Enlisted Submarine Warfare Insignia
← Back to Blog

The Reality of Hacker Communities

June 30, 2026 6 min read

A casual Discord link became a full triage exercise. Joe Sandbox, urlscan.io, BL Networks, BTCPay Server abuse, and what it all says about who is actually in the room with you.

Hacker-community Discords are some of the best places on the internet to learn. Somebody asks a question, somebody else drops a link, and a newcomer walks away with tools they would not have found on their own. That low-friction tool-trade is the whole point of being there.

It is also why some of the most dangerous links you will ever see show up in the same channels. The norm that gets a beginner a useful OSINT bookmark is the same norm that gets them a credential-harvesting page wrapped in a friendly recommendation. You cannot always tell which is which from the message.

I had one of those moments this week. A newcomer in a community channel said they were getting into security and asked what tools and resources people use. I dropped my OSINT and web-recon bookmarks. A few messages later, another member posted hxxps://wormgpt[.]zip and described it as a helpful AI tool for red team operations.

I do not know what that person was thinking. They could have grabbed the link from somewhere, taken the marketing at face value, and recommended it without checking. Or they could have known exactly what was behind it and recommended it anyway, with a beginner watching. From one Discord message, you cannot tell. That is the reality of these communities. Good and bad share the same room, and they look the same in chat.

So I pulled the URL into urlscan.io and ran the rest through everything else I had, because "helpful red team tool" from an unverified rec is not a recommendation I take on faith, especially when the brand on the page is named after a piece of cybercrime LLM software. What came out the other end was a fully productized scam operation, with every layer picked for anonymity, irreversibility, or takedown resistance.

The first ten seconds of triage

Three things stood out before I touched a sandbox.

The TLD was .zip. Google opened that TLD to the public in 2023 and it immediately became abuse central because browsers and chat apps autolink filenames like report.zip into clickable URLs. Anything serious on .zip is rare. Anything on .zip calling itself a hacking tool is a red flag by default.

The domain was ten days old. New domains are not automatically bad, but new domains pretending to sell paid software are.

The brand was WormGPT. The original WormGPT was a jailbroken GPT-J variant sold on hacking forums in 2023 for BEC, phishing, and malware authoring. The name has criminal history. Anything carrying it and marketing itself as an "ethical hacking AI" is either the original tool, a clone, or a lure pretending to be one.

A Malwarebytes reputation check came back suspicious with the 10-day-old domain age called out. That was enough for me to recommend nobody touch it. But I wanted to know what was actually on the other side, especially with a newcomer in the channel who might not have known better.

Joe Sandbox tells the rest

Detonating the URL in Joe Sandbox gave me the verdict: phishing on Windows, score 48 out of 100, confidence 100%. The AI signature fired with "AI detected malicious page (phishing or scam)."

The attack is a credential harvest stacked on top of a crypto theft. The /buy page presents a fake checkout asking for username and password, plus a delivery channel (Telegram, Discord, or email) for where you want your "credentials" sent. That is identity theft pretending to be a delivery option. Once you hit "Proceed to Bitcoin Payment," an iframe loads a payment modal from btcpay[.]amatuerfans[.]com and the page fires the browser's bitcoin: URI handler with an attacker-controlled wallet and a 0.00100614 BTC amount.

That is roughly a hundred dollars. Small enough that someone curious enough to find this page might actually pay it.

The pivot is where it gets interesting

wormgpt[.]zip is the lure. The infrastructure is amatuerfans[.]com. That domain was registered seven weeks before the storefront went live, by a registrant in Saint Kitts and Nevis, through Tucows, with Cloudflare DNS in front. The fact that the payment backend was prepped a month and a half before the storefront went up tells you this is not somebody's first try.

The backend IP is 168.100.10.129. It is hosted at BL Networks, ASN 399629, in Amsterdam. BL Networks is the public name for BitLaunch.io, a VPS reseller that advertises "anonymous Bitcoin VPS." You pay hourly in BTC, LTC, or ETH, and they front DigitalOcean, Linode, or Vultr behind the scenes so the underlying provider never sees the customer. BushidoToken's 2025 CTI research linked BitLaunch to Cobalt Strike C2 infrastructure and ransomware operations.

The SSL cert on the box is self-signed with subject CN=letsencrypt-nginx-proxy-companion. That is the default fallback cert from the jrcs/nginx-proxy plus acme-companion Docker stack, which is the exact deployment pattern in the official BTCPay Server install script. Both port 80 and 443 return 503 to direct IP visits because nginx is doing virtual-host routing and refuses unknown Host: headers. Translation: this same server is probably hosting payment backends for more than one front domain. I could not enumerate them from free tools, but Censys queries on the cert subject or Shodan queries on the SSH host key fingerprint (cc352487ca550a2e55cb1d4d118350405bd261c7a51deffb6e07fbc67be4be0e) would likely get there.

The operator stack

Look at it as a single design:

Every layer is replaceable except the BTC wallet. When wormgpt[.]zip gets reported and goes down, the actor spins up a new storefront, points it at the same BTCPay backend, and keeps going. BTCPay's own team has documented this exact pattern on their official blog under the "Bitcoin Bonus" scam name. The storefront is disposable. The backend is the real infrastructure.

Back to the community

I dropped the findings back into the channel. A few people thanked me. The newcomer got to watch the triage happen in real time, which is probably more useful than the bookmarks I posted in the first place. That part felt good.

What I keep thinking about is the gap between the two messages. One person showed up to help a beginner. Another person recommended a credential-harvesting page as a useful red team tool. They were sitting in the same channel, talking to the same new person, and from the outside the messages looked identical. Both were framed as "here is something you should check out."

That gap is the reality of hacker communities. Most people are there to learn or to teach. Some are there to phish or to recruit. Most of the time you cannot tell the difference from a single chat message, and a brand-new member definitely cannot.

A few rules I have settled on:

Treat every shared link as untrusted, including links from people you trust. They might be sharing it the same way you would, as "look at this." That is not an endorsement, it is a request for triage.

Run it through a sandbox before clicking. Joe Sandbox, ANY.RUN, and urlscan.io all have free tiers. Two minutes of detonation beats two days of incident response.

Share the verdict back. The community gave you the link. Give them the finding. It costs nothing, it teaches the newcomers what good triage looks like, and it makes the room incrementally safer for the next person who walks in green.

And if the link turns out to be productized criminal infrastructure with a six-layer anonymity stack behind it, write it up. Somebody else will hit the same lure next week.

IOCs (defanged)

Type Indicator
Domain wormgpt[.]zip
Domain btcpay[.]amatuerfans[.]com
URL hxxps://wormgpt[.]zip/buy
IP 172.67.186.136 (Cloudflare-fronted storefront)
IP 168.100.10.129 (BTCPay origin, BitLaunch / BL Networks NL)
ASN AS399629 (BL Networks / BitLaunch)
BTC wallet bc1qexterk3gk9jg4xp2n7casau4kcpenm4dhhjsmh
BTCPay Store ID 7Y8bUWoUy94FfyTjCWw19peQ9VAoK1kiymTfRDxKY5jB
SSH host key cc352487ca550a2e55cb1d4d118350405bd261c7a51deffb6e07fbc67be4be0e
discord community osint threat-intel scam-analysis phishing btcpay wormgpt joe-sandbox