Executive Summary

An anonymous operator self-identifying as "Satanist" runs 27 confirmed active Tor exit relays under the domains 2cb.li and 2cb.su, routing approximately 4โ€“5 Gbps of exit traffic across 16 autonomous systems in 11 countries. This single pseudonymous actor spans all three infrastructure providers documented in the previous letters: 1337 Services GmbH (030A), SERVPERSO (030B), and LAIN/Aluy (030C). They are the connecting thread โ€” the customer that makes the entire anonymity factory meaningful.

The "2C-B" name references a Schedule I psychedelic drug. The relay names โ€” death, demise, dismal, dim, die, dreary, drear, depression, dark, dead, desolate โ€” form a curated lexicon of darkness. The operator maintains a Monero node accessible only via Tor, accepts XMR donations, and hosts a website on Bear Blog with a pill emoji (๐Ÿ’Š) as its favicon. Their DNS is served by Mynymbox (Saint Kitts), their relays run on Aokigahara SRL (the "Suicide Forest" hosting company), and their domain was registered 11 years ago โ€” parked until January 2026.

All 27 relays were restarted simultaneously on June 19, 2026. One domain (2cb.network) was blackholed by its registrar in May 2026. The operator migrated to a Soviet-era TLD (.su) without interruption.

27Active Tor exit relays
~4.5 GbpsAggregate exit bandwidth
16ASNs hosting relays
11Countries
100%AbuseIPDB confidence
12+Linked investigations

Confidence: HIGH โ€” Primary sources: Tor Project Onionoo API (live relay data, June 20 2026), RDAP registries (NIC.LI, Identity Digital, ZDNS), 2cb.su live website analysis, AbuseIPDB reports, Wayback Machine archives, PeeringDB, ipinfo.io geolocation, and cross-referencing with 12+ prior investigations in our intelligence corpus.

Chapter 1: The Connecting Thread

Throughout this investigation series, three infrastructure providers emerged as distinct entities: a German GmbH with a SHA1-hashed director (030A), a Belgian RIPE maintainer serving Turkish phishing (030B), and a Munich anime enthusiast selling anonymous ASNs (030C). They appeared unrelated โ€” different jurisdictions, different business models, different aesthetic sensibilities.

The Satanist connects them all.

Multi-Provider Presence (Confirmed Active June 2026)

ProviderASNRelay ExamplesCount
Julian Achter / LAINAS211507tor-exit.nl.2cb.li, tor-exit.bg.2cb.li, tor-exit.fi.2cb.li, tor-exit.ch3.2cb.li, tor-exit.hk.2cb.li6 relays
Aokigahara SRL / Kyun SRLAS215659tor-exit.ro.2cb.li, tor-exit.nl8.2cb.li3 relays
MAXKO d.o.o.AS211619tor-exit.bg2.2cb.li, tor-exit.nl4.2cb.li, tor-exit.hu.2cb.li3 relays
FranTech SolutionsAS53667tor-exit.ch.2cb.li, tor.exit.us2.2cb.li2 relays
TechTies Inc.AS197170(no hostname)2 relays
Throttle LimitedAS198189(no hostname)2 relays
9 additional providersVarious1 relay each9 relays

No other actor in our entire intelligence corpus spans all three of the providers documented in this series. The Satanist is not merely a customer โ€” they are the proof of concept that the anonymity factory works as designed. Multiple bulletproof providers, each with plausible deniability, serving one pseudonymous operator who cannot be identified, contacted, or stopped through conventional channels.

The Coordinated Restart: All 27 relays show last_restarted: 2026-06-19 in Tor relay descriptors. This is cryptographic proof of centralized management โ€” one operator, one configuration push, 27 machines across 11 countries simultaneously updated. This is not a loose collective. This is one person's infrastructure.

Chapter 2: The Name โ€” Psychedelics, Death, and the Soviet TLD

2C-B (4-Bromo-2,5-dimethoxyphenethylamine) is a Schedule I controlled substance in most jurisdictions. First synthesized by Alexander Shulgin in 1974 and published in PiHKAL (1991), it was widely sold in Dutch smart shops before EU scheduling. The choice of this name for Tor relay infrastructure is deliberate cultural coding:

  • Subcultural membership โ€” signals familiarity with psychedelic/darknet culture
  • Transgressive identity โ€” "I name my infrastructure after drugs because I don't care about your norms"
  • Historical resonance โ€” Shulgin's work was itself an act of scientific defiance

The relay naming scheme reinforces this: death, demise, dismal, dim, die, dreary, drear, depression, dark, dead, desolate. Not random words โ€” a curated lexicon of darkness, each beginning with 'D'. This is an aesthetic choice revealing deliberate creative attention to branding.

