320135505/https://news.met.police.uk/news/met-seizes-website-making-millions-in-drug-sales-507234https://www.rocu.police.uk/news/2026/january/dark-web-arrests-in-romania-linked-to-portal-which-offered-services-including-murder/Related CTI Sourceshttps://home.treasury.gov/news/press-releases/sb0040https://www.tripwire.com/state-of-security/notorious-nemesis-market-zapped-video-game-loving-german-police
Analysis Summary
# Incident Report: UK Cybercrime Journal H1 2026 Dark Web Takedowns
## Executive Summary
During the first half of 2026, UK and international law enforcement agencies executed a series of high-profile takedowns targeting dark web marketplaces and vendors, including Nemesis Market, AEGIS, and Online Killers Marketplace (OKM). These operations resulted in the seizure of illicit digital infrastructure, the recovery of significant cryptocurrency assets, and the sentencing of key drug traffickers. The actions demonstrate a strategic shift toward targeting the intersection of encrypted messaging apps (Telegram) and dark web financial infrastructure.
## Incident Details
- **Discovery Date:** Multiple (June 2025 for AEGIS; investigations ongoing since 2021 for Nemesis)
- **Incident Date:** Takedowns and arrests spanning January 2026 – May 2026
- **Affected Organization:** Multiple Dark Web Entities (Nemesis, AEGIS, OKM)
- **Sector:** Cybercrime / Illicit Marketplaces
- **Geography:** United Kingdom, Romania, and Iran (Administrator location)
## Timeline of Events
### Initial Access
- **Date/Time:** 2021 – 2023 (Initial establishment of marketplaces)
- **Vector:** Use of Tor hidden services (.onion sites) and Telegram channels (e.g., Gorgonites handle).
- **Details:** Criminals leveraged the anonymity of the Tor network and the accessibility of Telegram to funnel users toward drug exchanges and fraudulent "harm-for-hire" services.
### Lateral Movement
- **N/A:** As this involves law enforcement infiltration rather than a corporate breach, movement refers to police "infiltrating" the AEGIS site to retrieve server data.
### Data Exfiltration/Impact
- **AEGIS:** Retrieval of server data by Met Police identifying admins, 30 sellers, and customers.
- **Nemesis:** Seizure of physical USB sticks containing login credentials for multiple dark web accounts.
- **OKM:** Exposure of a scam operation involving "murder-for-hire" services.
### Detection & Response
- **January 19, 2026:** Arrest of two suspects in Romania for the OKM scam site.
- **March 17, 2026:** London Met Police announce the total seizure of AEGIS Marketplace.
- **May 14, 2026:** Sentencing of "Gorgonites" dealers (initially arrested July 2024).
## Attack Methodology
- **Initial Access:** Marketing illicit goods via Telegram/Tor to reach buyers.
- **Persistence:** Use of decentralized hosting and rotating cryptocurrency wallets.
- **Defense Evasion:** Use of cryptocurrency (mixing/obfuscating transactions) and the Tor network.
- **Credential Access:** Dealers utilized a USB memory stick to store and manage credentials for various marketplaces.
- **Lateral Movement:** Pivot from Telegram "front-end" channels to "secure" back-end dark web marketplaces.
- **Impact:** Facilitation of drug sales, extortion, and fraudulent hitman services.
## Impact Assessment
- **Financial:** AEGIS generated ~£2M annual turnover; Nemesis facilitated ~$30M USD in sales; OKM seizure included $600k in crypto and ~£90k in cash.
- **Data Breach:** Compromise of admin, vendor, and buyer databases by law enforcement.
- **Operational:** Marketplaces were permanently offline (seized).
- **Reputational:** Deterrence established through public sentencing and international cooperation.
## Indicators of Compromise
- **Network Indicators:** Telegram handle: Gorgonites; Nemesis Market infrastructure.
- **File Indicators:** USB memory stick containing marketplace credentials.
- **Behavioral:** High-volume cryptocurrency transactions; use of Royal Mail for illicit logistics; Gorgonites-branded packaging.
## Response Actions
- **Containment:** Website seizures (AEGIS) and server data retrieval.
- **Eradication:** Arrests of administrators in Romania and vendors in the UK.
- **Recovery:** US Treasury OFAC sanctions placed on Nemesis administrator (Behrouz Parsarad) to prevent further financial activity.
## Lessons Learned
- **Telegram Vulnerability:** Telegram is increasingly used as an easy-access gateway for cybercrime, bridging the gap between the surface web and Tor.
- **OPSEC Failures:** Criminals often reuse credentials or aliases across platforms, allowing investigators to pivot from historical breach data to real-world identities.
- **False Anonymity:** While blockchain provides perceived anonymity, it is a permanent ledger that can be deanonymized via specialized analytics (e.g., TRM Labs).
## Recommendations
- **Blockchain Analytics:** Enhance use of toolsets to map mixed funds and identify fiat "cash-out" points at exchanges.
- **Infrastructure Fingerprinting:** Monitor for configuration mistakes (exposed IPs/X509 certificates) on hidden services.
- **Continuous Scraping:** Implement automated bots to track vendor PGP keys and stylometry to link identities across multiple marketplaces.
- **Deploy Synthetic Personas:** Utilize "sock puppet" accounts to gain long-term trust in private vendor portals and escrow systems.