Executive Summary
An anonymous operator self-identifying as "Satanist" runs 27 confirmed active Tor exit relays under the domains 2cb.li and 2cb.su, routing approximately 4โ5 Gbps of exit traffic across 16 autonomous systems in 11 countries. This single pseudonymous actor spans all three infrastructure providers documented in the previous letters: 1337 Services GmbH (030A), SERVPERSO (030B), and LAIN/Aluy (030C). They are the connecting thread โ the customer that makes the entire anonymity factory meaningful.
The "2C-B" name references a Schedule I psychedelic drug. The relay names โ death, demise, dismal, dim, die, dreary, drear, depression, dark, dead, desolate โ form a curated lexicon of darkness. The operator maintains a Monero node accessible only via Tor, accepts XMR donations, and hosts a website on Bear Blog with a pill emoji (๐) as its favicon. Their DNS is served by Mynymbox (Saint Kitts), their relays run on Aokigahara SRL (the "Suicide Forest" hosting company), and their domain was registered 11 years ago โ parked until January 2026.
All 27 relays were restarted simultaneously on June 19, 2026. One domain (2cb.network) was blackholed by its registrar in May 2026. The operator migrated to a Soviet-era TLD (.su) without interruption.
Confidence: HIGH โ Primary sources: Tor Project Onionoo API (live relay data, June 20 2026), RDAP registries (NIC.LI, Identity Digital, ZDNS), 2cb.su live website analysis, AbuseIPDB reports, Wayback Machine archives, PeeringDB, ipinfo.io geolocation, and cross-referencing with 12+ prior investigations in our intelligence corpus.
Chapter 1: The Connecting Thread
Throughout this investigation series, three infrastructure providers emerged as distinct entities: a German GmbH with a SHA1-hashed director (030A), a Belgian RIPE maintainer serving Turkish phishing (030B), and a Munich anime enthusiast selling anonymous ASNs (030C). They appeared unrelated โ different jurisdictions, different business models, different aesthetic sensibilities.
The Satanist connects them all.
Multi-Provider Presence (Confirmed Active June 2026)
| Provider | ASN | Relay Examples | Count |
|---|---|---|---|
| Julian Achter / LAIN | AS211507 | tor-exit.nl.2cb.li, tor-exit.bg.2cb.li, tor-exit.fi.2cb.li, tor-exit.ch3.2cb.li, tor-exit.hk.2cb.li | 6 relays |
| Aokigahara SRL / Kyun SRL | AS215659 | tor-exit.ro.2cb.li, tor-exit.nl8.2cb.li | 3 relays |
| MAXKO d.o.o. | AS211619 | tor-exit.bg2.2cb.li, tor-exit.nl4.2cb.li, tor-exit.hu.2cb.li | 3 relays |
| FranTech Solutions | AS53667 | tor-exit.ch.2cb.li, tor.exit.us2.2cb.li | 2 relays |
| TechTies Inc. | AS197170 | (no hostname) | 2 relays |
| Throttle Limited | AS198189 | (no hostname) | 2 relays |
| 9 additional providers | Various | 1 relay each | 9 relays |
No other actor in our entire intelligence corpus spans all three of the providers documented in this series. The Satanist is not merely a customer โ they are the proof of concept that the anonymity factory works as designed. Multiple bulletproof providers, each with plausible deniability, serving one pseudonymous operator who cannot be identified, contacted, or stopped through conventional channels.
last_restarted: 2026-06-19 in Tor relay descriptors. This is cryptographic proof of centralized management โ one operator, one configuration push, 27 machines across 11 countries simultaneously updated. This is not a loose collective. This is one person's infrastructure.
Chapter 2: The Name โ Psychedelics, Death, and the Soviet TLD
2C-B (4-Bromo-2,5-dimethoxyphenethylamine) is a Schedule I controlled substance in most jurisdictions. First synthesized by Alexander Shulgin in 1974 and published in PiHKAL (1991), it was widely sold in Dutch smart shops before EU scheduling. The choice of this name for Tor relay infrastructure is deliberate cultural coding:
- Subcultural membership โ signals familiarity with psychedelic/darknet culture
- Transgressive identity โ "I name my infrastructure after drugs because I don't care about your norms"
- Historical resonance โ Shulgin's work was itself an act of scientific defiance
The relay naming scheme reinforces this: death, demise, dismal, dim, die, dreary, drear, depression, dark, dead, desolate. Not random words โ a curated lexicon of darkness, each beginning with 'D'. This is an aesthetic choice revealing deliberate creative attention to branding.
