⚠️ SW-ISAC Advisory
A Russian spam network creating hundreds of accounts across dozens of servers remains active on numerous ActivityPub services, constituting coordinated inauthentic behaviour, and spam.
We are directly contacting affected services, but all admins should check for new accounts that match the indicators.
Common usernames and other indicators of compromise are at connect.iftas.org/library/ifta…
Based in part on BlueSky accounts identified and shared to us by Antibot4Navalnyd
Spam Fediverse Services - IFTAS Connect
The domains listed below are automated spam sources, predominantly to drive web traffic to ad farms using scraped and republished content, potentially scraped using LLM…IFTAS
Questa voce è stata modificata (1 settimana fa)
reshared this
IFTAS
in reply to IFTAS • • •related references:
bsky.app/profile/antibot4naval…
about.iftas.org/2025/10/05/coo…
sgdsn.gouv.fr/files/files/2024…
checkfirst.network/pravda-netw…
IFTAS
2025-10-05 19:48:43
Dave Clark
in reply to IFTAS • • •IFTAS
in reply to Dave Clark • • •@bedirthan if the additional indicators listed on that page are also there (recently registered, throwaway domain used for registration, links to Telegram channels) they may be.
The username is a starting point for investigation, but should not be considered in and of itself proof of inauthentic account status.
IFTAS
in reply to IFTAS • • •@bedirthan We observed three associated accounts on three different Mastodon services with a BBC username, and one associated account with a France24 username.
They have all been suspended.
Dave Clark
in reply to IFTAS • • •thank you for the clarifications.
Way back, ending in 2016, I was a moderator at Newsvine. One of the last things we learned before being shutdown was that we were a target of the Fancy Bear project
Inky says "What the hell?!"
in reply to IFTAS • • •@bedirthan
Do we need to watch out for them muddying the waters with reposts of actual BBC etc material?
IFTAS
in reply to IFTAS • • •Update 2025-10-23
Accounts identified: 553
Accounts mitigated: 395
Servers affected: 159
Servers with active accounts: 38
Spam accounts continue to be created and SW-ISAC volunteers are flagging them as we find them.
Many observed accounts have been taken down, and the observed usernames list is being updated daily (see above for link).
If you receive a report from this account you believe to be a false positive, please let us know.
reshared this
Anuj Ahooja e GhostOnTheHalfShell reshared this.
IFTAS
in reply to IFTAS • • •As a timely reminder, our DNI list includes 78 domains we strongly recommend for defederation.
Some are known to be expired, but they remain on the list for safety's sake.
Each domain is labelled and was investigated by human review. This is not an automated or consensus list.
A Mastodon format CSV for import is available at about.iftas.org/trust-safety-s…
Inclusion on the DNI list means we are extremely confident the domain will never be retracted from the list.
#FediAdmin #MastoAdmin
IFTAS Do Not Interact (DNI) List
IFTAS BlogStefan Bohacek reshared this.
DieMadColonizer
in reply to IFTAS • • •