| Category | Listings |
|---|---|
| Digital | 2,951 |
| Counterfeit | 2,871 |
| Stimulants | 1,174 |
| Benzos | 995 |
| Opioids | 974 |
| Cannabis & Hash | 678 |
| Ecstasy | 445 |
| Psychedelics | 333 |
| Dissociatives | 183 |
| Prescriptions | 158 |
| Steroids | 139 |
| Metals | 107 |
| Organ Trafficking | 37 |
Dark Web Market: Anubis Market
Anubis Market is a multi-category Dark Web marketplace operating as a Tor hidden service, with escrow-backed trading in Bitcoin (BTC) and Monero (XMR). Its visible category strip displays more than 11,000 listings, and while narcotics account for the largest share of physical goods, its Digital section is the single biggest category on the market. That section is what makes Anubis relevant to security teams: beneath it sit dedicated subcategories for stolen payment cards, bank drops, compromised accounts, stealer logs, identity documents, and cracked offensive tooling.
Overview
- Market Type: Multi-category darknet marketplace
- Access Model: Tor (onion) with rotating verified mirrors
- Languages: English
- Payment Methods: BTC, XMR, and an ETH swap that converts Ethereum into BTC or XMR
- Trust Model: Wallet escrow, 14-day auto-finalize, dispute system, 10-level vendor ranking
- Vendor Bond: USD 500 one-time fee, waivable for established vendors from other markets
- Notable Categories: Digital goods, counterfeits, fraud, hacking tools and services, personal information
- Monitoring Value: Credential and card exposure, identity fraud, cracked malware distribution, cross-market vendor tracking

Anubis Market home page
What Is a Dark Web Market?
A Dark Web market is an online marketplace reachable through anonymity-preserving networks such as Tor, hosting illegal goods and services outside the reach of conventional commercial oversight. These platforms settle transactions in cryptocurrency and reproduce the mechanics of legitimate e-commerce, including product categories, vendor profiles, buyer reviews, escrow, and dispute resolution, in order to build workable trust between parties who never identify themselves to one another.
For a wider view of the platforms operating in this space, see SOCRadar’s overview of the top Dark Web Markets.
A Note on the Anubis Name
The Anubis name is reused heavily across the threat landscape and the overlap causes frequent misattribution. Anubis Market is unrelated to Anubis Ransomware and the Anubis Android banking trojan. They share only a name drawn from the same Egyptian funerary iconography, and no public reporting connects the operators.
Anubis Market Structure
Anubis presents a conventional storefront layout: a search bar, a leading vendors panel showing level and rating, a horizontal category strip with per-category counts, and a featured products grid. Its homepage carries a rotating mirror block, a list of directory services users are told to verify links through, and a standing advisory to disable JavaScript while browsing. Site rules are stated prominently and repeatedly, warning users against sharing contact details or dealing outside the platform.
Counting the visible category strip gives roughly 11,000 listings. This should be treated as a marketplace-displayed figure rather than an independently verified inventory. Darknet markets routinely inflate counts through duplicate listings, stale inventory, and vendor spam, and the visible strip may not represent the market’s full taxonomy.
Displayed Category Counts:
Two observations matter here. First, Digital is the largest category on the market, ahead of every narcotics class, which distinguishes Anubis from heavily drug-driven marketplaces.
Second, Anubis displays an Organ Trafficking category, which most established darknet markets explicitly prohibit alongside weapons and violent services. The label should not be read literally. Its small count and the general character of what sits beneath it point to a catch-all for miscellaneous illicit services, with the name chosen for notoriety rather than to describe actual supply.
Shock branding of this kind is a common tactic for newer markets competing for attention, and the useful signal is not the category itself but what it says about how loosely the operators police their own taxonomy.
The Digital Section
The Digital category expands into a nested tree that maps closely onto the cybercrime economy. This is the most useful structure on the market for intelligence purposes, because the subcategory labels reveal what the operators expect to sell in volume.