Domain Portfolio โ Jurisdictional Diversity
| Domain | TLD | Status | Registered | Significance |
|---|---|---|---|---|
| 2cb.li | .li (Liechtenstein) | Active, NymDNS | 2015-04-09 | 11-year parked domain, privacy jurisdiction |
| 2cb.network | .network (gTLD) | BLACKHOLED May 2026 | 2025-09-18 | Suspended by NameSilo/Dendrite |
| 2cb.su | .su (Soviet Union) | Active, current primary | Unknown | Russian-managed TLD, opaque WHOIS |
The migration path is telling: When 2cb.network was blackholed (May 2026), the operator was already prepared with 2cb.su โ a Soviet-era TLD managed by the Russian Foundation for Internet Development, where WHOIS/RDAP queries are opaque and registrar cooperation with Western law enforcement is... complex. The .su TLD is a dead country's domain that persists as a haven for actors seeking registrar-level opacity.
The site's hidden HTML metadata reveals additional personality: <meta name="2cb" content="look-for-the-bear-necessities"> โ a Jungle Book reference functioning as a playful Easter egg. The favicon is a ๐ pill emoji rendered as SVG. These details reveal a personality: irreverent, technically competent, culturally literate, deliberately transgressive but with humor.
Chapter 3: The Complete Relay Roster
The Tor Project's Onionoo API (queried June 20, 2026) returns the complete active family, cryptographically verified via shared family certificate J5lwoyq+EYO6k9uq+HixF30nFFBBcKGPOsfasr+yLzo:
All 27 Active Relays โ Family C4FEABB1C0F7709312B33345040FBC29682877DE
| Name | IP | Country | ASN | Hostname | BW |
|---|---|---|---|---|---|
| dead | 107.189.12.157 | CH | AS53667 FranTech | tor-exit.ch.2cb.li | ~42 MB/s |
| desolate | 176.65.142.198 | SE | AS198189 Throttle | โ | ~51 MB/s |
| dismal | 185.222.160.89 | NL | AS214668 AxusHost | โ | ~45 MB/s |
| dismal | 5.83.143.18 | NL | AS200912 J. Krause | tor-exit.nl2.2cb.li | ~33 MB/s |
| desolate | 176.65.142.223 | SE | AS198189 Throttle | โ | ~32 MB/s |
| demise | 77.90.185.93 | DE | AS213790 Limited Net | โ | ~28 MB/s |
| dismal | 192.109.200.33 | NL | AS197170 TechTies | โ | ~25 MB/s |
| dreary | 167.17.40.238 | NL | AS57043 HOSTKEY | โ | ~21 MB/s |
| dismal | 89.125.255.12 | NL | AS212477 RoyaleHosting | โ | ~21 MB/s |
| demise | 94.26.106.102 | DE | AS197170 TechTies | โ | ~20 MB/s |
| depression | 45.133.73.6 | FR/HK | AS211507 LAIN | tor-exit.hk.2cb.li | ~18 MB/s |
| death | 193.32.162.86 | RO | AS47890 UNMANAGED | โ | ~18 MB/s |
| dismal | 87.121.79.14 | NL | AS199428 A. Navas | โ | ~16 MB/s |
| dim | 45.9.156.110 | BG | AS211619 MAXKO | tor-exit.bg2.2cb.li | ~15 MB/s |
| dismal | 150.40.127.65 | NL | AS211619 MAXKO | tor-exit.nl4.2cb.li | ~15 MB/s |
| die | 45.141.119.80 | CH | AS211507 LAIN | tor-exit.ch3.2cb.li | ~13 MB/s |
| dim | 45.137.201.5 | BG | AS211507 LAIN | tor-exit.bg.2cb.li | ~12 MB/s |
| dismal | 185.132.53.121 | NL | AS211507 LAIN | tor-exit.nl.2cb.li | ~12 MB/s |
| dreary | 194.34.134.13 | FI | AS51765 Crea Nova | โ | ~12 MB/s |
| dreary | 45.137.69.9 | FI | AS211507 LAIN | tor-exit.fi.2cb.li | ~12 MB/s |
| dismal | 150.40.117.43 | NL | AS215659 Kyun/Aokigahara | tor-exit.nl8.2cb.li | ~10 MB/s |
| dark | 45.9.168.102 | HU | AS211619 MAXKO | tor-exit.hu.2cb.li | ~10 MB/s |
| drear | 209.141.61.225 | US | AS53667 FranTech | tor.exit.us2.2cb.li | ~9 MB/s |
| demise | 64.204.180.233 | DE | AS213250 ITP-Solutions | โ | ~8 MB/s |
| drear | 45.38.20.213 | US | AS215659 Kyun/Aokigahara | โ | ~7 MB/s |
| dismal | 95.155.151.200 | NL | AS40662 Layer7 Tech | โ | ~7 MB/s |
| death | 93.113.25.109 | RO | AS215659 Kyun/Aokigahara | tor-exit.ro.2cb.li | ~6 MB/s |
Bandwidth distribution: The top 5 relays account for ~200 MB/s; the bottom 10 account for ~90 MB/s. This is a deliberately distributed architecture โ no single relay is critical, but collectively they form a substantial exit capacity.
