if it was behind whonix, all outside traffic would be routed through tor. One of its selling points is that malware running on the VM as root cannot get the real IP (without additional exploits).

Whonix is great but the fact you need two servers and how the set up is more involved than just installing Tor and setting up a Hidden Service are the most common reasons why most takes the easy but less secure route.

Whonix is amazing. I recommend it to anyone who is serious about avoiding even sending a single packet over the clearnet.

Even doing it on a single server is more secure than whatever these guys had. You can only be found if there's an actual exploit in the VM or tor or something, webserver bugs don't pwn you alone.

