Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
IFTAS
IFTAS
@iftas@mastodon.iftas.org  ·  activity timestamp 19 hours ago

⚠️ SW-ISAC Advisory

The account "oscarolg" continues to proliferate across federated services, with over 50 accounts observed today

#SW_ISAC_ADVISORY #Spam #CIB

a view of many "oscarolg" profiles listed
a view of many "oscarolg" profiles listed
a view of many "oscarolg" profiles listed
  • Copy link
  • Flag this post
  • Block
Matt
Matt
@matt@oslo.town replied  ·  activity timestamp 17 hours ago

@iftas @evan What is interesting about this is that almost every account (except one) I have clicked on is Spanish and have introduction posts saying that they love nature and want to post about wildlife.

And if you look up the TikTok account mentioned in most profiles, it's just 3 years of regular posting of local nature crudely filmed on a phone: https://www.tiktok.com/@videoabsurdos

Is this some long-game spam or someone that doesn't understand you have to be registered on every Mastodon instance?

https://www.tiktok.com

Videos Absurdos's Creator Profile

  • Copy link
  • Flag this comment
  • Block
Kay Ohtie
Kay Ohtie
@KayOhtie@blimps.xyz replied  ·  activity timestamp 16 hours ago

@matt @iftas @evan either that or, like the "fediverse chick" thing, a harassment campaign against the individual

  • Copy link
  • Flag this comment
  • Block
Admin Jerry
Admin Jerry
@admin@hear-me.social replied  ·  activity timestamp 17 hours ago

@matt @iftas @evan
When I suspended this account back in October, the person appealed the suspension, asking for the reason, saying they didn't understand what they did wrong, although I already mentioned in the suspension that opening an account on multiple servers was the reason. The appeal was in Spanish.

It never occurred to me that this person may not understand the concept of federation and believed an account needed to be created on 18K instances.

Could this really be?

  • Copy link
  • Flag this comment
  • Block
Matt
Matt
@matt@oslo.town replied  ·  activity timestamp 17 hours ago

@admin @iftas @evan I have seen spam that starts out with posting "innocently" and then turns to be politically charged narratives (usually heavily pro-Russian content), but that usually turns in a matter of weeks.

I've never one that links to another platform that has a posting history of related content that spans across multiple years. That sure is a long-game.

Maybe some of the instance admins can cross-compare email and IP addresses to see if it stems from the same account and location.

  • Copy link
  • Flag this comment
  • Block
David Penfold :verified:
David Penfold :verified:
@davep@infosec.exchange replied  ·  activity timestamp 18 hours ago

@iftas pinging @jerry

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct