October 10, 2026
Inside an Alleged Campaign of Cyberattacks Against the Powerscaling Community
An investigation into two online aliases, allegations of coordinated attacks, and the growing security concerns surrounding Discord's…

By Michael Jonhson
17 min read
Inside an Alleged Campaign of Cyberattacks Against the Powerscaling Community
An investigation into two online aliases, allegations of coordinated attacks, and the growing security concerns surrounding Discord's powerscaling community.
Disclaimer: This article documents allegations concerning online accounts identified as marksolos985, marksolos, mark, marz, and themarzer. The accounts are alleged to be associated with coordinated malicious activity targeting members and communities within the Discord powerscaling scene. Some incidents described below are reported to have supporting screenshots and confirmation from a server owner. Other claims remain unverified and should not be interpreted as independently established facts. This article does not claim to establish the real-world identities of the individuals behind these aliases.
- Introduction: When Online Rivalries Become Something More
Online communities are often built around shared interests, competition, debate, and social interaction. Within the powerscaling community, members debate the abilities of fictional characters, compare fictional universes, and construct arguments about intelligence, strength, cosmology, and other analytical categories.
Like many online subcultures, these communities can experience interpersonal conflicts, rivalries, harassment, and disputes over reputation.
However, there is a significant difference between participating in an argument and allegedly using cyberattacks, account compromise, extortion, or the exposure of private information against an opponent.
This investigation concerns two sets of online aliases: marksolos985, marksolos, and mark, and marz and themarzer. According to information provided for this article, these accounts are associated with two attackers who allegedly cooperate in targeting individuals and communities.
Their reported motivations include entertainment, personal retaliation, and financial gain. They are also alleged to have expressed an ideological hostility toward the powerscaling and debating communities, characterizing members of these communities as evil or predatory.
The available account suggests a pattern in which online disputes can escalate beyond ordinary community moderation and into activities with potentially serious consequences for victims.
The central questions are straightforward:
- What incidents can be documented?
- What evidence connects the two sets of aliases to particular attacks?
- What motivates the alleged activity?
- How are targeted communities affected?
- What can community administrators and members do to reduce their exposure to similar threats?
Answering these questions requires distinguishing reported incidents from independently verified findings.
- The Two Sets of Aliases
2.1. The first actor: Mark
The first actor is associated with the following aliases:
- "marksolos985"
- "marksolos"
- "mark"
According to the information supplied for this investigation, Mark is alleged to be involved in server disruption, unauthorized access to online accounts, harassment, extortion, and coordinated campaigns against Discord communities.
The reported activities also include the use of automation and social engineering to influence how other users and platform systems respond to targeted incidents.
These are serious allegations. Establishing them individually would require evidence linking particular accounts, actions, and incidents to the person or people responsible.
A username appearing in a screenshot, for example, does not necessarily establish who controlled the account at the time or who performed a particular technical action.
Consequently, the distinction between identifying an account and establishing responsibility for an attack is essential.
2.2. The second actor: Marz
The second actor is associated with:
- "marz"
- "themarzer"
According to the supplied account, Marz and Mark work together rather than operating exclusively as independent antagonists.
Their alleged cooperation is important because coordinated activity can create a substantially different security problem from isolated harassment.
When several accounts or individuals participate in the same campaign, responsibility may become more difficult to establish. One participant may communicate with a target, another may spread allegations, and another may engage in disruptive behavior.
Nevertheless, the existence and division of these roles must be established through evidence rather than inferred solely from similar behavior or overlapping social connections.
For this investigation, the relationship between Mark and Marz should therefore be examined through documented communications, incident timelines, account activity, and corroborating statements from people directly involved.
2.3. Why attribution matters
Online investigations frequently encounter a fundamental problem: the visible account is not always the person responsible for the activity associated with it.
Accounts can be compromised, impersonated, renamed, or controlled by someone other than their apparent owner.
A rigorous investigation should therefore distinguish between:
- Account identification: Which username appeared in a particular incident?
- Behavioral attribution: What actions can be connected to that account?
- Individual attribution: What evidence connects those actions to a particular person?
- Coordination: What evidence demonstrates cooperation between multiple participants?
- Motivation: What direct evidence, if any, establishes why the activity occurred?
These distinctions are particularly important when allegations involve account theft, malicious software, extortion, or unauthorized access.
- The Noblesse Incident: A Reported Turning Point
One of the principal incidents described for this investigation concerns Noblesse, identified as the Discord server associated with the powerscaling creator ZetaSolos.
According to the account provided, Mark targeted the community, disrupted its server, and banned numerous members through automated or scripted activity.
The incident is particularly significant because the information supplied states that screenshots exist and that the server owner confirmed the event.
That reported corroboration makes Noblesse an important starting point for reconstructing the alleged campaign.
However, the exact method, extent of the disruption, number of affected accounts, and attribution of individual actions should be documented separately rather than assumed from the overall account.
3.1. The alleged server disruption
The reported sequence begins with activity directed against Noblesse.
Mark is alleged to have used advanced scripts to disrupt the server and ban multiple members.
A Discord server can be affected by unauthorized administrative actions, compromised accounts, malicious applications, or abuse of legitimate permissions. Automation can also accelerate disruptive actions when an account or application has sufficient access.
The technical explanation matters because different causes require different evidence.
For example, establishing that a large number of members were banned would demonstrate disruption. Establishing that the bans were unauthorized would require additional context. Attributing those actions to a particular actor would require evidence connecting that actor to the relevant accounts or events.
A useful reconstruction would include:
- The approximate date and time of the incident.
- The number of affected members, if reliably documented.
- The administrative actions recorded in available audit logs.
- Statements from the server owner or administrators.
- Screenshots showing the relevant events.
- Any subsequent acknowledgment or communication attributable to the alleged perpetrator.
Such records would allow readers to distinguish the incident itself from claims about how it occurred.
3.2. The incident involving KD
According to the account provided, a moderator known as KD subsequently posted an image in a Noblesse public-service-announcement channel that was believed to depict Mark.
The account alleges that Mark retaliated against KD following the post.
The reported retaliation included doxxing, extortion, and pressure that ultimately resulted in KD deleting the image.
If corroborated, this would represent a substantial escalation from disruption of a community to targeting an individual associated with it.
The distinction is important.
A dispute involving a server can affect hundreds or thousands of users, but targeting a moderator personally can introduce additional risks involving privacy, safety, and coercion.
Doxxing generally refers to the unauthorized disclosure or dissemination of identifying or private information. Extortion involves coercive demands backed by threatened consequences. When these behaviors occur together, the affected person may experience pressure that extends well beyond the original online dispute.
The allegation that KD was pressured into deleting the image is particularly relevant to the reported sequence. However, the exact demands, threats, and circumstances should be established through appropriately preserved evidence.
Private identifying information should not be reproduced in this article. Demonstrating that private information was allegedly exposed does not require publishing that information again.
3.3. Why this incident matters
The Noblesse incident, as described, contains several distinct elements:
- Alleged disruption of a community.
- Alleged use of scripts to carry out administrative actions at scale.
- A subsequent dispute involving a moderator.
- Alleged retaliation directed at that moderator.
- Claims of doxxing and extortion.
- A reported continuing pattern of hostility toward the community.
Taken together, these allegations suggest a possible progression from collective disruption to personal retaliation.
That interpretation should remain provisional until the timeline and supporting evidence have been examined in detail.
Nevertheless, the incident provides a concrete framework for investigating the broader claims: identify the original disruption, establish what happened to KD, document the relationship between the events, and determine which subsequent incidents can be independently connected to the same actors.
- The Alleged Continuing Campaign Against Noblesse
The information provided states that Mark continued targeting Noblesse following the earlier incident.
The reported behavior includes raids, mass-reporting campaigns, and social engineering.
These allegations should be evaluated as separate categories because they involve different mechanisms, forms of evidence, and potential consequences.
4.1. Raids and coordinated disruption
A raid generally involves multiple accounts participating in disruptive activity against a community within a limited period.
Depending on the circumstances, this may involve spam, coordinated harassment, or attempts to overwhelm moderators and ordinary members.
