Conspirador Norteño Profile picture
Apr 29, 2021 10 tweets 7 min read Read on X
Are these spammy replies from accounts with cat avatars some mysterious form of feline communication? Nope, it's another botnet, and the cats are fake (GAN-generated, similar to those produced by thiscatdoesnotexist.com).

cc: @ZellaQuixote
The reply spammers with the GAN-generated cat pics follow a bunch of other accounts with GAN-generated cat avatars, as well as GAN-generated human face pics and anime pics (and some other things), all with similar follow stats and all created in April 2021.
By recursively exploring the follow relationships of the initial group of accounts, we found 5007 accounts that we believe to be part of the botnet, created in batches between April 2nd and April 27th, 2021.
To date, only 1226 of the 5007 accounts in this network have tweeted. Almost all tweets are repetitive replies consisting of nonsensical strings of letters. They mostly reply to porn accounts (porn is also what they retweet on the rare occasions that they retweet something).
This network uses 3 different types of GAN-generated profile pic (GAN = "generative adversarial network, the AI technology used to produce the images):

• 681 human faces (thispersondoesnotexist.com)
• 660 cats (thiscatdoesnotexist.com)
• 656 anime pics (thiswaifudoesnotexist.com)
543 of the accounts in the network use the default profile pic. The remaining 2467 of the accounts use a variety of images, most of which are repeated across multiple accounts (the collage shows some examples).
The GAN-generated human face pics have the telltale trait that the major facial feature (particularly the eyes) are in the same pixel position on each image. This becomes apparent when one blends all the images together, as in this video:
For more information on detecting the various types of GAN-generated pics, here is a trio of threads:

• faces
• cats
• anime
Finally, we suspect that this is at least the third incarnation we've seen of this particular botnet. Analyses of the previous two:


Typo in one o the tweets in this thread (missing quote mark) - first sentence should read:

This network uses 3 different types of GAN-generated profile pic (GAN = "generative adversarial network", the AI technology used to produce the images):

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Conspirador Norteño

Conspirador Norteño Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @conspirator0

Dec 31, 2023
It's New Year's Eve, and a bunch of politics enthusiasts with GAN-generated faces are enthusiastically replying to a variety of posts with similarly-worded replies. #NewYearShenaniGANs

cc: @ZellaQuixote collage of 10 replies containing variations on "politics enthusiast" from accounts that use GAN-generated faces as avatars
The politics enthusiasts are part of a spam network consisting of (at least) 575 accounts created between May and December 2023 with GAN-generated faces. Many of their handles, such as @Maairiuieinaaa and @eJooeiaAoneueer, contain long strings of vowels.
histogram of account creation dates
table of example accounts from the network
@Maairiuieinaaa @eJooeiaAoneueer All 575 of these accounts use StyleGAN-generated faces as profile images. Some of these, such as @MauMoiagaia's profile image, contain a tiny "StyleGAN 2 (Karras et al.)" watermark in the lower right corner. collage of the GAN-generated faces that the accounts in the network use as profile images
Read 11 tweets
Dec 7, 2023
It's a great day to look at a network of inauthentic accounts that post identical AI art images (with a side of good old fashioned T-shirt spam).

cc: @ZellaQuixote


3 posts containing the same AI-generated image
3 posts containing the same AI-generated image
3 posts containing the same AI-generated image
3 posts containing the same AI-generated image
This network consists of 24 X accounts. 12 of these accounts were created in the latter half of 2023 and have female avatars, while the other 12 were created in 2013 or earlier and have male avatars.

table of the 24 accounts in the network
screenshots of the profiles of the 12 female-presenting accounts in the network, all created in 2023
screenshots of the profiles of the 12 male-presenting accounts in the network, all created in 2013 or earlier
The 12 accounts with female avatars and 2023 creation dates regularly post AI-generated art images, and these image posts are quickly reposted by other accounts in the network (both female and male). The AI-generated images are often duplicated across accounts.


examples of AI art images posted by the network, and screenshots of the reposts
3 posts containing the same AI-generated image
3 posts containing the same AI-generated image
3 posts containing the same AI-generated image
Read 8 tweets
Sep 1, 2023
Meet @ImJamesMiller (permanent ID 1371651462153994242), an account with a GAN-generated face, 172K followers, and no tweets prior to two days ago. What's up with that?

cc: @ZellaQuixote screenshot of @ImJamesMiller's profile, screenshot of tweeterid.com lookup showing @ImJamesMiller's permanent ID, and closeup of @ImJamesMiller's profile image, a GAN-generated face
As it turns out, @ImJamesMiller wasn't always named @ImJamesMiller. In June, the account was named @/IamJimCaviezel in an apparent attempt to impersonate Sound of Freedom actor Jim Caviezel.

web.archive.org/web/2023062319…
screenshot of wayback machine archive
@ImJamesMiller Multiple prominent users appear to have accepted the fake Jim Caviezel account as legitimate, including Texas Congressman Brian Babin, right-wing influencer/ex-Game of Thrones blogger Jack Posobiec, and recently indicted ex-Assistant Attorney General Jeff Clark. screenshots of tweets from large accounts tagging the fake Jim Caviezel account
Read 9 tweets
Aug 27, 2023
It's a great day to look at a network of Bluesky spam accounts with randomized names. #SundaySpam

cc: @ZellaQuixote collage of 16 bluesky accounts with random adjective + noun names
This spam network consists of (at least) 401 accounts, all of which were created (or added to the Bluesky app view) in August 2023. These accounts do not follow each other; rather, each one follows a small number of popular Bluesky accounts. histogram of account creation dates for the 401 accounts in the network, all created in August 2023
The accounts in this network cycle rhythmically between posting three types of content:

• reposts
• posts containing links to news articles
• posts containing links to news articles accompanied by images hourly post volume by post type bar chart
Read 6 tweets
Jun 18, 2023
This #FathersDay2023 tweet from @PaulFox50854324 has gone somewhat viral, but both @PaulFox50854324's profile image and the alleged image of the neighbor's son are GAN-generated faces.

cc: @ZellaQuixote Image
More on GAN-generated faces and their use on Twitter here:

Tips on recognizing GAN-generated faces here:
Today's #FathersDay2023 tweet is not the first time @PaulFox50854324 engaged in image shenanigans.

This glass of grape Kool-Aid that @PaulFox50854324's son supposedly made in 2021 somehow traveled back in time to 2019 and became alcoholic kombucha. Image
Read 7 tweets
Jun 4, 2023
Meet @thisisorange, a Twitter account created in February 2022 with a gold "verified organization" badge, thousands of batch-created fake followers, and a couple other interesting traits.

cc: @ZellaQuixote screenshots of @thisisorang...follow order by creation da...
Verified organizations on Twitter can verify affiliated accounts (employees, teams, brand names, etc), which receive blue checkmarks as well as an organization badge (help.twitter.com/en/using-twitt…). The @thisisorange account has thousands of affiliates, mostly cryptocurrency accounts.
How did this come about? The website linked on @thisisorange's profile (orange dot associates) apparently allows one to become an affiliate simply by providing a Twitter account and a cryptocurrency wallet. screenshot of orange . asso...
Read 5 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(