Oof. A massive spam attack just now on mstdn.social

A few thousand signups all accounts starting with "SAAR_"

I STRONGLY recommend admins to BLOCK this name from signing up 🚨

This goes on for a while..

All suspended and signups closed

It seems email domains are reused, here are some to block:

reevalmail.com
bientotmail.com
sabesmail.com
bonjourfmail.com

@stux @Oregon_Pacifist Here's something you may want to see.
@stux Don’t forget whitehouse.gov
@64bithero @stux or @ theRealDonaldTrump

@RichieRich @64bithero Or this sucker his site

https://jdvance.com/

OH WAIT 😆

JD Vance for U.S. Senate

JD Vance: Conservative Outsider Running for U.S. Senate in Ohio.

JD Vance for Senate Inc.
@stux @64bithero Aaah, malware! This is awful. 😆

@stux

Yikes.

Hey @trumpet, in case you're seeing any of this.

@deirdrebeth @stux @trumpet I thought mas.to was invite only?

@cnk @stux @trumpet

Ah right! That does tend to solve these types of issues 🙂

@deirdrebeth @cnk @trumpet ish 😉

If they manage to get an unlimited invite you're still oof if that's not blocked

Keep an eye out

@cnk @deirdrebeth @trumpet For now these 4 email domains seems to be it, plus the "SAAR_" in the username

It was a bad bot but super duper mega fast..

@mikelovesbikes @stux
Thank you both for bringing this to my attention.

I blocked sign-ups that begin with SAAR_ and I've blocked the 4 email domains.

@stux That's crazy..
@stux Soundvoice's new AI? Or someone exploiting it to fuel spam.
@stux You can do that? With a partial string match like that? Zesty.
@Sempf Yup, "equals" or "contains"
@stux Wow! Neat feature for an open source project. Me likey.
@stux At least those are easy to block. Very odd.
@alterelefant @stux Exactly. I wonder if there is something we are missing. Maybe there is something else going on.
@stux they seem to originate from Asia
@stux cc @mdallastella in case anyone has tried to apply for an account consistent with this behavior

@trebach @mdallastella They also send massive amounts of applies, still costing money for all mails  

Be careful

I've turned off signups completely now

@stux

​ ​​ ​​ ​

Well done.

So sad so many ... individuals of dubious origin ... try to exploit & ruin things for everyone.

@stux

I'm glad to be under the stux umbrella!

@stux

I made an annual donation back in Feb via Patreon, hope you received it!

@FallsMom Thank you ❤️ it means a lot  Amazing to see we can build something wonderful together!
@stux From what I gather, they were spamming invites to a Discord room with the code "krebble" - they were trying to DDOS #KrebsOnSecurity, and I think they also doxxed one of their members.
@csolisr @stux pretty bad opsec for them to not use any vpns nor proxies doing that
They explicitly boasted about having thousands of domains and millions of residential IPs at their disposal. Being very public about it was part of their advertisement strategy
@stux blocked a couple of those accounts already, got fed up with them continuously following me back after repeated attempts at removing them from my follower list.
@stux I've heard that instance is always under some kind of attack... is that true?

@kshernandez Haha no ♥️😸 I can know since I own it!

I keep an close eye but since we are one of the bigger instances we often are a target if something happens

@stux Ah! Yes, then you would know. lol :)
@stux Are you ok with me dm'ing you about something?

@stux

The attackers will just change the prefix.

@stux One has to wonder why they so conveniently make it stand out.