Scam Alert!

If you receive an email or response on Mastodon like the following, DO NOT click the link. It is a scam fishing for login details at the very least.

"Mastodon has detected botting malware on your PC that is congesting the Mastodon network. All affected accounts will be suspended within 24 hours unless removed. _https://REDACTEDLINK"

This was a rogue bot on the mastodon.cloud instance. We've blocked the bot, and reached out to the instance admin. If further bots appear from there we will be limiting the instance, with a view to defederating from them if they don't reign in the issue.

@ambassador I've seen others who've recently joined mastodon.cloud complaining about Nazi pile-ons. Looking at their Moderated Servers list, there are only about a dozen items on it and none of the notorious dangerous servers seem to be there.

It seems to be primarily Japanese-language-focused so perhaps that's why they're not on top of English-language moderation.

The admin account has only posted once in the last year:
https://mastodon.cloud/@TheAdmin/with_replies

The Admin ☁️ (@[email protected])

371 Posts, 14 Following, 14.4K Followers · mastodon.cloud Admin

mastodon.cloud
@hughster Yeah, I saw the moderated server list and alarm bells started to ring a bit. Have yet to get a reply from the admin, but with timezones as they are, will wait a good 24hrs before any escalation of actions.

@ambassador ah I suspended that bot account earlier but didn't think to report it to the instance admin. Thank you for mentioning it!

Does it help if multiple people report a bot?

@lookitmychicken Generally no, as long as someone on your instance has reported it. :)

@ambassador I'm the someone on my instance who should have reported it -- this is my personal alt but I'm also @admin . so I reported to mastodon.cloud just now, & then suspended the bot from my server.

Thank you for the advice!

@lookitmychicken @ambassador we at php.social also forwarded the report to them.
@ambassador Damn. Time to move server methinks...
@ambassador I've reported too. They seem to be behind on reports or asleep at the wheel. Not going to defed, that's too harsh.
@ambassador mastodon.cloud is a sibling instance of mstdn.jp which is pretty notorious for hosting yazis and illegal content due to the lack of moderation and being wide open. So I'd 100% suggest a block.
@ambassador
I've also run into a case where they simply followed my account without posting a message or comment, and then had this same exact message in their profile.
@flamepanther @ambassador Yeah, this is exactly what just happened to me. Reported and blocked. I guess part of the growth is attracting scams.

@ianrosewrites
@ambassador
Lots of confused newbies, lots of instances that might not be prepared or well moderated... I guess I can see the draw.

Hopefully they've underestimated the platform, its users, and everyone running it!

@flamepanther @ambassador — Same. As a #noob, I didn’t understand, so I deleted the post they liked, too.

@ambassador Came across this mess too right now, via this Bot who mass fav'd my posts.

https[://]photog[dot]social/[at]MastodonBOT[at]mastodon.cloud

Miserable Old-Git (@[email protected])

Attached: 2 images #Help #Attention Anyone else getting 'favourited' by this bot? The link in the bio is highly suspect!

Independent Media UK
@Welshsprout Yep, that's the one. Hopefully your instance admin has already blocked it (but if not, report it and block it yourself).
@ambassador any email that claims virus and malware should always be deleted.
I had a follow who claimed in his bio to increase your followers - reported and blocked.
@ambassador this account liked one of my posts earlier.
@ambassador there's a bot which was reblogging my posts and it has the same message on its profile. I blocked it
@ambassador I got a post 'favourited' by that earlier. Very strange!

@ambassador

I've blocked it on both our instances. And reported to their admin.

@ambassador it's the first time in three years I had to report a spam bot. I guess these kind of activities will become more frequent on the #fediverse and people will have to be more careful. In the next future we will see spam instances instead of #spam users.
@emanuele @ambassador As a #Twitter refugee may I apologize for the filth that follows us around. They only want to be with us it seems. Hopefully the #fediverse will block them all.
@ambassador Yup that bot favorited one of my posts. Attempts to look like a server bot. Mastodon.cloud admin hasn’t been active for a year? I find that hard to believe with the migration happening and garnering so much attention. Anyway, blocked the bot.
@ambassador @stemid Fick favorites av den här skiten också...
@ambassador thank you! I really was worried that I was being suspended. I will report them
@ambassador Having had various younger siblings, cousins and then children of my own, I still smile when "bots" are mentioned! I have cleaned many bots...

@ambassador

JSOK - saw this presented elsewhere as a picture and it made it easier to identify.

@ambassador I know you’re aware. More telemetry @jerry
@ambassador thanks for the info. Being a #newbie, I’m sure that would be confusing.
@ambassador Elon, is that you or your buddy Donald ? <grin>
@ambassador En een filtertje op "https://REDACTEDLINK"
@ambassador As a rule of thumb for people, you'd never get that type of message ever.
Especially the "Mastodon detected" part. An email from your instance would have your instance name in it, not just "Mastodon". It would probably come from your server admins/moderators, and wouldn't be about malware because Mastodon is just a website, it doesn't check your PC for things.

@ambassador Oh fuck me. 🤦

OF COURSE the scammers had to try to profit on the situation, too 🙄

@ambassador luckily this one at least has been suspended.
@ambassador In the internet is necesary to be cautious and have some knowledge about phishing. Here is a test that can help to know if you can identify a phishing email: https://phishingquiz.withgoogle.com/
Take Jigsaw's Phishing Quiz

Can you spot when you're being phished?

@ambassador how does one change their password on Mastodon?
@NotYourStrayDog @ambassador In the web interface, it's under Settings > Account > Account settings.
@thegurkha @ambassador but only on the web interface, im guessing? Cause i have been through the setting pages on here and couldnt find it

@NotYourStrayDog @ambassador All the apps are slightly different, and none of them have all the functionality of the web interface. The only common denominator is the web interface.

The generic Mastadon apps aren't great, either.

On iOS, Metatext is spoken highly of, and on Android, Tusky is.

@thegurkha @ambassador i am using tusky and like it, but was confused when i went to change my password a d couldnt find the settings

@ambassador We should be strongly advocating for users to use two-factor authentication, too.

Settings > Account > Two-Factor Auth

These credential harvesting scams might seem a bit lame ("What are they going to do with my Mastadon account ?") but what they do is use them to get your email address from your account settings, then try the credentials in all sorts of other accounts like PayPal, online banking etc.

Because people re-use passwords all over the web...

#2fa #security #password

@ambassador I'd recommend to report any such accounts via #fediblock - these should always be blocked.
@clipperchip @ambassador please post as unlisted when talking about hashtags to avoid flooding them
@darckcrystale @ambassador But what do you mean by "post as unlisted"? Is that a specific option?