Raids can interfere with legitimate discussion, force administrators to restrict access, and make a community difficult to use.
However, a sudden influx of disruptive accounts does not, by itself, establish who organized the activity.
Evidence of coordination might include contemporaneous communications, consistent timing, reliable platform records, or other information connecting the participants.
Where such evidence is unavailable, the article should describe the observed behavior without assigning responsibility beyond what the records support.
4.2. Mass reporting
Mass reporting is another alleged component of the campaign.
Reporting systems exist to help platforms identify policy violations. Their reliability depends partly on the quality of the reports and the platform's ability to evaluate context.
Coordinated or knowingly false reports can potentially be used to harass a target or trigger unnecessary investigations.
At the same time, multiple reports against a community are not automatically abusive. Different users can independently report genuine concerns, and an outside observer may not know what information the platform received.
A credible account of an alleged mass-reporting campaign should therefore establish more than the fact that a server or its members received reports.
Relevant evidence could include documented communications discussing a coordinated campaign, platform notifications, a verified chronology of related events, and statements from people who directly observed the activity.
The article should not publish operational instructions for manipulating reporting systems. The relevant issue is whether the systems were allegedly abused, not how another person could reproduce that abuse.
4.3. Social engineering and deception
Social engineering involves manipulating people into revealing information, granting access, or taking actions they would not otherwise take.
Unlike a purely technical attack, social engineering exploits trust, authority, urgency, confusion, or interpersonal relationships.
In online communities, it can intersect with impersonation, fabricated stories, misleading messages, or attempts to persuade moderators to make decisions based on incomplete information.
The supplied account characterizes Mark as particularly effective at deception and social engineering.
That characterization requires supporting examples.
A rigorous investigation would examine specific incidents, establish what was communicated, identify the person or account responsible where possible, and document the resulting consequences.
It would also distinguish deliberate deception from ordinary disputes, misunderstandings, and unverified suspicions.
4.4. Persistence and escalation
The reported persistence of the activity is another important question.
A single disruptive event and a sustained campaign are not equivalent. To establish a campaign, investigators need to demonstrate connections between incidents over time.
Those connections might involve repeated targeting of the same community, consistent methods, explicit statements of intent, or documented coordination.
If the evidence establishes that multiple incidents were connected, the timeline would help readers understand whether the activity escalated, changed direction, or continued in response to particular events.
The goal should be to reconstruct what happened, not simply to accumulate allegations into a single narrative.
- The Broader Technical Allegations
Beyond the Noblesse incidents, Mark and Marz are alleged to have engaged in a wider range of malicious activities affecting Discord users and communities.
The reported allegations include account compromise, malicious software, unauthorized access, server disruption, and information gathering.
These claims vary considerably in severity and should not be treated as equally established.
5.1. Token theft and account compromise
The information supplied alleges that the actors obtained authentication tokens belonging to multiple users.
Authentication tokens can allow software or services to maintain authenticated sessions. If a token is stolen and remains valid, an attacker may be able to misuse the associated session, depending on the platform's security controls and the token's privileges.
A compromised account can then become a source of further harm. Its apparent owner may be impersonated, private communications may be exposed, or actions may be performed without the owner's consent.
However, the term token logging is sometimes used loosely in online discussions.
To establish that token theft occurred in a particular incident, investigators would need evidence beyond suspicious account behavior alone. Relevant information might include platform security notifications, reliable forensic findings, or a documented connection between a compromised session and unauthorized activity.
Claims that particular actors collected tokens from many users should be supported by incident-specific evidence identifying the affected accounts and the basis for attributing the compromise.
5.2. Remote-access malware and information stealers
The supplied account also alleges the use of remote-access trojans, commonly abbreviated as RATs, and information-stealing malware.
These are distinct categories of malicious software.
A remote-access trojan can provide unauthorized remote control over an affected system. Information stealers are designed to collect data from a compromised device, potentially including saved credentials or browser information.
The exact capabilities depend on the malware involved, its configuration, the operating system, and the security controls present on the device.
If the reported use of these tools is substantiated, the consequences could extend beyond a single Discord account.
