Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I've noticed a very slow trickle of fake accounts registering at my instance recently.

I've noticed a very slow trickle of fake accounts registering at my instance recently.

Scheduled Pinned Locked Moved Uncategorized
mastoadminfediadmin
9 Posts 9 Posters 32 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • sb@metroholografix.caS This user is from outside of this forum
    sb@metroholografix.caS This user is from outside of this forum
    sb@metroholografix.ca
    wrote last edited by
    #1

    I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

    - they have somewhat convincing usernames
    - semi-reasonable descriptions
    - emails on custom domains (Hetzner vps usually)
    - unique IP per account (often same subnet)
    - uploads a profile pic & banner image
    - some of them boost a few posts from admin acct

    But then these accounts just sit there. They aren't spamming. What is their goal?

    #mastoAdmin #fediAdmin

    hipsterelectron@circumstances.runH dbrand666@mastodon.socialD paul@oldfriends.liveP kinetix@humanwords.partyK troy@opencoaster.netT 8 Replies Last reply
    2
    0
    • R relay@relay.mycrowd.ca shared this topic
    • sb@metroholografix.caS sb@metroholografix.ca

      I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

      - they have somewhat convincing usernames
      - semi-reasonable descriptions
      - emails on custom domains (Hetzner vps usually)
      - unique IP per account (often same subnet)
      - uploads a profile pic & banner image
      - some of them boost a few posts from admin acct

      But then these accounts just sit there. They aren't spamming. What is their goal?

      #mastoAdmin #fediAdmin

      hipsterelectron@circumstances.runH This user is from outside of this forum
      hipsterelectron@circumstances.runH This user is from outside of this forum
      hipsterelectron@circumstances.run
      wrote last edited by
      #2

      @sb scary.....

      1 Reply Last reply
      0
      • sb@metroholografix.caS sb@metroholografix.ca

        I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

        - they have somewhat convincing usernames
        - semi-reasonable descriptions
        - emails on custom domains (Hetzner vps usually)
        - unique IP per account (often same subnet)
        - uploads a profile pic & banner image
        - some of them boost a few posts from admin acct

        But then these accounts just sit there. They aren't spamming. What is their goal?

        #mastoAdmin #fediAdmin

        dbrand666@mastodon.socialD This user is from outside of this forum
        dbrand666@mastodon.socialD This user is from outside of this forum
        dbrand666@mastodon.social
        wrote last edited by
        #3

        @sb
        Any important elections coming up?

        1 Reply Last reply
        1
        0
        • sb@metroholografix.caS sb@metroholografix.ca

          I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

          - they have somewhat convincing usernames
          - semi-reasonable descriptions
          - emails on custom domains (Hetzner vps usually)
          - unique IP per account (often same subnet)
          - uploads a profile pic & banner image
          - some of them boost a few posts from admin acct

          But then these accounts just sit there. They aren't spamming. What is their goal?

          #mastoAdmin #fediAdmin

          paul@oldfriends.liveP This user is from outside of this forum
          paul@oldfriends.liveP This user is from outside of this forum
          paul@oldfriends.live
          wrote last edited by
          #4

          @sb A lot of times, nefarious accounts just sit idle for a long time before being called into action.

          It's also worthy to note, with Mastodon, users can setup interactions to be filtered under a special area in notifications for news accounts, as well as other settings... So, if a new account tries to send spam within the first 30 days, it will get filtered behind a special area in notifications. They could be for future nefarious use,

          Link Preview Image
          1 Reply Last reply
          0
          • sb@metroholografix.caS sb@metroholografix.ca

            I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

            - they have somewhat convincing usernames
            - semi-reasonable descriptions
            - emails on custom domains (Hetzner vps usually)
            - unique IP per account (often same subnet)
            - uploads a profile pic & banner image
            - some of them boost a few posts from admin acct

            But then these accounts just sit there. They aren't spamming. What is their goal?

            #mastoAdmin #fediAdmin

            kinetix@humanwords.partyK This user is from outside of this forum
            kinetix@humanwords.partyK This user is from outside of this forum
            kinetix@humanwords.party
            wrote last edited by
            #5

            @sb
            Possibly data harvesting while waiting for some command?

