Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I've noticed a very slow trickle of fake accounts registering at my instance recently.

I've noticed a very slow trickle of fake accounts registering at my instance recently.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
mastoadminfediadmin
10 Indlæg 10 Posters 55 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • sb@metroholografix.caS This user is from outside of this forum
    sb@metroholografix.caS This user is from outside of this forum
    sb@metroholografix.ca
    wrote sidst redigeret af
    #1

    I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

    - they have somewhat convincing usernames
    - semi-reasonable descriptions
    - emails on custom domains (Hetzner vps usually)
    - unique IP per account (often same subnet)
    - uploads a profile pic & banner image
    - some of them boost a few posts from admin acct

    But then these accounts just sit there. They aren't spamming. What is their goal?

    #mastoAdmin #fediAdmin

    hipsterelectron@circumstances.runH dbrand666@mastodon.socialD paul@oldfriends.liveP quasit@kolektiva.socialQ kinetix@humanwords.partyK 9 Replies Last reply
    0
    • sb@metroholografix.caS sb@metroholografix.ca

      I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

      - they have somewhat convincing usernames
      - semi-reasonable descriptions
      - emails on custom domains (Hetzner vps usually)
      - unique IP per account (often same subnet)
      - uploads a profile pic & banner image
      - some of them boost a few posts from admin acct

      But then these accounts just sit there. They aren't spamming. What is their goal?

      #mastoAdmin #fediAdmin

      hipsterelectron@circumstances.runH This user is from outside of this forum
      hipsterelectron@circumstances.runH This user is from outside of this forum
      hipsterelectron@circumstances.run
      wrote sidst redigeret af
      #2

      @sb scary.....

      1 Reply Last reply
      0
      • sb@metroholografix.caS sb@metroholografix.ca

        I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

        - they have somewhat convincing usernames
        - semi-reasonable descriptions
        - emails on custom domains (Hetzner vps usually)
        - unique IP per account (often same subnet)
        - uploads a profile pic & banner image
        - some of them boost a few posts from admin acct

        But then these accounts just sit there. They aren't spamming. What is their goal?

        #mastoAdmin #fediAdmin

        dbrand666@mastodon.socialD This user is from outside of this forum
        dbrand666@mastodon.socialD This user is from outside of this forum
        dbrand666@mastodon.social
        wrote sidst redigeret af
        #3

        @sb
        Any important elections coming up?

        1 Reply Last reply
        0
        • sb@metroholografix.caS sb@metroholografix.ca

          I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

          - they have somewhat convincing usernames
          - semi-reasonable descriptions
          - emails on custom domains (Hetzner vps usually)
          - unique IP per account (often same subnet)
          - uploads a profile pic & banner image
          - some of them boost a few posts from admin acct

          But then these accounts just sit there. They aren't spamming. What is their goal?

          #mastoAdmin #fediAdmin

          paul@oldfriends.liveP This user is from outside of this forum
          paul@oldfriends.liveP This user is from outside of this forum
          paul@oldfriends.live
          wrote sidst redigeret af
          #4

          @sb A lot of times, nefarious accounts just sit idle for a long time before being called into action.

          It's also worthy to note, with Mastodon, users can setup interactions to be filtered under a special area in notifications for news accounts, as well as other settings... So, if a new account tries to send spam within the first 30 days, it will get filtered behind a special area in notifications. They could be for future nefarious use,

          1 Reply Last reply
          0
          • sb@metroholografix.caS sb@metroholografix.ca

            I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

            - they have somewhat convincing usernames
            - semi-reasonable descriptions
            - emails on custom domains (Hetzner vps usually)
            - unique IP per account (often same subnet)
            - uploads a profile pic & banner image
            - some of them boost a few posts from admin acct

            But then these accounts just sit there. They aren't spamming. What is their goal?

            #mastoAdmin #fediAdmin

            quasit@kolektiva.socialQ This user is from outside of this forum
            quasit@kolektiva.socialQ This user is from outside of this forum
            quasit@kolektiva.social
            wrote sidst redigeret af
            #5

            @sb

            Whatever it is, I wouldn't count on it being anything good! Something smells like billionaire to me...

            1 Reply Last reply
            0
            • sb@metroholografix.caS sb@metroholografix.ca

              I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

              - they have somewhat convincing usernames
              - semi-reasonable descriptions
              - emails on custom domains (Hetzner vps usually)
              - unique IP per account (often same subnet)
              - uploads a profile pic & banner image
              - some of them boost a few posts from admin acct

              But then these accounts just sit there. They aren't spamming. What is their goal?

              #mastoAdmin #fediAdmin

              kinetix@humanwords.partyK This user is from outside of this forum
              kinetix@humanwords.partyK This user is from outside of this forum
              kinetix@humanwords.party
              wrote sidst redigeret af
              #6

              @sb
              Possibly data harvesting while waiting for some command?

              I think IFTAS had a post quite recently about a whole botnet that's creating tons of accounts, behaving kind of normally for awhile before they start doing... whatever it is they start doing (wow, having a short sleep is doing wonders for the memory).

              1 Reply Last reply
              0
              • sb@metroholografix.caS sb@metroholografix.ca

                I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

                - they have somewhat convincing usernames
                - semi-reasonable descriptions
                - emails on custom domains (Hetzner vps usually)
                - unique IP per account (often same subnet)
                - uploads a profile pic & banner image
                - some of them boost a few posts from admin acct

                But then these accounts just sit there. They aren't spamming. What is their goal?

                #mastoAdmin #fediAdmin

                troy@opencoaster.netT This user is from outside of this forum
                troy@opencoaster.netT This user is from outside of this forum
                troy@opencoaster.net
                wrote sidst redigeret af
                #7

                @sb definitely will be used later. Had that happen here, they’d look legit for a while then start spamming. Luckily recently for me all of the spam signups have been pretty dang obvious.

                1 Reply Last reply
                0
                • sb@metroholografix.caS sb@metroholografix.ca

                  I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

                  - they have somewhat convincing usernames
                  - semi-reasonable descriptions
                  - emails on custom domains (Hetzner vps usually)
                  - unique IP per account (often same subnet)
                  - uploads a profile pic & banner image
                  - some of them boost a few posts from admin acct

                  But then these accounts just sit there. They aren't spamming. What is their goal?

                  #mastoAdmin #fediAdmin

                  synnfynn@corteximplant.comS This user is from outside of this forum
                  synnfynn@corteximplant.comS This user is from outside of this forum
                  synnfynn@corteximplant.com
                  wrote sidst redigeret af
                  #8

                  @sb

                  Sounds like sleeper bot accounts.

                  They're most likely monitoring your public instance feed, including non-federated instance-local-only posts as I noticed some aren't following other accounts, but check if an account is following them.

                  I'd also check for any unexpected traffic to/from your instance on the wire when there shouldn't be any, just in case.

                  But it's concerning.

                  1 Reply Last reply
                  0
                  • sb@metroholografix.caS sb@metroholografix.ca

                    I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

                    - they have somewhat convincing usernames
                    - semi-reasonable descriptions
                    - emails on custom domains (Hetzner vps usually)
                    - unique IP per account (often same subnet)
                    - uploads a profile pic & banner image
                    - some of them boost a few posts from admin acct

                    But then these accounts just sit there. They aren't spamming. What is their goal?

                    #mastoAdmin #fediAdmin

                    ophiocephalic@kolektiva.socialO This user is from outside of this forum
                    ophiocephalic@kolektiva.socialO This user is from outside of this forum
                    ophiocephalic@kolektiva.social
                    wrote sidst redigeret af
                    #9

                    @sb
                    This sounds similar to a bot campaign which has recently unfolded on a number of instances including ours. They can talk their way through a manual signup review, leading some to think humans initiate the accounts. The Kolektiva bots initially boosted a few toots from local accounts. They post squalls of stochastic automated text, first in English, and then switching to Greek (!). They also post slop graphics. A thematic that emerges through the nonsense is clear, a focus on the Ukraine war which is derogatory to Ukrainians. IOW, actual Russian bots

                    1 Reply Last reply
                    0
                    • sb@metroholografix.caS sb@metroholografix.ca

                      I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

                      - they have somewhat convincing usernames
                      - semi-reasonable descriptions
                      - emails on custom domains (Hetzner vps usually)
                      - unique IP per account (often same subnet)
                      - uploads a profile pic & banner image
                      - some of them boost a few posts from admin acct

                      But then these accounts just sit there. They aren't spamming. What is their goal?

                      #mastoAdmin #fediAdmin

                      madsenandersc@social.vivaldi.netM This user is from outside of this forum
                      madsenandersc@social.vivaldi.netM This user is from outside of this forum
                      madsenandersc@social.vivaldi.net
                      wrote sidst redigeret af
                      #10

                      @sb

                      I've noticed similar accounts commenting on YouTube.

                      They have been created years ago with minimal information, and suddenly they come out and go full throttle with pro-Russian arguments in debates on videos related to the US, EU and Ukraine.

                      It's not ideal that Hetzner is hosting the email for them, but then again - if the Hetzner account is created by a EU citizen with Russian ties, it's almost impossible to detect.

                      Personally I would contact the account owner and ask them a couple of follow-up questions and tell them to go elsewhere if I felt something was fishy.

                      1 Reply Last reply
                      0
                      Svar
                      • Svar som emne
                      Login for at svare
                      • Ældste til nyeste
                      • Nyeste til ældste
                      • Most Votes


                      • Log ind

                      • Har du ikke en konto? Tilmeld

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      Graciously hosted by data.coop
                      • First post
                        Last post
                      0
                      • Hjem
                      • Seneste
                      • Etiketter
                      • Populære
                      • Verden
                      • Bruger
                      • Grupper