Salta al contenuto principale


⚠️ SW-ISAC Advisory

A Russian spam network creating hundreds of accounts across dozens of servers remains active on numerous ActivityPub services, constituting coordinated inauthentic behaviour, and spam.

We are directly contacting affected services, but all admins should check for new accounts that match the indicators.

Common usernames and other indicators of compromise are at connect.iftas.org/library/ifta…

Based in part on BlueSky accounts identified and shared to us by Antibot4Navalnyd

Questa voce è stata modificata (1 settimana fa)

reshared this

in reply to IFTAS

related references:

bsky.app/profile/antibot4naval…

about.iftas.org/2025/10/05/coo…

sgdsn.gouv.fr/files/files/2024…

checkfirst.network/pravda-netw…


Coordinated Pro-Russian Propaganda Network Targeting ActivityPub and ATProto Services


Update October 14: Accounts are still being created, and unused accounts registered earlier are being activated.

Since 15 September, IFTAS has been tracking a coordinated network of over 300 accounts operating across Mastodon. These accounts are engaged in a high-volume propaganda campaign, promoting pro-Russian narratives and linking to Telegram channels associated with known state-aligned disinformation operations.
six of the profiles identified
We became aware of a related investigation by the Antibot4Navalny research team that observed these accounts bridging to Bluesky, and we have since collaborated to enhance our investigations and share our findings. Their public post provides further context.

Antibot4Navalny’s observations identified additional impacted services we were unaware of, and highlighted that accounts were still being created. Furthermore, thanks to their specific expertise in this area, this helped clarify and confirm that what we were seeing was indeed the work of a coordinated campaign with an increased likelihood of it being a state-sponsored or state-approved campaign.

We have been contacting affected Mastodon administrators, and are now moving to a public advisory to inform the broader network.

The network includes accounts impersonating reputable news outlets such as BBC News, Euronews, and Meduza, designed to give credibility to Telegram propaganda links. We believe it may be connected to the “Pravda/Portal Kombat” pro-Russia propaganda network.

Accounts are hosted across numerous Mastodon instances and bridged into Bluesky, creating the appearance of independent sources. Activity on Bluesky helped reveal aggregate patterns, identical usernames, posting schedules, and content themes more clearly than across decentralised Mastodon services.

This campaign appears to mimic tactics observed in earlier influence operations, blending low-cost automation with impersonation and volume-based amplification.

We are sharing data with participants of the Social Web ISAC, and we issued a public advisory along with a list of observed usernames.

We are aware of accounts hosted on abandoned or unmanaged services, we may issue a Limit recommendation for those domains at a later date.

If you provide or can link to tools that may benefit administrators in identifying and/or managing these accounts, please let us know.

Further Reading:


Questa voce è stata modificata (2 settimane fa)
in reply to IFTAS

on the full list are BBC and France24. Are these both impersonators of the authentic orgs?
in reply to Dave Clark

@bedirthan if the additional indicators listed on that page are also there (recently registered, throwaway domain used for registration, links to Telegram channels) they may be.

The username is a starting point for investigation, but should not be considered in and of itself proof of inauthentic account status.

in reply to IFTAS

@bedirthan We observed three associated accounts on three different Mastodon services with a BBC username, and one associated account with a France24 username.

They have all been suspended.

in reply to IFTAS

thank you for the clarifications.

Way back, ending in 2016, I was a moderator at Newsvine. One of the last things we learned before being shutdown was that we were a target of the Fancy Bear project

in reply to IFTAS

@bedirthan

Do we need to watch out for them muddying the waters with reposts of actual BBC etc material?

in reply to IFTAS

Update 2025-10-23

Accounts identified: 553
Accounts mitigated: 395
Servers affected: 159
Servers with active accounts: 38

Spam accounts continue to be created and SW-ISAC volunteers are flagging them as we find them.

Many observed accounts have been taken down, and the observed usernames list is being updated daily (see above for link).

If you receive a report from this account you believe to be a false positive, please let us know.

Questa voce è stata modificata (22 ore fa)

reshared this

in reply to IFTAS

As a timely reminder, our DNI list includes 78 domains we strongly recommend for defederation.

Some are known to be expired, but they remain on the list for safety's sake.

Each domain is labelled and was investigated by human review. This is not an automated or consensus list.

A Mastodon format CSV for import is available at about.iftas.org/trust-safety-s…

Inclusion on the DNI list means we are extremely confident the domain will never be retracted from the list.

#FediAdmin #MastoAdmin

Questa voce è stata modificata (3 giorni fa)

Stefan Bohacek reshared this.

in reply to IFTAS

its be really useful if this could be done to tracc all the IDF accounts that sprang up to do hasbarah