Anubis Market Digital category tree with displayed subcategory counts
- Fraud (727): Accounts & Bank Drops (328), CVV & Cards (307), Others (26), Stolen Database (8), Personal Infos (5)
- Accounts (481): Compromised platform and service accounts
- Services (238): Carding (90), Others (22)
- Guides & Tutorials (214): Fraud (83), Drugs (83), Others (14), Social Engineering (2)
- Hacking and Cybersecurity (136): Hacking Services (38), Hacking Tools and Equipment (21), Cybersecurity and Protection (7), Others (8), Courses and Tutorials (2)
- Software (104): Cracked and pirated software
- Gold & Jewels (45): Gold (9), Silver (0), Others (10)
- Software & Hosting (21): Others (9), Malware (1), Hosting (0), SOCKS (0), VPN (0)
- E-Books (4)
- Others (43)
Subcategory counts do not reconcile to their parent totals, which suggests listings also sit at the parent level or that counts update independently.
Fraud is the dominant digital category, and within it, bank drops and card data account for the overwhelming majority of listings. For enterprises, the Accounts, Stolen Database, and Accounts & Bank Drops subcategories are the relevant risk surface. The Software & Hosting subtree, by contrast, is nearly empty, indicating Anubis is not competing as an initial access or infrastructure market in the way FreshTools does.
Hacking Tools and Services
The Hacking Tools and Equipment subcategory is small in volume but broad in type. Observed listings include cracked commercial and commodity offensive tooling, mobile surveillance malware, carding and cash-out kits, physical card cloning hardware bundled with tutorials, mobile device unlocking and iCloud bypass services, and flat-rate intrusion offers priced per target.
Anubis Market, Hacking Tools and Equipment section
Key Offerings:
- Cracked remote access trojans: Commodity RATs sold as cracked builds, including variants advertising hidden VNC capability for operating a victim session without the user noticing
- Mobile surveillance malware: Android RAT builds marketed for device monitoring and credential capture
- Cracked commercial security tooling: Pirated builds of legitimate penetration testing platforms, repackaged for offensive use without licensing or attribution
- Loaders and builders: Payload builders advertised with delivery and evasion features
- Carding and cash-out kits: Bundled methods, tooling, and instructions for monetizing stolen card data
- Card cloning hardware: Physical cloning equipment sold with step-by-step tutorials, bridging digital theft and in-person fraud
- Device unlocking services: iCloud, passcode, and activation lock bypass, relevant to the resale of stolen handsets
- Hacking as a service: Fixed-price intrusion offers, lowering the barrier for buyers with no technical capability
Personal Information and Identity Data
The Personal Infos section trades in identity data packaged for direct fraud use.

Anubis Market, Personal Infos section
Observed listing types include U.S. fullz combining Social Security numbers (SSNs), dates of birth, and driver’s license data at low per-record prices; bulk stealer log bundles advertised in the tens of thousands of records; standalone Social Security number listings with four-figure claimed inventory; payment platform account data with five-figure claimed inventory; and utility bills and proof-of-address documents.
The last of these is the most operationally significant and the most often overlooked. Utility bills and proof-of-address documents are sold specifically to defeat Know Your Customer verification at banks, exchanges, and payment providers. Combined with fullz from the same market, they supply everything needed to open accounts, launder proceeds, or take over existing relationships through account recovery flows. Claimed inventory figures in the thousands to tens of thousands should be treated as advertising rather than confirmed holdings, but the packaging itself tells you what the buyers are doing.
The presence of bulk stealer log listings also places Anubis downstream of the wider infostealer economy. Logs harvested by commodity stealer families are resold across multiple venues, and a general-purpose market like Anubis serves as a secondary distribution point rather than a primary source. Organizations tracking exposure should assume overlap with dedicated log markets such as Russian Market rather than treating an Anubis appearance as an independent incident.
Anubis Market’s Operation Model
Anubis runs a wallet escrow model. Buyers fund an internal market wallet or pay a generated address per order, and the market holds funds until the buyer confirms delivery and finalizes. Shipping details are encrypted against the vendor’s PGP key at checkout rather than stored in plaintext.