A compromised computer may contain browser sessions, saved credentials, personal files, and access to other online services. The extent of exposure would depend on the circumstances of the compromise.
However, the presence of malware on a victim's device does not, by itself, identify who deployed it.
Establishing responsibility would require a defensible connection between the malware, the incident, and the alleged actor.
It would also be inappropriate to attribute every compromised account within a community to the same people without supporting evidence.
5.3. Server nuking
The term server nuking is commonly used online to describe severe disruption of a Discord server, potentially involving the deletion of channels, changes to server configuration, mass bans, or other destructive administrative actions.
The term describes an outcome rather than a specific technical method.
A server can experience destructive administrative activity because of compromised moderator accounts, misuse of permissions, malicious applications, or other security failures.
Consequently, investigators should distinguish between evidence that a server was disrupted and evidence establishing how the disruption occurred.
Where an incident involves multiple administrative actions, a timestamped audit-log record may help reconstruct the sequence.
Where a privileged account was compromised, additional evidence may be needed to distinguish actions performed by its legitimate owner from actions performed by someone else.
5.4. Open-source and publicly available intelligence
The allegations also refer to advanced OSINT and CSINT.
OSINT, or open-source intelligence, involves gathering and analyzing information from publicly available sources.
CSINT is used in some online communities to refer to cyber-social intelligence: the collection and analysis of information about online identities, relationships, behavior, and activity. Its meaning is not entirely standardized, so the article should define precisely what it means when using the term.
Public information can be used for legitimate research and security investigations. It can also be misused to identify targets, connect accounts, or facilitate harassment.
The critical distinction is between collecting information lawfully for a legitimate purpose and using information to facilitate coercion, unauthorized access, or the exposure of private details.
The supplied account characterizes the actors' intelligence-gathering capabilities as advanced. That claim should be supported by documented examples rather than technical labels alone.
The article should also avoid reproducing sensitive information, publishing investigative techniques that could endanger victims, or providing a roadmap for locating private individuals.
5.5. Claims of sophisticated attack capabilities
The overall allegation is that Mark and Marz possess substantial technical knowledge and combine several forms of malicious activity.
That characterization may be worth investigating, but technical sophistication should not be inferred solely from the impact of an incident.
For example, a destructive outcome does not necessarily imply the use of an exceptionally advanced exploit. Abuse of an already privileged account can sometimes produce significant damage.
Likewise, a large number of affected users does not automatically establish that the activity required unusual technical expertise.
A more useful assessment would examine what occurred, what access was required, what evidence exists about the methods used, and whether the same methods appeared in multiple independently documented incidents.
This approach avoids both exaggerating the alleged capabilities of the actors and understating the consequences for their victims.
- Alleged Attacks Beyond Individual Discord Communities
The information provided suggests that the two actors may have targeted additional Discord servers, including large communities.
It also raises the possibility that they may have been involved in breaches of government websites.
These are separate claims and require different standards of evidence.
6.1. Alleged attacks on additional servers
If multiple servers were affected, each incident should be documented individually.
A useful incident record would contain:
- The community or organization affected.
- The approximate date of the event.
- The nature of the disruption.
- The evidence supporting the account.
- The basis for attributing responsibility.
- Any corroboration from administrators or other witnesses.
- The status of the claim: confirmed, corroborated, disputed, or unverified.
This would make it possible to determine whether the incidents form a coherent pattern.
It would also prevent unrelated attacks, impersonation incidents, and ordinary moderation disputes from being incorrectly attributed to the same people.
6.2. The allegation concerning government websites
One of the most serious claims is that the actors may have breached government websites.
At present, this should be described as an unverified allegation, unless additional evidence can establish otherwise.
A claim of a government website breach requires considerably more than an online boast or an assertion made by a third party.
Useful evidence might include an official incident statement, a credible technical investigation, a verifiable security advisory, or reliable documentation of unauthorized access.
Even when a website experiences a security incident, that does not automatically establish who was responsible.
The distinction matters because allegations involving government systems can have significant legal and reputational consequences.
Without reliable corroboration, it would be misleading to present this claim as an established part of the actors' history.
