Ukraine takes down massive bot farm, seizes 150,000 SIM cards

DannyMac@lemmy.world to World News@lemmy.world – 1165 points –
bleepingcomputer.com
173

I always wonder if Russia would collapse, if suddenly a lot of the disinfo & hate on various online media would become noticeably quieter.

That partially already happened at the start of the war. There was a massive "brain drain" among the higher educated part of society, which did include a bunch of hackers. Why live inside russia these days when you can move elsewhere and get paid better?

2 more...

As I recall there was a period a couple years back where Russia was cut off from the greater internet and a lot of interesting things got quieter, including r/conservative on Reddit.

there's also iran, I wouldn't be surprised if north korea and china also have bot farms, and then even in america evangelical christians fund shady hate operations around the world too

its well known china has an enormous online presence set around spreading misinformation, and of course the worlds best 'whataboutisms' you are ever likely to see

You can see them all over the lemmy.ml worldnews community talking about how Ukranians dying needlessly isn't anybody else's concern and any aid to them will immediately mean nuclear annihilation of the entire world.

we need to give in to every single one of putins demands otherwise you're in favor of WW3 😠😠😠 /s

Probably. They've managed use throughput using bots, but if the government collapsed the bit farms would stop receiving funding, and the entire project would either wither away or be wiped away by a new state trying to replace the instruments of the old.

We actually did see this at the start of the war. When Russia was dealing with the new sanction and shifting focus from the west to Ukraine.

They seem to think it's important based on how much they invest into it

Oh man, where would Lemmy be without all the communist propaganda memes?

communist propaganda

It's like you know that these are words, and they're words that you've seen people put together in the past, but you have no idea what they mean.

Where is anyone talking about communism? Where is the propaganda? What the fuck are you even talking about??

Where is anyone talking about communism?

Lemmygrad.ml, I assume? I dunno if it's "propaganda," though, mainly because I haven't really seen much from that instance. It isn't defederated or anything; it just apparently isn't popular enough to show up in Active/Hot/Top.

I see a lot of communism good/capitalism bad meme content in lemmy.ml in general. Now I'm really not against communism and I absolutely see the negative effects of western society's brand of unregulated late stage capitalism, but political meme content in general is just entirely devoid of all nuance to the point where people are seriously dropping silly statements like "capitalism is the sole contributor to climate change", as if if you could turn off capitalism climate change would just stop lol. It's straight up propaganda.

That and conveniently ignoring any negatives involving China/Russia.

There are a few users on Lemmy.ml who I see all over the place. Half their posts will just be funny "lol capitalism sucks, amirite?" memes and the other half will be "Look at how China is ushering the world into a golden age of social and economic progress" or "When will the west acknowledge Ukraine's Nazi problem?"

They often seem to blame capitalism for the fact we're not in an impossible utopia.

Agreed, seems like "capitalism" has become analogous with "greed", which I mean, they sort of go hand in hand, but that doesn't mean greed doesn't exist without capitalism.

I think people also conflate social democracy with socialism, and/or communism.

And communism with Stalins dictatorship (and Xi etc etc).

The ideas behind the ideologies are all interesting but only democracy have proven "not horribly killing a large part of the population and a large part of the neighbour population" like all the time

So for me anyways, it's full democracy, then tack on socialism (for example).

I think the discussion about democracy is also largely non present, I mean how fun is it if other people just decide what they want and you can like object every X Years?

We got democracy 0.1 let's move forward!

it's kind of like how USSR/Russia was seen bad because of communism, and now since 1991 they are not communist so they are the good guys.

It is the same freaking country, they just embraced fascism over communism in the last 3 decades.

People are confusing pro-china and pro-russia users as "pro-communists" even though they don't ever mention communism and only comment things that benefit the dictators running these two governments.

We're on different instances, bet our top day looks very different.

Yes, I understand how lemmy works... I meant in these comments specifically. Otherwise the comment was a complete non-sequitor.

Huh? The comment I replied to is about disinfo and hate in online media, Lemmy is online media. I was making a joke about the content I see regularly, and clearly it landed perfectly.

5 more...
5 more...

What does communism have to do with Russia?

Only a tankie can answer that question.

This is nonsensical, nobody that regularly gets called a tankie considers Russia communist. The tiny handful of instances of children that do not know better really don't count.

6 more...
8 more...

Russia has the last laugh since they confiscated 3 copies of The Sims 3.

I still can’t believe that happened

Context? Lol

recollecting from memory: Early in the war, russian news reported they busted a nazi hideout in the occupied donbass region. The report was accompanied by a picture of swastika flags, nazi tshirts, 3 copies of the "Sims 3" game and a document signed with "Illegible". All layed out neatly on a bed.

Apparently, the instructions for staging the photo was to include Nazi paraphenalia, 3 SIM Cards and a document with an illegible signature. And someone didn't read the instructions properly (or took them too literal), and instead used 3 copies of Sims 3, as well as a document signed with the name "illegible"

Iirc the illegible signature part was debunked as it was a reference to some nazi group whose signature was "illegible" (don't quote me on that, i'm recollecting from memory). But the Sims 3 cards was at some NotTheOnion levels of ridiculousness.

Like putting "null" as your license plate except Humana are reading this, not computers. Clever but not effective.

that is one of the more hilarious things ive heard out of this whole conflict of russia continually embarressing itself

https://www.vice.com/en/article/88gpmg/russia-sims-3

It almost makes less sense WITH context.