Domain Portfolio โ€” Jurisdictional Diversity

DomainTLDStatusRegisteredSignificance
2cb.li.li (Liechtenstein)Active, NymDNS2015-04-0911-year parked domain, privacy jurisdiction
2cb.network.network (gTLD)BLACKHOLED May 20262025-09-18Suspended by NameSilo/Dendrite
2cb.su.su (Soviet Union)Active, current primaryUnknownRussian-managed TLD, opaque WHOIS

The migration path is telling: When 2cb.network was blackholed (May 2026), the operator was already prepared with 2cb.su โ€” a Soviet-era TLD managed by the Russian Foundation for Internet Development, where WHOIS/RDAP queries are opaque and registrar cooperation with Western law enforcement is... complex. The .su TLD is a dead country's domain that persists as a haven for actors seeking registrar-level opacity.

The site's hidden HTML metadata reveals additional personality: <meta name="2cb" content="look-for-the-bear-necessities"> โ€” a Jungle Book reference functioning as a playful Easter egg. The favicon is a ๐Ÿ’Š pill emoji rendered as SVG. These details reveal a personality: irreverent, technically competent, culturally literate, deliberately transgressive but with humor.

Chapter 3: The Complete Relay Roster

The Tor Project's Onionoo API (queried June 20, 2026) returns the complete active family, cryptographically verified via shared family certificate J5lwoyq+EYO6k9uq+HixF30nFFBBcKGPOsfasr+yLzo:

All 27 Active Relays โ€” Family C4FEABB1C0F7709312B33345040FBC29682877DE

NameIPCountryASNHostnameBW
dead107.189.12.157CHAS53667 FranTechtor-exit.ch.2cb.li~42 MB/s
desolate176.65.142.198SEAS198189 Throttleโ€”~51 MB/s
dismal185.222.160.89NLAS214668 AxusHostโ€”~45 MB/s
dismal5.83.143.18NLAS200912 J. Krausetor-exit.nl2.2cb.li~33 MB/s
desolate176.65.142.223SEAS198189 Throttleโ€”~32 MB/s
demise77.90.185.93DEAS213790 Limited Netโ€”~28 MB/s
dismal192.109.200.33NLAS197170 TechTiesโ€”~25 MB/s
dreary167.17.40.238NLAS57043 HOSTKEYโ€”~21 MB/s
dismal89.125.255.12NLAS212477 RoyaleHostingโ€”~21 MB/s
demise94.26.106.102DEAS197170 TechTiesโ€”~20 MB/s
depression45.133.73.6FR/HKAS211507 LAINtor-exit.hk.2cb.li~18 MB/s
death193.32.162.86ROAS47890 UNMANAGEDโ€”~18 MB/s
dismal87.121.79.14NLAS199428 A. Navasโ€”~16 MB/s
dim45.9.156.110BGAS211619 MAXKOtor-exit.bg2.2cb.li~15 MB/s
dismal150.40.127.65NLAS211619 MAXKOtor-exit.nl4.2cb.li~15 MB/s
die45.141.119.80CHAS211507 LAINtor-exit.ch3.2cb.li~13 MB/s
dim45.137.201.5BGAS211507 LAINtor-exit.bg.2cb.li~12 MB/s
dismal185.132.53.121NLAS211507 LAINtor-exit.nl.2cb.li~12 MB/s
dreary194.34.134.13FIAS51765 Crea Novaโ€”~12 MB/s
dreary45.137.69.9FIAS211507 LAINtor-exit.fi.2cb.li~12 MB/s
dismal150.40.117.43NLAS215659 Kyun/Aokigaharator-exit.nl8.2cb.li~10 MB/s
dark45.9.168.102HUAS211619 MAXKOtor-exit.hu.2cb.li~10 MB/s
drear209.141.61.225USAS53667 FranTechtor.exit.us2.2cb.li~9 MB/s
demise64.204.180.233DEAS213250 ITP-Solutionsโ€”~8 MB/s
drear45.38.20.213USAS215659 Kyun/Aokigaharaโ€”~7 MB/s
dismal95.155.151.200NLAS40662 Layer7 Techโ€”~7 MB/s
death93.113.25.109ROAS215659 Kyun/Aokigaharator-exit.ro.2cb.li~6 MB/s

Bandwidth distribution: The top 5 relays account for ~200 MB/s; the bottom 10 account for ~90 MB/s. This is a deliberately distributed architecture โ€” no single relay is critical, but collectively they form a substantial exit capacity.