For the purposes of this investigation, the appropriate next step is to determine whether any credible documentation exists and, if so, what it actually establishes.
- Motivation: Entertainment, Retaliation, Money, and Ideology
According to the information supplied, the reported motivations behind the activity include entertainment, personal retaliation, and financial gain.
A further allegation is that the actors regard the powerscaling and debating community as morally objectionable and want to eliminate its servers.
These potential motivations should be examined separately.
7.1. Entertainment
Malicious online behavior can sometimes be driven by the desire to provoke reactions, disrupt communities, or demonstrate control over a target.
In such cases, the disruption itself may become the reward.
However, it is difficult to establish a person's internal motivation from behavior alone. A claim that an attack was carried out for entertainment is strongest when supported by direct communications or other evidence attributable to the person involved.
If the actors have explicitly described attacks as entertaining, the relevant statements could help establish this motive, provided their authenticity and context can be verified.
7.2. Personal retaliation
The alleged events involving Noblesse and its moderator raise the possibility of retaliation following interpersonal conflict.
According to the supplied account, the incident involving KD occurred after a photograph believed to depict Mark was posted in the server.
If the sequence is corroborated, it would be important to determine whether subsequent activity was explicitly linked to that incident.
A documented retaliatory motive would help explain why a particular individual or community was targeted. It would not, by itself, prove responsibility for every subsequent attack.
The distinction between motive and attribution remains essential: a person may have a reason to target someone without being responsible for every harmful event that follows.
7.3. Financial gain
Financial gain is another reported motivation.
The allegation of extortion involving KD is particularly relevant to this possibility, although the exact circumstances and any financial demands would need to be documented.
Extortion differs from ordinary financial disputes because it involves coercion. Depending on the facts and applicable law, threats used to obtain money or force a person to take an action can have serious legal implications.
A rigorous account should establish what was demanded, what was threatened, how the demand was communicated, and whether the evidence connects the communication to the alleged actor.
The article should not assume that every alleged attack was financially motivated simply because financial gain is among the broader reported objectives.
7.4. Ideological hostility toward the community
The supplied account also alleges that the actors have characterized members of the powerscaling and debating communities as evil or predatory, including by using the phrase "evil pedos."
It further alleges that one of their objectives is to eliminate servers within that community.
If authentic statements establish that the actors explicitly expressed this objective, those statements could provide important context for understanding the reported targeting.
However, an accusation directed at an entire community is not evidence that the accusation is true.
Nor does the presence of a stated ideological motive establish that every person or server targeted was selected for that reason.
The investigation should preserve the distinction between an actor's stated beliefs, the evidence supporting those beliefs, and the actual conduct attributed to the actor.
A community's members should not be presumed guilty of serious misconduct because an alleged attacker characterizes them that way.
- What the Noblesse Case May Reveal About Community Security
The reported Noblesse incident raises questions that extend beyond the individuals involved.
Discord communities frequently depend on a relatively small number of administrators and moderators to maintain order, manage permissions, respond to incidents, and protect members.
That concentration of responsibility can create vulnerabilities when privileged accounts are compromised or when administrators become targets of harassment.
The lessons below are general security considerations, not claims that any particular measure would have prevented the incidents described.
8.1. Administrative access should be limited
Server administrators should periodically review which accounts and applications possess elevated permissions.
People who no longer need administrative access should not retain it indefinitely. Applications should be reviewed to ensure that their permissions match their legitimate purpose.
Limiting unnecessary privileges can reduce the damage caused by a compromised account or misconfigured application.
8.2. Account security matters
Moderators and administrators should use strong, unique passwords and available multifactor authentication protections.
They should be cautious about unexpected files, suspicious links, fake verification requests, and applications that request excessive permissions.
If an account is suspected of being compromised, its owner should secure the associated account and review relevant security settings using official platform guidance.
8.3. Incident records should be preserved
When a server experiences a serious incident, administrators should preserve relevant records before they disappear.
These may include audit logs, timestamps, platform notifications, screenshots, and communications from affected users.
Records should be stored securely, with access limited to people who need them.