Before anyone asks, yes, russia really is that dumb.

“We’re lucky they’re so stupid”

They wouldn't have started this war if they weren't this stupid.

Before anyone asks, yes, russia really is that dumb.

In the US, we have absolutely zero room to talk shit about other countries' leaders doing stupid shit. We sat through 4 years of Trump.

Nah we can call Trump a stupid shit along with Putin.

And Trump is running again in 2024 lmao

Dude's more impossible to shake than a bad habit.

1 more...
1 more...
1 more...
1 more...

Ukraine will never recover from that crushing blow. Without The Sims 3, those 3 soldiers will surely turn against Zelensky.

1 more...

How does this have negative three comments??

Looks like a bug! For me, from lemmy.world's web interface, it is -1 as of this posting.

As the saying goes, there are two fundamentally difficult things about programming:

  1. cache coherence
  2. coming up with good names for things
  3. off-by-one errors

Negative comment counts are likely caused by the latter.

It's something glitchy that happens when people delete comments. I know Voyager recently pushed a fix, I'm not sure about Liftoff (If I'm recognizing the UI in your screenshot correctly).

If a user deletes a comment it subtracts from the count, seems to go to negative numbers sometimes, maybe when it's removed it subtracts two on certain circumstances

why are these are being set up in Ukraine and not Russia? What do they gain from having them within reach of the Ukrainian police?

My guess is that it'd make it look like it were actual ukrainians spreading the disinfo, as the IP wouldn't show russian addresses. Could also be that Ukraine is blocking internet traffic from Russia, so being there is a way to bypass the block.

I fully expect the assholes behind said farms to be safely within russian territory, so they're just sighing and shrugging as having to set up a new base.

Still, being physically there is weird. Aren't there reliable ways to fake it?

Depends what you mean by "faking". You can fake Ukrainian IP by using some VPN service, but then you're using VPN IP which is quite obvious. If you want many genuinely residential IPs, you could use some botnet and infected computers in Ukraine. This is more authentic and harder to filter out. But some services actually require phone number and at least capability to receive texts to verify the number, some use the number as user account. (Telegram and such) Then you need actual SIM cards (not to be confused with Sims 3, the game 😉) and you need to connect to local cell tower. (perhaps you could do roaming, but that would be quite obvious long term) Now to fake all that, you'd need at least some devices operated in Ukraine and at that stage it's probably easier to find some people willing to do this locally for money or because they are high on russian propaganda themselves.

Do you need to connect to actual celltowers tho? I know legit SIMs are a kind of a barrier, but then...

Using a portal through KZ to an UA endpoint via VPN\proxy, faking geoloc and other identifying stuff on your device.

For me, it sounds like enough, and a collaborant is only holding an exit node that is easier to defend in court than having all infrastructure at their place.

Well you do if you want to receive the confirmation text. And while you're at it, you might as well use the same cell tower for data so that you get "residential" IP.

You can definitely fake geolocation and perhaps you could fake IP through some proxy, but you can't use commercial VPN services as their IPs are well known VPN IP ranges at this stage. (these SIMs might have been used as such proxies for some spamming besides being used for this specific botnet) Effectively the more you want to blend in with the actual Ukrainian end user traffic, the more you need to be present in the country and the more complicated it is to fake it otherwise. Especially if you're trying to hide from state level investigation, that has access to triangulation from cell towers, providers logs, etc..

It's just I see one collab having a gateway on their PC for russian-based labs to operare rather than the whole scheme based oin Ukraine.

Cell-tower data would be hepfull to locate the guy, but do web\apps collect it?

You can do the gateway on a PC thing. You don't even need to have collaborator to do that, plenty of people run outdated systems riddled with malware.

But once you need actual working SIM (Telegram, Watsapp, etc..) you really need that SIM somewhere in Ukraine. And you need plenty of them. (see the pictures in the article, there's a ton) At minimum to activate the accounts and more realistically for occasional re-verification. (2fa) Sure you can then run actual bots in russia, but that need for physical presence is still there at least occasionally. The article mentions 100 individuals, when you consider that 150k SIMs were there, most of the operation indeed was in russia or somewhere else.

The triangulation is just a way to maybe correlate multiple SIMs in the same spot by Ukrainian officials once they had enough suspected malicious SIMs. (So that they know it's not just few random persons with malware on their phone, but it's indeed huge concentration of SIMs in one spot)

1 more...

Sim farms can be found in most countries. Granted this is a big one.

Russia would be a less than ideal choice for criminals right now due to the sanctions affecting routes and prices between Russia and Europe.

4 more...

be interesting to see how much the usership of lemmygrad drops lol

(and the rest of lemmy)

Nah, lemmy is too small of a circlejerk to really be a target for these people. I don't think instances require working phone numbers for account creation anyway.

bruh, if its small the troll farms have no problem outmassing real ppl

Yeah but if there aren't enough eyeballs on the spam it doesn't actually matter.

Have you seen Hexbear? It's all just Russian/Chinese propaganda. If the trolls aren't posting there, the users are getting their information from the trolls and then reposting it.

4 more...
4 more...
4 more...

I'd be interested in seeing exactly what messages this farm was putting out. Lists of accounts and what networks they primarily operated on would also be very interesting.

I saw on yahoo about pringles being in Belarus a comment about how Pringles was killing “Nazzis” in Ukraine. Makes we wonder if that shit was from Russia