Trust and Security Mechanisms
- Wallet escrow: Funds are held by the market and released only on buyer finalization, with a dispute path for quality or quantity complaints
- 14-day auto-finalize: Escrow releases automatically after 14 days, transferring risk to the buyer if no dispute is opened in time
- PGP encryption at checkout: Delivery details are encrypted to the vendor key before submission
- Non-recoverable PIN: A user-set PIN authorizes payments and withdrawals and cannot be reset or recovered, eliminating a common account takeover path at the cost of permanent lockout
- Mirror verification: Users are directed to confirm addresses through third-party darknet directory services before logging in
- JavaScript advisory: The market advises disabling JavaScript while browsing, a direct response to browser-based deanonymization
- Off-platform dealing ban: Sharing contact details or transacting outside the market is grounds for a permanent ban
The auto-finalize window is worth noting. A 14-day timer favors vendors and the market over buyers, and disputes that miss it are unrecoverable. This is a common source of the complaints that surface on marketplace-adjacent forums such as Dread, and shifts in a market’s finalize policy are often an early indicator of deteriorating operator behavior.
Vendor Reputation and Ranking
Anubis operates a 10-level vendor ranking alongside a detailed performance panel. Vendor profiles display an aggregate rating percentage, completed and rated order counts, disputes won and lost over a rolling 12-month window, and separate star scores for quality, communication, and shipping.

Anubis Market, one of the vendor’s performance rating panel
This granularity is useful to analysts. Completed order counts, dispute ratios, and rating trajectories provide a rough activity baseline for tracked vendors, and sudden divergence between order volume and rating is a practical signal of vendor compromise, account resale, or an emerging exit scam.
The Vendor Bond and Cross-Market Portability
Selling on Anubis requires a one-time USD 500 vendor fee, payable in BTC or XMR.

Anubis Market, Become a Vendor page
More interesting is the waiver. Anubis will grant a free vendor bond to applicants who hold at least level 6 of 10 on another market, have completed 200 or more sales there, and carry a strong rating. The market names Torzon, DrugHub, and Nexus as qualifying platforms.
This is a documented statement of reputation portability across the darknet market ecosystem, and it has direct analytic value. It confirms which markets Anubis operators regard as peers with credible reputation systems, it identifies the specific platforms from which Anubis expects to recruit established sellers, and it means vendor identities and handles seen on Anubis are likely to correlate with prior activity on those named markets. Bond waivers are a standard growth tactic for newer markets competing for supply after a larger platform collapses, and they create exactly the cross-market linkage that makes vendor tracking productive.
Threat Implications:
- Credential and account exposure: Compromised account and stealer log listings support account takeover, business email compromise, and lateral movement into corporate environments
- Payment fraud: Card data, CVV listings, and bank drop services drive direct financial loss and chargeback exposure for merchants and issuers
- Identity fraud and KYC bypass: Fullz combined with proof-of-address documents enable synthetic identity creation, fraudulent onboarding, and money laundering through regulated institutions
- Lowered attacker barrier: Cracked RATs, builders, and fixed-price intrusion services give unskilled actors working capability without development effort
- Backdoored tooling: Pirated offensive and security software distributed through the market frequently carries additional implants, creating downstream compromise
- Database exposure: Stolen database listings can expose customer records, internal data, and third-party information tied to an organization’s supply chain
Current Status of Anubis Market
Anubis is operational and actively developed. The market was serving live pages with current timestamps as of early September 2026, with an ETH swap promoted as a new feature on the homepage banner, indicating ongoing work on payment flexibility rather than a platform in decline.
Its positioning fits the post-disruption pattern seen repeatedly across the ecosystem. When a large Western-facing market collapses through takedown or exit scam, vendors and buyers migrate, and newer platforms compete for that supply through bond waivers, payment features, and aggressive category breadth. The vendor waiver naming Torzon, DrugHub, and Nexus places Anubis squarely in that competition.