Geographic strategy: Netherlands dominates (11 relays) due to hosting availability and legal environment. But presence in Romania, Bulgaria, Hungary, Finland, Sweden, and the US ensures that no single European legal action can eliminate the network.

Chapter 4: The Mynymbox Link โ€” DNS as Identity

The single most revealing technical finding: 2cb.li's nameservers are dns.mynymdns.me and dns.mynymdns.st โ€” Mynymbox's NymDNS service.

The NymDNS Dependency Chain

LayerServiceProviderJurisdiction
Domain registration2cb.li at Key-Systems GmbHGerman registrarLiechtenstein (.li)
DNS resolutiondns.mynymdns.me / .stMynymbox Hosting LLCSaint Kitts & Nevis
Web hostingBear Blog platformHermanMartinus (indie dev)South Africa / DigitalOcean
Relay hosting16 ASNs across 11 countriesVarious bulletproofMulti-jurisdiction
PaymentMonero (XMR)Peer-to-peerNo jurisdiction

Mynymbox Hosting LLC is registered at Hamilton Development, Unit B, Charlestown, Nevis, KN0802. This is the same address structure used by the allium.top registrant. The company describes itself as "entirely self-funded and privately owned" โ€” a privacy-focused hosting company that acts as a "privacy proxy" between customers and upstream domain registrars.

The Satanist is a confirmed Mynymbox customer. Mynymbox controls DNS resolution for all *.2cb.li subdomains โ€” meaning every relay hostname (tor-exit.nl.2cb.li, tor-exit.bg.2cb.li, etc.) resolves through Mynymbox's infrastructure. This is not merely a service relationship; it's an operational dependency. If Mynymbox chose to blackhole 2cb.li's DNS, the entire relay network would lose its vanity hostnames instantly.

The Three-Body Problem: Mynymbox (KN), Aokigahara/Kyun SRL (RO), and the Satanist (unknown) all launched in 2024-2025. All three converge on death-themed aesthetics and privacy-extremist ideology. All three connect through Saint Kitts and Nevis. Are they three entities โ€” or three brands operated by one person?

Chapter 5: Aokigahara SRL โ€” The Suicide Forest Hosts Your Relays

Aokigahara SRL (AS215659), operating commercially as Kyun SRL under the brand kyun.sh, is a Romanian privacy cloud provider hosting 3 of the Satanist's relays:

Aokigahara/Kyun SRL โ€” Dual Identity

FieldRIPE RegistrationPeeringDB
NameAokigahara SRLKyun SRL
Websiteโ€”kyun.sh
ASNAS215659AS215659
CountryRomaniaRomania
Createdโ€”2024-02-17
Last updatedโ€”2026-06-17 (3 days before report)
IPv4 originated2,304โ€”

The naming is diagnostic:

  • Aokigahara = Japan's "Suicide Forest" at the base of Mount Fuji, notorious worldwide as a site of death
  • Kyun = Japanese onomatopoeia for a heartbeat/pang (ใ‚ญใƒฅใƒณ) โ€” common in anime
  • MOEMOEKYUN = AS description referencing K-On! anime (่Œใˆ่Œใˆใ‚ญใƒฅใƒณ)

This company provides infrastructure for the Satanist's relays in three countries: Romania (93.113.25.109, near Bucharest), Netherlands (150.40.117.43, Amsterdam), and United States (45.38.20.213, Spokane Valley, Washington). A Romanian SRL routing IP space to the United States is highly unusual for a small provider and suggests a sophisticated understanding of BGP routing and remote IP justification at RIR level.

The aesthetic connection between Aokigahara SRL (death/suicide naming) and the Satanist (death-themed relay names) is too precise to be coincidental. Either:

  1. The Satanist chose Aokigahara SRL specifically because the naming resonated (customer with shared aesthetic)
  2. The Satanist is the operator of Aokigahara SRL (one person, multiple brands)

We cannot currently prove option 2. But the convergence of: death-themed naming, privacy cloud services, 2024 founding date, anime aesthetic overlap, and hosting of the Satanist's relays across three countries makes option 1 (pure coincidence of taste) insufficient as an explanation.

