Meet one short-lived botnet, with a Japanese focus. Its handles started with @kurikairiku51 and went up sequentially to @kurikairiku100.
Sequential handles. Identical bios. Identical tweets in identical order. Thousands of likes. Following the same number of accounts.
Bots.
There were 50 accounts in the botnet.
They only had three profile pictures.
There was a bit more originality with the background photos.
They had four.
What's striking is how fast these accounts were set up. Six in seven minutes, on March 24 (UK time).
Then the main burst: 44 in just under an hour, on March 25. (Image of the first and last in the sequence.)
A rate of almost one a minute: either that's automated, or someone's employing a team to do this.
They were hyperactive while they lasted. This one posted 2,574 likes in under five days, for an average of about 588 a day.
Across the network, we're talking on the order of 100,000 likes in five days.
Numbers 101 onwards don't exist; the numbers up to 50 had been suspended earlier. (The "suspended" image here is from @kurikairiku49).
So this looks like a botnet that was created in a batch of 50, probably to avoid tripping Twitter's automated detectors.
Twitter shut it down yesterday. That shows their detectors are working.
But someone managed to set them up in the first place, fast, blatantly (those handles), and undetected. That shows there's still a window open, even if it's getting narrower. / Thread ends.
• • •
Missing some Tweet in this thread? You can try to
force a refresh
🚨BREAKING🚨 @Meta took down two covert influence ops:
Big one from Russia🇷🇺 targeting Europe with spoofed media websites like the Guardian and Spiegel
First one from China 🇨🇳 to focus on both sides of domestic US 🇺🇸 politics and Czech-China relations. about.fb.com/news/2022/09/r…
@Meta The operations were very different, but both worked on multiple social media platforms and petitions sites.
The Russian op was even on LiveJournal (cute).
List of domains, petitions etc in the report. #OSINT community, happy hunting!
@Meta China: this was the first Chinese network we’ve disrupted that focused on US domestic politics ahead of the midterms and Czech foreign policy toward China and Ukraine.
It was small, we took it down before it built an audience, but that’s a new direction for Chinese IO.
🚨JUST OUT🚨
Quarterly threat report from @Meta’s investigative teams.
Takedowns from around the world:
Cyber espionage in South Asia;
Harassment in India;
Violating networks in Greece, South Africa, India;
Influence ops from Malaysia & Israel
AND... about.fb.com/news/2022/08/m…
A deep dive into a Russian troll farm, linked to people with ties to what’s known as the Internet Research Agency.
It used fake accounts across the internet to make it look like there’s support for Russia’s war in Ukraine - and to pretend the troll farm's doing a good job.
The operation called itself “Cyber Front Z”.
We think of it as the Z Team, because it was about as far from being the A Team as you can get.
🚨JUST OUT🚨
Quarterly threat report from @Meta’s investigative teams.
Much to dig into:
State & non-state actors targeting Ukraine;
Cyber espionage from Iran and Azerbaijan;
Influence ops in Brazil and Costa Rica;
Spammy activity in the Philippines... about.fb.com/news/2022/04/m…
🚨 TAKEDOWN 🚨
This weekend, we took down a relatively small influence operation that had targeted Ukraine across multiple social media platforms and websites. It was run by people in Russia and Ukraine: about.fb.com/news/2022/02/s…
It consisted of approx 40 accounts, Groups and Pages on FB and IG, plus on Twitter, YouTube, VK, OK, Telegram.
It mainly posted links to long-form articles on its websites, without much luck making them engaging. It got very few reactions, and under 4k followers.
It ran a few fake personas posing as authors. They had fake profile pics (likely GAN), and unusually detailed public bios - e.g. former civil aviation engineer, hydrography expert.
The op posted their articles on its websites and social media, & amplified them using more fakes.
Personal 🧵 based on years of OSINT research into influence operations since 2014.
Looking at the Russian official messaging on “de-nazification” and “genocide”, it’s worth putting them in context of the many different Russian IO that targeted Ukraine over the years.
* Iran, targeting the UK, focusing on Scottish independence;
* Mexico, a PR firm targeting audiences across LATAM;
* Turkey, targeting Libya, and linked to the Libyan Justice and Construction Party (affiliated w/Muslim Brotherhood).
It’s not the first time for an Iranian op to pose as supporters of Scottish independence.
In the past, FB found a page that copied and posted political cartoons about independence as far back as 2013. @Graphika_NYC writeup here (pages 26-27) graphika.com/reports/irans-…