Security researcher Sh1ttyKids has published details about a new Tor server deanonymization trick that uses the entity tag (ETag) portion of an HTTP response header.
The technique was initially developed back in November 2020 and privately shared with law enforcement agencies.
The technique appears to have been used by the FBI to deanonymize the dark web leak site of the RagnarLocker ransomware group.
https://sh1ttykids.medium.com/new-techniques-uncovering-tor-hidden-service-with-etag-5249044a0e9d