Chapter 6: The Saint Kitts Pattern

Three distinct entities in the 2cb.li ecosystem register in Saint Kitts and Nevis (KN), a Caribbean microstate with 47,000 inhabitants:

Charlestown, Nevis Convergence

EntityAddressRole
Mynymbox Hosting LLCHamilton Development, Unit B, Charlestown, Nevis, KN0802DNS/hosting for 2cb.li
allium.top registrantCharlestown, Nevis, KNSeparate Tor relay operator
1337 Services LLCSaint Kitts & Nevis (RDAP)ASN operator hosting relays

Saint Kitts and Nevis offers: no MLAT with Germany for cybercrime, LLC formation under $500, minimal beneficial ownership disclosure, and no established precedent for EU cyber-crime extradition. The jurisdiction was chosen specifically for these gaps.

Consider the investigator's path: A German prosecutor investigating abuse from 185.132.53.121 must trace through: Tor Project (US, content-neutral) โ†’ IP registered to AS211507 โ†’ ASN operated by Julian Achter (Germany, but mere conduit) โ†’ serving an operator identified only as "Satanist" โ†’ paying in Monero through NymBox (Saint Kitts) โ†’ domain in Liechtenstein with NymDNS (Saint Kitts). Every link is designed to break legal continuity.

Chapter 7: The allium.top Distinction

Prior analysis conflated allium.top with 2cb.li. The research definitively separates them:

Two Operators, Shared Providers

Attribute2cb.li / Satanistallium.top
Contactadmin@2cb.sua78i2efsewr0neeknk@proton.me
XMR wallet85rXJTzRN2nAx...F23iUkm82sdVXSFUJcici...VjtPbEk
Relay namesdeath, dim, dark, die...SieNCoAd, ASqUADeo, NgePTimE
AestheticDeath/drug themedRandom alphanumeric
Active relays273
DNSMynymbox NymDNSNjalla (Peter Sunde)
Registrant locationUnknown (NymDNS privacy)Charlestown, Nevis KN
Shared ASNsBoth use AS53667 (FranTech) and AS210558 (1337 Services)

The allium.top operator is technically transparent (publishes relay costs via CIISS format: LiteServer โ‚ฌ3.75, rdp.sh โ‚ฌ5, BuyVM $7) and uses a Njalla privacy DNS (founded by Peter Sunde of The Pirate Bay). They share hosting providers with the Satanist but are a distinct individual with a different wallet, different naming convention, and different cultural aesthetic.

Both operators converge on Saint Kitts and Nevis for registration. Both use bulletproof hosting. Both accept Monero. The difference: allium.top operates 3 relays transparently; the Satanist operates 27 relays behind layers of identity erasure. Scale and opacity distinguish ideology from operation.

Chapter 8: The Phishing Subnet

The 45.154.98.0/24 subnet โ€” where allium.top previously operated (tor-exit-1.allium.top at 45.154.98.33, now relocated) โ€” reveals the character of bulletproof hosting:

PTR Record Archaeology โ€” 45.154.98.0/24

CategoryCountExamples
RDP.sh branded30+ns1.rdp.sh, rdp.sh PTR records
Tor exit relays5+allium.top, 2cb.li
French bank phishing3+caisse-epargne-se-connecter.net
Turkish phishing30+Various domains
Crypto wallet phishingMultipleWallet impersonation domains

45.154.98.153 hosts caisse-epargne-se-connecter.net โ€” an active phishing page impersonating Caisse d'ร‰pargne, France's largest savings bank (26 million customers). This domain cohabits with Tor exit infrastructure on the same /24 โ€” the bulletproof provider serves both with equal enthusiasm.

The Ethical Question: Does a Tor exit operator bear responsibility for their network neighborhood? Zwiebelfreunde (100 exits, AS60729) chose clean hosting and generates zero abuse. The Satanist chose bulletproof hosting where phishing lives next door. The technology is identical. The infrastructure choice is not.

Chapter 9: The Zwiebelfreunde Contrast

To understand what the Satanist is, examine what they are not.

Ethical Spectrum of Tor Exit Operation

MetricZwiebelfreunde e.V.Cyberology2cb.li (Satanist)
Exit relays1001 (133 Gbps)27
Risk score18/100Low40-61/100
Honeypot attacksZERONone documentedMultiple confirmed
AbuseIPDBLowLow90-100%
RegistrationGerman e.V. (non-profit)Dutch KvK 93306199NymBox (KN, anonymous)
RaidedYes (2018, later illegal)NoCannot be located
Hosting typeLegitimateLegitimateBulletproof
Subnet neighborsCleanCleanActive phishing

Zwiebelfreunde was raided in 2018 โ€” later declared illegal by German courts. They accepted the legal risk of transparent operation and were vindicated. Cyberology operates the world's single largest Tor exit (133.9 Gbps) as a registered Dutch company. Both demonstrate that Tor exit operation does not require anonymity, bulletproof hosting, or offshore shells.