            I think IFTAS had a post quite recently about a whole botnet that's creating tons of accounts, behaving kind of normally for awhile before they start doing... whatever it is they start doing (wow, having a short sleep is doing wonders for the memory).

            1 Reply Last reply
            0
            • sb@metroholografix.caS sb@metroholografix.ca

              I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

              - they have somewhat convincing usernames
              - semi-reasonable descriptions
              - emails on custom domains (Hetzner vps usually)
              - unique IP per account (often same subnet)
              - uploads a profile pic & banner image
              - some of them boost a few posts from admin acct

              But then these accounts just sit there. They aren't spamming. What is their goal?

              #mastoAdmin #fediAdmin

              troy@opencoaster.netT This user is from outside of this forum
              troy@opencoaster.netT This user is from outside of this forum
              troy@opencoaster.net
              wrote last edited by
              #6

              @sb definitely will be used later. Had that happen here, they’d look legit for a while then start spamming. Luckily recently for me all of the spam signups have been pretty dang obvious.

              1 Reply Last reply
              0
              • sb@metroholografix.caS sb@metroholografix.ca

                I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

                - they have somewhat convincing usernames
                - semi-reasonable descriptions
                - emails on custom domains (Hetzner vps usually)
                - unique IP per account (often same subnet)
                - uploads a profile pic & banner image
                - some of them boost a few posts from admin acct

                But then these accounts just sit there. They aren't spamming. What is their goal?

                #mastoAdmin #fediAdmin

                synnfynn@corteximplant.comS This user is from outside of this forum
                synnfynn@corteximplant.comS This user is from outside of this forum
                synnfynn@corteximplant.com
                wrote last edited by
                #7

                @sb

                Sounds like sleeper bot accounts.

                They're most likely monitoring your public instance feed, including non-federated instance-local-only posts as I noticed some aren't following other accounts, but check if an account is following them.

                I'd also check for any unexpected traffic to/from your instance on the wire when there shouldn't be any, just in case.

                But it's concerning.

                1 Reply Last reply
                0
                • sb@metroholografix.caS sb@metroholografix.ca

                  I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

                  - they have somewhat convincing usernames
                  - semi-reasonable descriptions
                  - emails on custom domains (Hetzner vps usually)
                  - unique IP per account (often same subnet)
                  - uploads a profile pic & banner image
                  - some of them boost a few posts from admin acct

                  But then these accounts just sit there. They aren't spamming. What is their goal?

                  #mastoAdmin #fediAdmin

                  madsenandersc@social.vivaldi.netM This user is from outside of this forum
                  madsenandersc@social.vivaldi.netM This user is from outside of this forum
                  madsenandersc@social.vivaldi.net
                  wrote last edited by
                  #8

                  @sb

                  I've noticed similar accounts commenting on YouTube.

                  They have been created years ago with minimal information, and suddenly they come out and go full throttle with pro-Russian arguments in debates on videos related to the US, EU and Ukraine.

                  It's not ideal that Hetzner is hosting the email for them, but then again - if the Hetzner account is created by a EU citizen with Russian ties, it's almost impossible to detect.

                  Personally I would contact the account owner and ask them a couple of follow-up questions and tell them to go elsewhere if I felt something was fishy.

                  1 Reply Last reply
                  0
                  • sb@metroholografix.caS sb@metroholografix.ca

                    I've noticed a very slow trickle of fake accounts registering at my instance recently. They put more work into them than normal:

                    - they have somewhat convincing usernames
                    - semi-reasonable descriptions
                    - emails on custom domains (Hetzner vps usually)
                    - unique IP per account (often same subnet)
                    - uploads a profile pic & banner image
                    - some of them boost a few posts from admin acct

                    But then these accounts just sit there. They aren't spamming. What is their goal?

                    #mastoAdmin #fediAdmin

                    iftas@mastodon.iftas.orgI This user is from outside of this forum
                    iftas@mastodon.iftas.orgI This user is from outside of this forum
                    iftas@mastodon.iftas.org
                    wrote last edited by
                    #9

                    @sb Please see: https://about.iftas.org/library/suspected-portal-kombat-accounts/

                    1 Reply Last reply
                    1
                    0
                    • R relay@relay.infosec.exchange shared this topic
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • World
                    • Users
                    • Groups