Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Over 2,000 accounts now being tracked on the Russian Botnet infecting the fediverse.

Over 2,000 accounts now being tracked on the Russian Botnet infecting the fediverse.

Scheduled Pinned Locked Moved Uncategorized
16 Posts 7 Posters 32 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • retech@corteximplant.comR retech@corteximplant.com

    @iftas Do you have that list in a csv file so individuals could add them to their personal blocklist?

    iftas@mastodon.iftas.orgI This user is from outside of this forum
    iftas@mastodon.iftas.orgI This user is from outside of this forum
    iftas@mastodon.iftas.org
    wrote last edited by
    #6

    @retech

    see https://about.iftas.org/iftas-abandoned-unmanaged-denylist-output/

    or

    FIRES - Dataset: IFTAS Abandoned and Unmanaged Denylist

    FIRES: Fediverse Intelligence Replication Endpoint Server

    favicon

    (fires.1sland.social)

    1 Reply Last reply
    1
    0
    • R relay@relay.mycrowd.ca shared this topic
    • ethergear@infosec.exchangeE ethergear@infosec.exchange

      @iftas @anewsocial doesn't seem to belong on this list

      *edit* and they're not on it actually. Is there a reason they're in the screenshot?

      iftas@mastodon.iftas.orgI This user is from outside of this forum
      iftas@mastodon.iftas.orgI This user is from outside of this forum
      iftas@mastodon.iftas.org
      wrote last edited by
      #7

      @ethergear @anewsocial it's just a general snapshot of the bot activity, copying and pasting whatever they come across in this instance.

      1 Reply Last reply
      0
      • informapirata@poliverso.orgI informapirata@poliverso.org

        @iftas I'm a moderator of the Italian instance mastodon.uno through @informapirata, and I noticed that one of the Russian bot accounts listed is attributed to the mastodon.uno instance.

        The account in question was registered on January 12th and began to be active after more than a week. I personally reported it on January 21st and, as administrator @filippodb can confirm, I deactivated it using mastodon's freeze function.
        At the same time, all posts published by that account were deleted, but obviously the messages (three in total) reshared by other accounts, messages that contained no problematic content, were not deleted.

        The decision to deactivate it rather than suspend it was based on the fact that we were studying the Russian bot phenomenon to understand how often they attacked the deactivated profile, whether they connected automatically or manually, and whether the freeze function helped reduce subscriptions. And indeed, it did.

        I would like to add that I personally continue to use this method to combat Russian bot registrations, even on the poliversity.it instance, which I personally manage. Following your report, I have added a silencing action to the freezing process, so that those accounts are not detected by your scraping system.

        On mastodon.uno, however, for purely organizational reasons, we began directly suspending all accounts that still manage to bypass the blocks we've placed on the email addresses used to register.

        Returning to the main point, I would like to point out that your report only reached us on April 30th, a full 90 days later, and that account had been rendered practically unusable. Your identification of the account was carried out through automated processing (scraping) and resulted in a now useless report because it was not linked to any content and to an account that was no longer usable. A report that was therefore completely rightfully not given priority.

        The account was then permanently suspended on May 3rd, three days after your report.

        Mastodon.uno is the largest Italian instance, with thousands of active users and dozens of registrations per day. Thanks to a staff of around twenty volunteer moderators, we can keep registrations open with virtually immediate processing times and extremely rapid decision-making.

        We therefore ask you to remove the name of the bot that was no longer present in our instance from the list of Russian bots, which had been removed from our instance well before your report.

        We believe it is not only unfair but also extremely damaging to our reputation that our instance, one of the most active in combating Russian botnets, should be lumped together with other instances that do not practice moderation at all, or that practice poor or incomplete moderation.

        We look forward to hearing from you and thank you for your attention.

        iftas@mastodon.iftas.orgI This user is from outside of this forum
        iftas@mastodon.iftas.orgI This user is from outside of this forum
        iftas@mastodon.iftas.org
        wrote last edited by
        #8

        @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

        >Your identification of the account was carried out through automated processing (scraping)

        To be clear, I spend roughly two hours per day, every day, manually reviewing accounts, looking at over 150 instances. There is no scraping of any kind. Just me and my mouse.

