fun way to mess with these people?To some extent yes, give them a status 200 for anything they send at you, especially for your default catch-all domain/IP/virtual-host. In NGinx this looks like
error_page 404 500 501 502 503 504 =200 /some_generic_message.html;
I would personally just disable fail2ban. It just consumes more CPU especially if using it with iptables. If using
ip route blackhole {ip} its not as bad but still a waste of time in my opinion. There are enough known compromised hosts out there to add millions of entries to your routing table ahead of time. [1]
Add headers and content to the generic message file that has links to URL's like WordPress, wp_login.php, wp-story.php, js/file-uploader, nf_tracking.php, about.php, wp-reset.php and others. To minimize writes on your disk, set custom logs for your default virtual-host/IP/domains to either write into a tmpfs ram disk or to /dev/null once you get bored watching them. If writing to tmpfs be sure to set up a more frequent log rotation and less retention. Be sure to also set the HTTP keepalive time very low so they are not wasting your resources. No need to tarpit them, most of the code used by these bots will time out after a few seconds.
[Edit] I should add, these are not hackers you are messing with. They are just parasitical script-kiddies that prey on the weak, most often using their batches of WordPress hosts as jump-off points and watering hole phishing sites to scam the elderly out of their life savings.
Making them lose money would be great too!
That's much harder. Most of the IP's you see do not belong to the attacker. The attacker is likely using a set of Command and Control C&C nodes that control a swath of end-user PC's and Wordpress servers infected with malware. Anything you do will cost them nothing but it might slow their threads down a little. The only way to make them lose money would be to find who is controlling the C&C nodes, gather evidence and have law enforcement take them down. To do this one would have to break the law by hacking into the compromised host and see what C&C nodes it is dialing home to, then hack into those hosts and see who is connecting to them. They could be using Tor but most people are lazy enough to not do this.
[1] - https://github.com/firehol/blocklist-ipsets.git