As with any darknet market, status can change without warning. Availability should be re-confirmed through direct intelligence collection rather than assumed from prior reporting, and Anubis should be described with current-at-time-of-observation wording.
Mitigation and Security Measures
Organizations cannot remove listings from a market like Anubis, but they can shorten the window between exposure and response. For a general-purpose market, the realistic focus is narrow: exposed credentials, access being resold, and the tooling and services on offer.
Dark Web Monitoring: SOCRadar’s Black Market Monitoring tracks marketplace activity across platforms including general-purpose markets like Anubis, surfacing mentions of corporate domains, employee credentials, and compromised accounts without requiring analysts to interact with the market directly. Early detection lets teams act before access is resold.

Black Market Monitoring, SOCRadar’s Dark Web Monitoring
Credential and Session Response: Because stealer logs bundle saved passwords alongside session cookies and tokens, password rotation alone is insufficient. Effective response requires session invalidation, token revocation, and endpoint investigation to identify the infection that produced the log.
Access Sale Tracking: Compromised account and bank drop listings are the point at which a prior breach becomes someone else’s entry path. Treat an appearance as an active intrusion indicator rather than a historical exposure, and correlate it against authentication logs for the named assets.
Tooling and Service Intelligence: The cracked RATs, builders, and fixed-price intrusion services listed on Anubis indicate what capability is currently cheap and in circulation. Feeding those families into detection engineering and threat hunting is more useful than tracking the listings themselves.
Avoid Direct Engagement: Manual browsing of darknet markets creates legal, operational, and security risk, including exposure to phishing mirrors and malware. Structured monitoring through a threat intelligence platform is the appropriate collection method.
Frequently Asked Questions
What Is Anubis Market?
Anubis Market is a multi-category Dark Web marketplace operating as a Tor hidden service. It lists narcotics, counterfeits, and digital goods, and accepts Bitcoin and Monero with an escrow system holding funds until buyers confirm delivery. Its Digital category, covering fraud, stolen accounts, card data, and hacking tools, is the largest section on the market.
Is Anubis Market Related to Anubis Ransomware?
No. Anubis Market, Anubis ransomware, and the Anubis Android banking trojan are separate and unconnected. They share a name only, and no public reporting links their operators.
How Many Listings Does Anubis Market Have?
The market’s visible category strip displays more than 11,000 listings. This is a marketplace-displayed figure, not a verified inventory, and darknet markets commonly inflate counts through duplicate and stale listings.
What Does Anubis Market Sell That Affects Businesses?
The categories that matter to organizations are compromised accounts, bank drops, CVV and card data, stolen databases, stealer logs, identity documents, and cracked hacking tools. These support account takeover, payment fraud, identity fraud, KYC bypass, and follow-on intrusion.
What Is a Vendor Bond?
A vendor bond is an upfront fee a marketplace charges sellers before they can list products, intended to deter scammers by making fraudulent selling expensive. Anubis charges USD 500 and waives it for vendors who can demonstrate established standing and sales history on other named markets.
What Is Escrow on a Dark Web Market?
Escrow is a payment-holding system. The buyer’s cryptocurrency is held by the marketplace and released to the vendor only after the buyer confirms delivery. It reduces vendor fraud but does not protect against exit scams, in which operators disappear with all escrowed funds. Anubis also auto-finalizes escrow after 14 days, which transfers risk to buyers who do not open a dispute in time.
Are Stealer Logs Sold on Anubis Market a Serious Risk?
Yes. Stealer logs contain saved credentials, browser cookies, session tokens, and autofill data harvested from infected devices. They allow attackers to resume authenticated sessions and bypass multi-factor authentication, which is why password rotation alone is an incomplete response.
How Can Organizations Monitor Anubis Market Safely?
Through a dedicated Dark Web monitoring platform rather than direct browsing. Automated collection surfaces exposed credentials, brand mentions, and leaked data without the legal, operational, and security risks of interacting with the market or its participants.