Geographic strategy: Netherlands dominates (11 relays) due to hosting availability and legal environment. But presence in Romania, Bulgaria, Hungary, Finland, Sweden, and the US ensures that no single European legal action can eliminate the network.
Chapter 4: The Mynymbox Link โ DNS as Identity
The single most revealing technical finding: 2cb.li's nameservers are dns.mynymdns.me and dns.mynymdns.st โ Mynymbox's NymDNS service.
The NymDNS Dependency Chain
| Layer | Service | Provider | Jurisdiction |
|---|---|---|---|
| Domain registration | 2cb.li at Key-Systems GmbH | German registrar | Liechtenstein (.li) |
| DNS resolution | dns.mynymdns.me / .st | Mynymbox Hosting LLC | Saint Kitts & Nevis |
| Web hosting | Bear Blog platform | HermanMartinus (indie dev) | South Africa / DigitalOcean |
| Relay hosting | 16 ASNs across 11 countries | Various bulletproof | Multi-jurisdiction |
| Payment | Monero (XMR) | Peer-to-peer | No jurisdiction |
Mynymbox Hosting LLC is registered at Hamilton Development, Unit B, Charlestown, Nevis, KN0802. This is the same address structure used by the allium.top registrant. The company describes itself as "entirely self-funded and privately owned" โ a privacy-focused hosting company that acts as a "privacy proxy" between customers and upstream domain registrars.
The Satanist is a confirmed Mynymbox customer. Mynymbox controls DNS resolution for all *.2cb.li subdomains โ meaning every relay hostname (tor-exit.nl.2cb.li, tor-exit.bg.2cb.li, etc.) resolves through Mynymbox's infrastructure. This is not merely a service relationship; it's an operational dependency. If Mynymbox chose to blackhole 2cb.li's DNS, the entire relay network would lose its vanity hostnames instantly.
Chapter 5: Aokigahara SRL โ The Suicide Forest Hosts Your Relays
Aokigahara SRL (AS215659), operating commercially as Kyun SRL under the brand kyun.sh, is a Romanian privacy cloud provider hosting 3 of the Satanist's relays:
Aokigahara/Kyun SRL โ Dual Identity
| Field | RIPE Registration | PeeringDB |
|---|---|---|
| Name | Aokigahara SRL | Kyun SRL |
| Website | โ | kyun.sh |
| ASN | AS215659 | AS215659 |
| Country | Romania | Romania |
| Created | โ | 2024-02-17 |
| Last updated | โ | 2026-06-17 (3 days before report) |
| IPv4 originated | 2,304 | โ |
The naming is diagnostic:
- Aokigahara = Japan's "Suicide Forest" at the base of Mount Fuji, notorious worldwide as a site of death
- Kyun = Japanese onomatopoeia for a heartbeat/pang (ใญใฅใณ) โ common in anime
- MOEMOEKYUN = AS description referencing K-On! anime (่ใ่ใใญใฅใณ)
This company provides infrastructure for the Satanist's relays in three countries: Romania (93.113.25.109, near Bucharest), Netherlands (150.40.117.43, Amsterdam), and United States (45.38.20.213, Spokane Valley, Washington). A Romanian SRL routing IP space to the United States is highly unusual for a small provider and suggests a sophisticated understanding of BGP routing and remote IP justification at RIR level.
