cross-posted from: https://dubvee.org/post/1878799
Instance Admins: Check Your Instance for Vote Manipulation Accounts [PSA]
Over the past 5-6 months, I’ve been noticing a lot of new accounts spinning up that look like this format:
https://instance.xyz/u/gmbpjtmt
https://instance.xyz/u/tjrwwiif
https://instance.xyz/u/xzowaikv
What are they doing?
They’re boosting and downvoting mostly, if not exclusively, US news and politics posts/comments to fit their agenda.
Edit: Could also be manipulating other regional news/politics, but my instance is regional and doesn’t subscribe to those limiting my visibility into the overall manipulation patterns.
What do these have in common?
- Most are on instances that have signups without applications (I’m guessing the few that are on instances with applications may be from before those were enabled since those are several months old, but just a guess; they could have easily just applied and been approved.)
- Most are random 8-character usernames (occasionally 7 or 9 characters)
- Most have a common set of users they’re upvoting and/or downvoting consistently
- No posts/comments
What can you, as an instance admin, do?
Keep an eye on new registrations to your instance. If you see any that fit this pattern, pick a few (and a few off this list) and see if they’re voting along the same lines. You can also look in the
login_token
table to see if there is IP address overlap with other users on your instance and/or any other of these kinds of accounts.You can also check the
local_user
table to see if the email addresses are from the same provider (not a guaranteed way to match them, but it can be a clue) or if they’re they same email address using plus-addressing (e.g. user+whatever@email.xyz, user+whatever2@emai.xyz, etc).Why are they doing this?
Your guess is as good as mine, but US elections are in a few months, and I highly suspect some kind of interference campaign based on the volume of these that are being spun up and the content that’s being manipulated. That, or someone, possibly even a ghost or an alien life form, really wants the impression of public opinion being on their side. Just because I don’t know exactly why doesn’t mean that something fishy isn’t happening that other admins should be aware of.
Who are the known culprits?
These are ones fitting that pattern which have been identified. There are certainly more, but these have been positively identified. Some were omitted since they were more garden-variety “to win an argument” style manipulation.
These all seem to be part of a campaign. This list is by no means comprehensive, and if there are any false positives, I do apologize. I’ve tried to separate out the “garden variety” type from the ones suspected of being part of a campaign, but may have missed some.
https://lemy.lol/u/ihuklfle https://lemy.lol/u/iltxlmlr https://lemy.lol/u/szxabejt https://lemy.lol/u/woyjtear https://lemy.lol/u/jikuwwrq https://lemy.lol/u/matkalla https://lemmy.ca/u/vlnligvx https://ttrpg.network/u/kmjsxpie https://lemmings.world/u/ueosqnhy https://lemmings.world/u/mx_myxlplyx https://startrek.website/u/girlbpzj https://startrek.website/u/iorxkrdu https://lemy.lol/u/tjrwwiif https://lemy.lol/u/gmbpjtmt https://thelemmy.club/u/avlnfqko https://lemmy.today/u/blmpaxlm https://lemy.lol/u/xhivhquf https://sh.itjust.works/u/ntiytakd https://jlai.lu/u/rpxhldtm https://sh.itjust.works/u/ynvzpcbn https://lazysoci.al/u/sksgvypn https://lemy.lol/u/xzowaikv https://lemy.lol/u/yecwilqu https://lemy.lol/u/hwbjkxly https://lemy.lol/u/kafbmgsy https://discuss.online/u/tcjqmgzd https://thelemmy.club/u/vcnzovqk https://lemy.lol/u/gqvnyvvz https://lazysoci.al/u/shcimfi https://lemy.lol/u/u0hc7r https://startrek.website/u/uoisqaru https://jlai.lu/u/dtxiuwdx https://discuss.online/u/oxwquohe https://thelemmy.club/u/iicnhcqx https://lemmings.world/u/uzinumke https://startrek.website/u/evuorban https://thelemmy.club/u/dswaxohe https://lemdro.id/u/efkntptt https://lemy.lol/u/ozgaolvw https://lemy.lol/u/knylgpdv https://discuss.online/u/omnajmxc https://lemmy.cafe/u/iankglbrdurvstw https://lemmy.ca/u/awuochoj https://leminal.space/u/tjrwwiif https://lemy.lol/u/basjcgsz https://lemy.lol/u/smkkzswd https://lazysoci.al/u/qokpsqnw https://lemy.lol/u/ncvahblj https://ttrpg.network/u/hputoioz https://lazysoci.al/u/lghikcpj https://lemmy.ca/u/xnjaqbzs https://lemy.lol/u/yonkz
Edit: If you see anyone from your instance on here, please please please verify before taking any action. I’m only able to cross-check these against the content my instance is aware of.
Fantastic work here, hopefully this catches the attention from admins.
Well it got me
lemmy finally made it to the big leagues
Thanks for raising awareness to the issue.
I won’t hear this slander about mah boi x2h583td9p
Are we a real social media now? 😃
Lemmybotz!
Don’t know that I’ve seen the lemy.lol instance. Thank you for the heads-up!
I promise it’s not all bots
Sounds like something a bot would aay
Everyone on Lemmy is a bot except you.
Lol!
Definitely not all bots, I have a friend that uses it, and an alt there as well.
Unless I’m a bot
Muahahajahaha!