The Satanist chose: anonymous registration over transparency, bulletproof hosting over legitimate infrastructure, offshore shells over domestic accountability, a Soviet TLD over a mainstream registrar. The legitimate operator accepts risk. The bulletproof operator eliminates all possibility of accountability. This distinction is the finding.

Chapter 10: Operation Talent Survival and Domain Blackholing

Two enforcement events bracket the Satanist's operational timeline:

Enforcement Timeline

DateEventImpact on Satanist
January 2025FBI Operation Talent seizes Cracked/NulledZero impact โ€” transport โ‰  content
September 20252cb.network registered at NameSiloPost-Talent expansion
~January 20262cb.li activated (was parked 10 years)Infrastructure buildout
May 14, 20262cb.network blackholed by Dendrite/NameSiloDomain loss, migrate to .su
June 20262cb.su active, all 27 relays operationalFull recovery in weeks

Operation Talent targeted content platforms (forums, payment processors). The Satanist's transport infrastructure was structurally immune โ€” you cannot seize a Tor relay the way you seize a forum. The operation targeted specific servers; the Satanist has 27 across 16 providers.

The 2cb.network blackholing is more interesting. NameSilo suspended the domain via Identity Digital's Dendrite abuse system. This could be: registrar abuse response (most likely โ€” NameSilo has suspended bulletproof domains under pressure before), law enforcement request (possible but no press release), or voluntary migration (the operator had already prepared 2cb.su). The 8-month lifespan (September 2025 โ†’ May 2026) matches the pattern of gTLDs being hostile to controversial content โ€” reinforcing why the operator maintains 2cb.li (privacy TLD) and 2cb.su (opaque TLD) as fallbacks.

Chapter 11: The Financial Model

The Satanist solicits Monero donations on every page of 2cb.su:

Financial Intelligence

AssetValueTraceability
XMR wallet85rXJTzRN2nAx8yHFQmCFp...F23iUkmUntraceable (RingCT + Stealth)
Monero node (.onion)vm62zwfqrusvmej5...onion:18081Tor-only, no clearnet exposure
Old Monero nodezpoohy3efkpkcknw...onion:18081From 2cb.network era (Dec 2025)

Cost Estimation (27 relays)

ProviderRelaysEst. Monthly Cost
LAIN (AS211507)6โ‚ฌ60-180
MAXKO d.o.o. (AS211619)3โ‚ฌ30-90
Aokigahara/Kyun (AS215659)3โ‚ฌ30-90
FranTech/BuyVM (AS53667)2$28-84
Other 13 providers13โ‚ฌ130-390
Total estimated27โ‚ฌ300-800/month

At โ‚ฌ300-800/month, this is within reach of a single individual with modest income โ€” comparable to a car payment. The low cost makes several funding models viable: personal funds, XMR donations, Monero node service fees, or a combination. The infrastructure does not require external funding or commercial revenue to sustain.

The Monero node (accessible only via Tor v3 onion) could generate passive income from light wallet users who pay for remote node access. The operator explicitly describes running "privacy focused services" โ€” plural โ€” suggesting multiple revenue streams beyond relay operation alone.

Chapter 12: Cross-Corpus Intelligence

Searching our complete intelligence corpus (30+ investigations, 8,000+ IPs, 271,000+ entity links) reveals the Satanist connects to more prior investigations than any other single entity:

Intelligence Connections (12+ Investigations)