The aesthetic connection between Aokigahara SRL (death/suicide naming) and the Satanist (death-themed relay names) is too precise to be coincidental. Either:
- The Satanist chose Aokigahara SRL specifically because the naming resonated (customer with shared aesthetic)
- The Satanist is the operator of Aokigahara SRL (one person, multiple brands)
We cannot currently prove option 2. But the convergence of: death-themed naming, privacy cloud services, 2024 founding date, anime aesthetic overlap, and hosting of the Satanist's relays across three countries makes option 1 (pure coincidence of taste) insufficient as an explanation.
Chapter 6: The Saint Kitts Pattern
Three distinct entities in the 2cb.li ecosystem register in Saint Kitts and Nevis (KN), a Caribbean microstate with 47,000 inhabitants:
Charlestown, Nevis Convergence
| Entity | Address | Role |
|---|---|---|
| Mynymbox Hosting LLC | Hamilton Development, Unit B, Charlestown, Nevis, KN0802 | DNS/hosting for 2cb.li |
| allium.top registrant | Charlestown, Nevis, KN | Separate Tor relay operator |
| 1337 Services LLC | Saint Kitts & Nevis (RDAP) | ASN operator hosting relays |
Saint Kitts and Nevis offers: no MLAT with Germany for cybercrime, LLC formation under $500, minimal beneficial ownership disclosure, and no established precedent for EU cyber-crime extradition. The jurisdiction was chosen specifically for these gaps.
Consider the investigator's path: A German prosecutor investigating abuse from 185.132.53.121 must trace through: Tor Project (US, content-neutral) โ IP registered to AS211507 โ ASN operated by Julian Achter (Germany, but mere conduit) โ serving an operator identified only as "Satanist" โ paying in Monero through NymBox (Saint Kitts) โ domain in Liechtenstein with NymDNS (Saint Kitts). Every link is designed to break legal continuity.
Chapter 7: The allium.top Distinction
Prior analysis conflated allium.top with 2cb.li. The research definitively separates them:
Two Operators, Shared Providers
| Attribute | 2cb.li / Satanist | allium.top |
|---|---|---|
| Contact | admin@2cb.su | a78i2efsewr0neeknk@proton.me |
| XMR wallet | 85rXJTzRN2nAx...F23iUkm | 82sdVXSFUJcici...VjtPbEk |
| Relay names | death, dim, dark, die... | SieNCoAd, ASqUADeo, NgePTimE |
| Aesthetic | Death/drug themed | Random alphanumeric |
| Active relays | 27 | 3 |
| DNS | Mynymbox NymDNS | Njalla (Peter Sunde) |
| Registrant location | Unknown (NymDNS privacy) | Charlestown, Nevis KN |
| Shared ASNs | Both use AS53667 (FranTech) and AS210558 (1337 Services) | |
The allium.top operator is technically transparent (publishes relay costs via CIISS format: LiteServer โฌ3.75, rdp.sh โฌ5, BuyVM $7) and uses a Njalla privacy DNS (founded by Peter Sunde of The Pirate Bay). They share hosting providers with the Satanist but are a distinct individual with a different wallet, different naming convention, and different cultural aesthetic.
Both operators converge on Saint Kitts and Nevis for registration. Both use bulletproof hosting. Both accept Monero. The difference: allium.top operates 3 relays transparently; the Satanist operates 27 relays behind layers of identity erasure. Scale and opacity distinguish ideology from operation.
Chapter 8: The Phishing Subnet
The 45.154.98.0/24 subnet โ where allium.top previously operated (tor-exit-1.allium.top at 45.154.98.33, now relocated) โ reveals the character of bulletproof hosting:
PTR Record Archaeology โ 45.154.98.0/24
| Category | Count | Examples |
|---|---|---|
| RDP.sh branded | 30+ | ns1.rdp.sh, rdp.sh PTR records |
| Tor exit relays | 5+ | allium.top, 2cb.li |
| French bank phishing | 3+ | caisse-epargne-se-connecter.net |
| Turkish phishing | 30+ | Various domains |
| Crypto wallet phishing | Multiple | Wallet impersonation domains |
45.154.98.153 hosts caisse-epargne-se-connecter.net โ an active phishing page impersonating Caisse d'รpargne, France's largest savings bank (26 million customers). This domain cohabits with Tor exit infrastructure on the same /24 โ the bulletproof provider serves both with equal enthusiasm.
Chapter 9: The Zwiebelfreunde Contrast
To understand what the Satanist is, examine what they are not.
