Are you running an open registration mastodon instance?

Have you dealt with local accounts being reported for Russian troll farm or misinformation activity?

You NEED to look at more than just those accounts.

For each one that is getting reported, there are probably a dozen that do not. Once the troll farms get one in and that lasts a while, they'll come back and make more. Lots more.

🧵 1/5

#MastoAdmin #fediblock

This kind of activity is not new. See also https://about.iftas.org/2025/10/05/coordinated-pro-russian-propaganda-network-targeting-activitypub-and-atproto-services/

If you are absolutely certain that you cannot close registration or at least require account approval, you will need to be very vigilant and have someone watching your account creations or local timeline constantly.

CURRENT Russian misinformation troll farm accounts will usually fit at least 4, but never all, of the below:

🧵 2/5

Coordinated Pro-Russian Propaganda Network Targeting ActivityPub and ATProto Services

Indicators of compromise (IOCs) that identify accounts as likely being part of the network include: a single follow (the bsky.brid.gy @ bsky.brid.gy account), or first follow is the bridge follower…

IFTAS

- Usernames that look like random strings that are kinda pronounceable, 5 to 8 characters long.
- Cutesy ai-generated cartoon you'd expect from a random profile picture generator
- AI-generated portrait photo that does not seem to match the firstname_lastname account name.
- Bio that looks real at a glance, but if you read it, it actually makes no sense. Occasionally their posts are like this too.
- Extremely prolific posting on exactly one political topic

🧵 3/5

- Posts split up by "..." which results in some posts starting and ending with "..." and happens no matter what the instance's char limit is.
- Almost all posts have images, and the images are reused a lot (including across multiple accounts)
- Sentences sometimes miss spaces between them (a fun thing AI bots do, so y'know)
- Posts repeatedly end with usernames on other platforms, or media site links (texts get split across multiple posts, so not all will end in these)

🧵 4/5

- Commonly used tags are parties, locations, and regions related to european or middle-east conflicts etc.
- May be mimicking pro-israel rhetoric, posting islamophobia, or pro-iran rhetoric, posting antisemitism, to cause anger and stir engagement from hashtags
- May be mimicking Ukrainian Azov members to make Ukraine seem dominated by nazism

Running a fedi server is not just the monetary cost of hosting the server.

Someone must spend time, DAILY, on bullshit like this as well.

🧵 5/5

@el_on_libera

report, report, report the #vatniks #vatnik accounts

their game is always straight boring mediocre #DARVO

(deny, attack, reverse victim and offender: the west is to blame for #russia invading #ukraine, somehow, amazingly)

ukraine is always #nazi, somehow, amazingly, while #putin engages in #genocide #ethnofascism #imperialism mass murder: the real #nazism

we do not need #kremlin #disinfo on the #fediverse, but it keeps cropping up. it requires your reporting