InvestigationConnectionType
TI-014 (Phase Layer)Private Layer INC: same PA/CH jurisdictional split modelPattern parallel
TI-019C (Outlaw)Monero mining on compromised hosts โ€” same crypto economyEcosystem overlap
019M (Operation Talent)Adjacent infrastructure: RDP.sh, MEVSPACE, darknet hostingInfrastructure adjacency
TI-2026-023A (VPN)Zwiebelfreunde contrast: 100 exits, zero abuse, non-profitContrast case
TI-2026-023B (Backbone)Private Layer HASSH overlap with Omegatech โ€” operational linksShared tooling
TI-2026-024 (Omegatech)Seychelles shell + bulletproof hosting โ€” parallel patternPattern parallel
TI-2026-025A (SSH Parasite)Monero mining on compromised infrastructure โ€” same economyEcosystem overlap
TI-2026-026 (PIO-Hosting)Multi-jurisdiction shell game โ€” identical legal architecturePattern parallel
TI-2026-028 (MAXTV)Geographic discrepancy technique โ€” same obfuscation methodShared technique
019L (Cyberology)World's largest legitimate Tor exit โ€” contrast caseContrast case
TI-007 (Supply Chain)Private Layer in interlocking crime network modelStructural parallel
DOSSIER-PRIVATE-CUSTOMER-001Aokigahara SRL confirmed in separate investigationShared infrastructure

This density is not incidental. The Satanist operates at the nexus where multiple threat ecosystems converge. Their relays serve as generalist transport infrastructure that enables specialists in phishing, darknet markets, botnets, and C2 operations to route traffic through a single anonymization layer. They are not a specialist โ€” they are a platform.

Chapter 13: What We Cannot Know

Intellectual honesty requires acknowledging opacity:

  • Identity: One person or a group? The coordinated restart (all 27 relays, same day) and consistent aesthetic suggest a single mind. But we cannot prove this.
  • Satanist = Kyun SRL? The death-themed naming overlap, 2024 founding timeline, and hosting relationship strongly suggest identity โ€” but could be mere aesthetic affinity.
  • Motivation: Privacy ideology, commercial operation, intelligence collection, or criminal enterprise? The architecture is motive-neutral. All are possible simultaneously.
  • Traffic monitoring: A Tor exit operator can log unencrypted traffic. 27 exits represent substantial surveillance capability if deployed by a state actor. No evidence either way.
  • The 2cb.network blackholing: Law enforcement, registrar abuse action, or voluntary migration? The timing and preparation (2cb.su already active) leaves all three plausible.
  • Relationship to Mynymbox: Customer, affiliate, or operator? The Charlestown convergence is suggestive but not conclusive.
The Fundamental Ambiguity: The very architecture designed to prevent identification also prevents us from determining intent. Is this (a) extreme privacy activism, (b) commercial bandwidth resale, (c) state-level traffic collection, or (d) criminal infrastructure laundering? The design ensures these hypotheses are indistinguishable from outside. That indistinguishability is the product.

Conclusions

The Satanist represents the maximum expression of the anonymity factory documented in this series:

  1. A single pseudonymous operator controls 27 Tor exit relays across 16 ASNs in 11 countries, generating ~4.5 Gbps of exit bandwidth
  2. The multi-layer anonymity stack (NymDNS + Saint Kitts shells + Monero + .su TLD + Tor) creates effectively unbreakable identity protection
  3. Bulletproof hosting (LAIN, Aokigahara/Kyun, MAXKO) specifically enables cohabitation with criminal infrastructure
  4. The legal framework in each jurisdiction creates gaps that, combined, form a comprehensive shield
  5. Legitimate operators (Zwiebelfreunde, Cyberology) demonstrate that the choice of bulletproof hosting signals intent beyond privacy advocacy
  6. Domain blackholing (2cb.network) proved ineffective โ€” the operator migrated to .su within weeks, all relays continued operating
  7. The 11-year domain dormancy (2cb.li, registered 2015, activated 2026) reveals patient planning

The connecting thread is not the technology. Tor is neutral. Exit relays are legal. Monero is legal. Offshore LLCs are legal. Each component, individually, serves legitimate purposes. The combination โ€” assembled to prevent any accountability for any activity โ€” is what makes this architecture notable. And the patient, deliberate, aesthetically unified deployment across multiple providers demonstrates not impulse but craft.

The Satanist didn't build the factory. They are its most dedicated customer โ€” and the proof that it delivers exactly what it promises.

Intelligence Sources: Tor Project Onionoo API (live relay consensus, June 20 2026), RDAP registries (NIC.LI, Identity Digital/ZDNS, PeeringDB), 2cb.su live website HTML analysis, Wayback Machine (2cb.network December 2025 snapshot), AbuseIPDB, Shodan, ipinfo.io, LSN Cowrie honeypot correlation, AlienVault OTX, and cross-referencing with 12+ prior investigations in the LSN dossier intelligence corpus (Qdrant + Elasticsearch, 30+ published dossiers). No active scanning of target infrastructure was performed.
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Anonymity Factory โ€” 4 / 12 Next โ†’