The preservation process should avoid exposing victims' private information to a wider audience.
8.4. Moderators need support
Moderators often occupy a difficult position: they are expected to protect a community while managing disputes that can become personally hostile.
If a moderator is targeted, the response should not depend entirely on that individual.
Other trusted administrators can help preserve evidence, secure accounts, communicate with affected members, and report incidents through appropriate channels.
A coordinated response can reduce the pressure on an individual who may already be dealing with harassment or coercion.
8.5. Public accusations require care
Communities should be able to discuss credible security incidents without turning suspicion into certainty.
Publicly accusing someone of a serious offense without adequate evidence can harm innocent people, complicate investigations, and undermine the credibility of legitimate warnings.
The answer is not to remain silent about every incident. It is to communicate carefully.
A useful report explains what happened, what is known, what remains uncertain, and where the evidence comes from.
That standard protects both the people reporting misconduct and the people who could otherwise be wrongly accused.
- Documenting the Allegations Responsibly
An investigation of this kind depends on the quality of its records.
Screenshots can be useful, but their evidentiary value depends on context, authenticity, and corroboration. A screenshot may show that a message appeared in a conversation without establishing who controlled the account or whether the message accurately describes an event.
Similarly, a statement from a server owner may corroborate an incident without independently establishing every technical detail or identifying the person responsible.
For each reported event, the investigation should answer five questions.
What happened?
Describe the observable event without adding assumptions.
When did it happen?
Establish an approximate date and time, using original records wherever possible.
What evidence supports the account?
Identify whether the information comes from screenshots, audit logs, direct witnesses, platform notifications, or other records.
Who is alleged to be responsible, and why?
Explain the specific evidence connecting the incident to a particular account or individual.
What remains unknown?
State any gaps, disputed details, alternative explanations, or unverified claims.
These questions should be applied consistently, including when the available evidence appears to support an allegation.
Evidence-based reporting does not require treating every explanation as equally plausible. It requires making the reasoning behind a conclusion visible to the reader.
- What This Investigation Has—and Has Not—Established
Based on the information currently available to the author, the Noblesse incident is the principal reported event for which screenshots and confirmation from a server owner are said to exist.
The supplied account describes a sequence involving server disruption, the banning of members, an incident involving moderator KD, and subsequent alleged retaliation.
Those materials should be examined to determine precisely which parts of the sequence are corroborated and what they establish about responsibility.
Other allegations—including the use of remote-access malware and information stealers, widespread token theft, attacks against numerous additional servers, and possible breaches of government websites—require their own supporting evidence.
The distinction is not a technicality.
A documented incident can justify concern without proving every allegation made about the people associated with it.
Likewise, uncertainty about one allegation does not automatically invalidate independently documented evidence concerning another.
The most useful approach is to investigate each claim on its own merits and then determine whether the evidence supports a broader conclusion about coordination and recurring behavior.
- Conclusion: Evidence Is Stronger Than Escalation
The allegations concerning Mark and Marz describe a potentially serious pattern of online misconduct, ranging from disruptive activity against Discord communities to claims of personal retaliation, extortion, and technical compromise.
The reported Noblesse incident provides a starting point for examining those allegations because supporting screenshots and a statement from the server owner are said to exist.
If the alleged retaliation against KD and the subsequent targeting of Noblesse are corroborated, they would raise important questions about the use of private information and coercion in online community disputes.
The broader technical allegations deserve equally careful examination. Claims involving stolen authentication tokens, malicious software, large-scale attacks, and government systems should be supported by reliable documentation rather than repeated as established facts.
The objective should not be to create an exaggerated image of supposedly unstoppable attackers. It should be to establish what happened, identify the people responsible where the evidence permits, understand the consequences, and help affected communities protect themselves.
Online communities should not have to choose between ignoring credible threats and engaging in uncontrolled cycles of accusation and retaliation.
They need accurate information, responsible reporting, secure administration, and support for the people affected.
Ultimately, the credibility of an investigation depends not on how alarming its allegations sound, but on how carefully it demonstrates what it claims to know.
The next step is to examine the evidence, incident by incident, and let the documented facts determine the conclusions.