Ethical Spectrum of Tor Exit Operation
| Metric | Zwiebelfreunde e.V. | Cyberology | 2cb.li (Satanist) |
|---|---|---|---|
| Exit relays | 100 | 1 (133 Gbps) | 27 |
| Risk score | 18/100 | Low | 40-61/100 |
| Honeypot attacks | ZERO | None documented | Multiple confirmed |
| AbuseIPDB | Low | Low | 90-100% |
| Registration | German e.V. (non-profit) | Dutch KvK 93306199 | NymBox (KN, anonymous) |
| Raided | Yes (2018, later illegal) | No | Cannot be located |
| Hosting type | Legitimate | Legitimate | Bulletproof |
| Subnet neighbors | Clean | Clean | Active phishing |
Zwiebelfreunde was raided in 2018 โ later declared illegal by German courts. They accepted the legal risk of transparent operation and were vindicated. Cyberology operates the world's single largest Tor exit (133.9 Gbps) as a registered Dutch company. Both demonstrate that Tor exit operation does not require anonymity, bulletproof hosting, or offshore shells.
The Satanist chose: anonymous registration over transparency, bulletproof hosting over legitimate infrastructure, offshore shells over domestic accountability, a Soviet TLD over a mainstream registrar. The legitimate operator accepts risk. The bulletproof operator eliminates all possibility of accountability. This distinction is the finding.
Chapter 10: Operation Talent Survival and Domain Blackholing
Two enforcement events bracket the Satanist's operational timeline:
Enforcement Timeline
| Date | Event | Impact on Satanist |
|---|---|---|
| January 2025 | FBI Operation Talent seizes Cracked/Nulled | Zero impact โ transport โ content |
| September 2025 | 2cb.network registered at NameSilo | Post-Talent expansion |
| ~January 2026 | 2cb.li activated (was parked 10 years) | Infrastructure buildout |
| May 14, 2026 | 2cb.network blackholed by Dendrite/NameSilo | Domain loss, migrate to .su |
| June 2026 | 2cb.su active, all 27 relays operational | Full recovery in weeks |
Operation Talent targeted content platforms (forums, payment processors). The Satanist's transport infrastructure was structurally immune โ you cannot seize a Tor relay the way you seize a forum. The operation targeted specific servers; the Satanist has 27 across 16 providers.
The 2cb.network blackholing is more interesting. NameSilo suspended the domain via Identity Digital's Dendrite abuse system. This could be: registrar abuse response (most likely โ NameSilo has suspended bulletproof domains under pressure before), law enforcement request (possible but no press release), or voluntary migration (the operator had already prepared 2cb.su). The 8-month lifespan (September 2025 โ May 2026) matches the pattern of gTLDs being hostile to controversial content โ reinforcing why the operator maintains 2cb.li (privacy TLD) and 2cb.su (opaque TLD) as fallbacks.
Chapter 11: The Financial Model
The Satanist solicits Monero donations on every page of 2cb.su:
Financial Intelligence
| Asset | Value | Traceability |
|---|---|---|
| XMR wallet | 85rXJTzRN2nAx8yHFQmCFp...F23iUkm | Untraceable (RingCT + Stealth) |
| Monero node (.onion) | vm62zwfqrusvmej5...onion:18081 | Tor-only, no clearnet exposure |
| Old Monero node | zpoohy3efkpkcknw...onion:18081 | From 2cb.network era (Dec 2025) |
Cost Estimation (27 relays)
| Provider | Relays | Est. Monthly Cost |
|---|---|---|
| LAIN (AS211507) | 6 | โฌ60-180 |
| MAXKO d.o.o. (AS211619) | 3 | โฌ30-90 |
| Aokigahara/Kyun (AS215659) | 3 | โฌ30-90 |
| FranTech/BuyVM (AS53667) | 2 | $28-84 |
| Other 13 providers | 13 | โฌ130-390 |
| Total estimated | 27 | โฌ300-800/month |
At โฌ300-800/month, this is within reach of a single individual with modest income โ comparable to a car payment. The low cost makes several funding models viable: personal funds, XMR donations, Monero node service fees, or a combination. The infrastructure does not require external funding or commercial revenue to sustain.
The Monero node (accessible only via Tor v3 onion) could generate passive income from light wallet users who pay for remote node access. The operator explicitly describes running "privacy focused services" โ plural โ suggesting multiple revenue streams beyond relay operation alone.