        I have two lists, the new one starting in April. Any accounts not suspended on the old list were brought forward to the new list, generating new reports for older accounts.

        iftas@mastodon.iftas.orgI informapirata@poliverso.orgI brozu@mastodon.unoB 3 Replies Last reply
        0
        • iftas@mastodon.iftas.orgI iftas@mastodon.iftas.org

          @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

          >Your identification of the account was carried out through automated processing (scraping)

          To be clear, I spend roughly two hours per day, every day, manually reviewing accounts, looking at over 150 instances. There is no scraping of any kind. Just me and my mouse.

          I have two lists, the new one starting in April. Any accounts not suspended on the old list were brought forward to the new list, generating new reports for older accounts.

          iftas@mastodon.iftas.orgI This user is from outside of this forum
          iftas@mastodon.iftas.orgI This user is from outside of this forum
          iftas@mastodon.iftas.org
          wrote last edited by
          #9

          @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

          I do not see any active account on your service in our data, but if there is something you want me to specifically review, please DM me.

          I want to emphasise that mastodon.uno is a stellar example of a well-moderated instance. The dedication of your volunteer staff is evident, and you have my complete respect for the proactive measures you take to keep the Fediverse safe.

          iftas@mastodon.iftas.orgI filippodb@mastodon.unoF 2 Replies Last reply
          0
          • iftas@mastodon.iftas.orgI iftas@mastodon.iftas.org

            @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

            I do not see any active account on your service in our data, but if there is something you want me to specifically review, please DM me.

            I want to emphasise that mastodon.uno is a stellar example of a well-moderated instance. The dedication of your volunteer staff is evident, and you have my complete respect for the proactive measures you take to keep the Fediverse safe.

            iftas@mastodon.iftas.orgI This user is from outside of this forum
            iftas@mastodon.iftas.orgI This user is from outside of this forum
            iftas@mastodon.iftas.org
            wrote last edited by
            #10

            @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

            Please understand that being listed does not equate to a failure in moderation; rather, it reflects the reality of being a target for these campaigns. Your transparency regarding the "freeze" strategy is in fact helpful context for those of us tracking these movements and activities.

            iftas@mastodon.iftas.orgI 1 Reply Last reply
            1
            0
            • iftas@mastodon.iftas.orgI iftas@mastodon.iftas.org

              @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

              Please understand that being listed does not equate to a failure in moderation; rather, it reflects the reality of being a target for these campaigns. Your transparency regarding the "freeze" strategy is in fact helpful context for those of us tracking these movements and activities.

              iftas@mastodon.iftas.orgI This user is from outside of this forum
              iftas@mastodon.iftas.orgI This user is from outside of this forum
              iftas@mastodon.iftas.org
              wrote last edited by
              #11

              @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb for completeness' sake, I will add that there are two automations:

              1. I have a script on cron that queries each active account every six hours to see if it still active, and update the spreadsheet accordingly

              2. when it comes to actually filing reports, I have now automated the report creation

              These two actions have saved me a couple of hours of labour every day, I was manually filing reports and reviewing active accounts (since October)

              iftas@mastodon.iftas.orgI 1 Reply Last reply
              0
              • iftas@mastodon.iftas.orgI iftas@mastodon.iftas.org

                @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb for completeness' sake, I will add that there are two automations:

                1. I have a script on cron that queries each active account every six hours to see if it still active, and update the spreadsheet accordingly

                2. when it comes to actually filing reports, I have now automated the report creation

                These two actions have saved me a couple of hours of labour every day, I was manually filing reports and reviewing active accounts (since October)

                iftas@mastodon.iftas.orgI This user is from outside of this forum
                iftas@mastodon.iftas.orgI This user is from outside of this forum
                iftas@mastodon.iftas.org
                wrote last edited by
                #12

                @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

                I think it's important to state this very clearly:

                Everything published under the IFTAS name is human-reviewed. Every list, every label.

