My Top 10 Favorite CIA & NSA Subdomains

Chris Kubecka
6 min readMay 24, 2023

Interesting discoveries over the years using Robtex & Censys.io

Back in the B.C. (Before Covid times) 2017. I ran a workshop 1 day course for Security BSides Las Vegas. It was an OSINT course, mostly focused on intelligence agencies worldwide. Using a bunch of fun tools plus a bit bash, PowerShell, python, etc. Whist setting up the labs I went down a rabbit hole and discovered oh so many funny, trolling subdomains. Wanting a fun experience for all participants, what’s cooler than peering safely into shadowy, elite organizations on the web? Plus I find people learn more effectively if they can have fun whilst doing it.

Now it’s a hobby to periodically scan key intelligence agencies utilizing tools that are legal in the Netherlands. By utilizing already scanned data, using no pinging or destructive means.

The Top Ten List

10 OSINT is magical

Was it named in homage to the film by the NSA?

A fun little one found was abracadabra. Might be a bit of a fan of the movie Half Baked. However, some technologists do seem to have magical digital powers.

9 Is there truth behind the conspiracy theory?

From Robtex 2017

For years there were rumors among some in the hacker / technologist scene that thought maybe, just maybe. The person or persons behind the handle the3j35tr which is the Jester in leetspeak. might actually be working for the US government. Many in the hacker community seem naturally more paranoid versus other groups I’ve encountered. Rumors like this should be take with a grain of salt. However, it is rather odd that both the NSA and CIA have subdomains dedicated to this legendary hacktivitst who is rumored to be a sponsored by the US government.

More about him/her/them at:

8 They are watching you

From Robtex 2017

Randy Maugans discusses conspiracy theories as part of his YouTube and social media. His show, OffPlanet Radio, often delves into topics that challenge mainstream narratives and explore alternative explanations for various phenomena. Randy engages in conversations with guests who delve into subjects such as government secrecy, hidden agendas, covert operations, and other controversial topics that are often categorized as conspiracy theories. Randy has spoken out before how he believes the US government is watching him.

Apparently Randy was right about one thing, the CIA is watching him. Sorry Randy.

7 Strong Lady Fandom… or not

Ode to a strong, smart lady. Robtex 2017

Most of us live in sexually repressed societies with a massive “whore-virgin dichotomy”. Nearly everyone consumes porn, nearly everyone pretends they don’t. Even ChatGPT is too prudish to help me edit #7! However, There is a history within the NSA to recognize strong women who’ve done porn. Hedy Lamarr filmed the first female orgasm scene and later invented technology involving spread-spectrum-frequency-hopping which was incorporated into Bluetooth, GPS and older versions of WiFi.

In 2013 Belle Knox confided a secret her “friend” Thomas Bagley. How she was paying for university without taking on crippling loans. Thomas Bagley broke her confidence that evening in the worst way, to all his Duke University Phi Delta Theta frat bros and the news spread like wildfire. The betrayal have devastating consequences for Belle. She suffered massive harassment, bullying and doxxing. Thomas Bagley, who now works at Microsoft as a senior software engineer. later publicly regretted his actions after he started to get backlash for being a bit of a dick. Thomas’s actions also prompted Porn CEO Mike Kulich to write him an invitation letter featuring the gems “someone who subscribes to a site like Facial Abuse I want to commend you for spending the $200 a week your parents send you every week” and “ALSO, for every inch you are packing over 4, I will throw in an EXTRA $1,000. Get your tiny pecker out here and become the next Ron Jeremy kiddo!

Or someone in the NSA setup a creepy server to download and store all of Belle Knox’s works. I’ll let you decide…..

6 Even secret agents have a sense of humor

From Censys.io May 2023
Robtex confirming it indeed belongs to the CIA May 2023

Yes, this is a real system owned by the CIA. Sometime the internet makes you laugh.

5 Douchery Abounds

Robtex 2017

The NSA used to have a series of Douchery related subdomains. Don’t know what was going on there at the time, but they make me chuckle.

4 Star Trek Fandom

The previous NSA Director has=d this Star Trek themed command center built. This is an actual picture of it
Robtex 217

Why Does the NSA Control Center Look Like the Bridge From Star Trek? Well, lots of tehcnologically curious folks are into Star Trek. Some technologies we have today were inspired by the TV show and movies. The NSA are fans. Its not that strange to find other fan subdomains especially Lord of the Rings and Marvel. If I was the Director of the NSA, damn skippy I’d have a Star Trek command center.

3 NSA has no love for Script Kiddies

I prefer the term Script Kitty
Robtex 2017

The NSA used to have several subdomains calling out or jesting about Script Kiddies. Kinda made me imagine grumpy old NSA hackers telling them to get off their digital lawn. Gotta have fun with tech, especially when you work for any government.

2 Snowden was right!

Actual Prism servers 1 was located in the Netherlands. Robtex 2017

Remember that guy named Edward Snowden who revealed the NSA was perhaps illegally collecting data on people it shouldn’t? One of the programs he revealed was called Prism. These were that actual Prism servers Snowden discussed, but I was able to prove existed. I‘ve discovered more systems on the internet that are tied to various projects leaked by Edward Snowden over the years. They’re watching us, why shouldn’t we watch them?

1 0 The NSA expressing its love for the Iranian government

The only Iranian Government attire approved for women
Robtex 2017

The Iranian people are great, the government not so much. Ask the average Iranian woman what she thinks about the regime….Oh wait, the Iranian government is too busy arresting, disappearing, executing or poisoning them. The Iranian government and the US have not been bitter enemies after their catastrophic divorce in the late 1970’s. Apparently the NSA don’t think too highly of the Iranian government. Hence the naming of this subdomain.

If you’d like to discover more, use a few tools like Robtex and Censys.io. Or check out some of the tools listed on GitHub. Most of these subdomains are now sadly hidden away in various cloud services, hidden away from the hacker curious public.

--

--

Chris Kubecka

Author, Hacker, OSINT Junkie, Security Researcher, CEO of HypaSec. @SecEvangelism Passionate about cyber warfare, digital security, hacking, AI & privacy.