Chapter 12: Cross-Corpus Intelligence
Searching our complete intelligence corpus (30+ investigations, 8,000+ IPs, 271,000+ entity links) reveals the Satanist connects to more prior investigations than any other single entity:
Intelligence Connections (12+ Investigations)
| Investigation | Connection | Type |
|---|---|---|
| TI-014 (Phase Layer) | Private Layer INC: same PA/CH jurisdictional split model | Pattern parallel |
| TI-019C (Outlaw) | Monero mining on compromised hosts โ same crypto economy | Ecosystem overlap |
| 019M (Operation Talent) | Adjacent infrastructure: RDP.sh, MEVSPACE, darknet hosting | Infrastructure adjacency |
| TI-2026-023A (VPN) | Zwiebelfreunde contrast: 100 exits, zero abuse, non-profit | Contrast case |
| TI-2026-023B (Backbone) | Private Layer HASSH overlap with Omegatech โ operational links | Shared tooling |
| TI-2026-024 (Omegatech) | Seychelles shell + bulletproof hosting โ parallel pattern | Pattern parallel |
| TI-2026-025A (SSH Parasite) | Monero mining on compromised infrastructure โ same economy | Ecosystem overlap |
| TI-2026-026 (PIO-Hosting) | Multi-jurisdiction shell game โ identical legal architecture | Pattern parallel |
| TI-2026-028 (MAXTV) | Geographic discrepancy technique โ same obfuscation method | Shared technique |
| 019L (Cyberology) | World's largest legitimate Tor exit โ contrast case | Contrast case |
| TI-007 (Supply Chain) | Private Layer in interlocking crime network model | Structural parallel |
| DOSSIER-PRIVATE-CUSTOMER-001 | Aokigahara SRL confirmed in separate investigation | Shared infrastructure |
This density is not incidental. The Satanist operates at the nexus where multiple threat ecosystems converge. Their relays serve as generalist transport infrastructure that enables specialists in phishing, darknet markets, botnets, and C2 operations to route traffic through a single anonymization layer. They are not a specialist โ they are a platform.
Chapter 13: What We Cannot Know
Intellectual honesty requires acknowledging opacity:
- Identity: One person or a group? The coordinated restart (all 27 relays, same day) and consistent aesthetic suggest a single mind. But we cannot prove this.
- Satanist = Kyun SRL? The death-themed naming overlap, 2024 founding timeline, and hosting relationship strongly suggest identity โ but could be mere aesthetic affinity.
- Motivation: Privacy ideology, commercial operation, intelligence collection, or criminal enterprise? The architecture is motive-neutral. All are possible simultaneously.
- Traffic monitoring: A Tor exit operator can log unencrypted traffic. 27 exits represent substantial surveillance capability if deployed by a state actor. No evidence either way.
- The 2cb.network blackholing: Law enforcement, registrar abuse action, or voluntary migration? The timing and preparation (2cb.su already active) leaves all three plausible.
- Relationship to Mynymbox: Customer, affiliate, or operator? The Charlestown convergence is suggestive but not conclusive.
Conclusions
The Satanist represents the maximum expression of the anonymity factory documented in this series:
- A single pseudonymous operator controls 27 Tor exit relays across 16 ASNs in 11 countries, generating ~4.5 Gbps of exit bandwidth
- The multi-layer anonymity stack (NymDNS + Saint Kitts shells + Monero + .su TLD + Tor) creates effectively unbreakable identity protection
- Bulletproof hosting (LAIN, Aokigahara/Kyun, MAXKO) specifically enables cohabitation with criminal infrastructure
- The legal framework in each jurisdiction creates gaps that, combined, form a comprehensive shield
- Legitimate operators (Zwiebelfreunde, Cyberology) demonstrate that the choice of bulletproof hosting signals intent beyond privacy advocacy
- Domain blackholing (2cb.network) proved ineffective โ the operator migrated to .su within weeks, all relays continued operating
- The 11-year domain dormancy (2cb.li, registered 2015, activated 2026) reveals patient planning
The connecting thread is not the technology. Tor is neutral. Exit relays are legal. Monero is legal. Offshore LLCs are legal. Each component, individually, serves legitimate purposes. The combination โ assembled to prevent any accountability for any activity โ is what makes this architecture notable. And the patient, deliberate, aesthetically unified deployment across multiple providers demonstrates not impulse but craft.
The Satanist didn't build the factory. They are its most dedicated customer โ and the proof that it delivers exactly what it promises.