                If it says CSAM, I reviewed it. If it says terroristic content I reviewed it. If it says spam I reviewed it.

                IFTAS is on it's last legs and it's pretty much just me at this point, other than two small groups that share information with each other.

                So please, do not ascribe scraping to IFTAS. It doesn't happen.

                1 Reply Last reply
                0
                • iftas@mastodon.iftas.orgI iftas@mastodon.iftas.org

                  @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

                  I do not see any active account on your service in our data, but if there is something you want me to specifically review, please DM me.

                  I want to emphasise that mastodon.uno is a stellar example of a well-moderated instance. The dedication of your volunteer staff is evident, and you have my complete respect for the proactive measures you take to keep the Fediverse safe.

                  filippodb@mastodon.unoF This user is from outside of this forum
                  filippodb@mastodon.unoF This user is from outside of this forum
                  filippodb@mastodon.uno
                  wrote last edited by
                  #13

                  @iftas Thank you very much for your kind words, and thank you as well for all the important work you are doing.
                  We truly appreciate the recognition of the effort our volunteer staff puts into moderation and community care.

                  We have always maintained a zero-tolerance policy toward Russian bots and Kremlin propaganda accounts, and we will continue to take proactive measures to keep the Fediverse safe, healthy, and welcoming for everyone. @informapirata@poliverso.org @informapirata

                  1 Reply Last reply
                  0
                  • iftas@mastodon.iftas.orgI iftas@mastodon.iftas.org

                    @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

                    >Your identification of the account was carried out through automated processing (scraping)

                    To be clear, I spend roughly two hours per day, every day, manually reviewing accounts, looking at over 150 instances. There is no scraping of any kind. Just me and my mouse.

                    I have two lists, the new one starting in April. Any accounts not suspended on the old list were brought forward to the new list, generating new reports for older accounts.

                    informapirata@poliverso.orgI This user is from outside of this forum
                    informapirata@poliverso.orgI This user is from outside of this forum
                    informapirata@poliverso.org
                    wrote last edited by
                    #14

                    @iftas I've always thought that identifying suspicious accounts was achieved through a mass search, not by ticking off individual instances. This makes your work even more impressive.

                    Thanks for the clarification, and thank you for your continued success!

                    @informapirata @filippodb

                    1 Reply Last reply
                    0
                    • iftas@mastodon.iftas.orgI iftas@mastodon.iftas.org

                      @informapirata@poliverso.org @informapirata@mastodon.uno @filippodb

                      >Your identification of the account was carried out through automated processing (scraping)

                      To be clear, I spend roughly two hours per day, every day, manually reviewing accounts, looking at over 150 instances. There is no scraping of any kind. Just me and my mouse.

                      I have two lists, the new one starting in April. Any accounts not suspended on the old list were brought forward to the new list, generating new reports for older accounts.

                      brozu@mastodon.unoB This user is from outside of this forum
                      brozu@mastodon.unoB This user is from outside of this forum
                      brozu@mastodon.uno
                      wrote last edited by
                      #15

                      @iftas @informapirata@poliverso.org @informapirata @filippodb huge work. Thank you very much 🙏

                      1 Reply Last reply
                      0
                      • iftas@mastodon.iftas.orgI iftas@mastodon.iftas.org

                        Over 2,000 accounts now being tracked on the Russian Botnet infecting the fediverse.

                        35% of them would be silenced or suspended by the IFTAS AUD list.

                        More info: https://about.iftas.org/library/suspected-portal-kombat-accounts/

                        Link Preview ImageLink Preview ImageLink Preview Image
                        iftas@mastodon.iftas.orgI This user is from outside of this forum
                        iftas@mastodon.iftas.orgI This user is from outside of this forum
                        iftas@mastodon.iftas.org
                        wrote last edited by
                        #16

                        A lot of these accounts have what appear to be randomly generated or LLM-assisted bios, and my current favourite is

                        "Farmer with a taste for cronut culture in Milwaukee"

                        1 Reply Last reply
                        1
                        0
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups