Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Leaky Elasticsearch Server Reveals Massive Instagram Click Farm

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,908
Reaction score
943
Points
212
Awards
2
  • trusted user
  • Rich User
Security researchers have uncovered a massive Instagram click farm in central Asia, operating tens of thousands of fake profiles.

A team at vpnMentor found the operation thanks to a completely unsecured Elasticsearch database it was using, connected to the public-facing internet.

“The click farm appears to be run by a sophisticated operation that has built a highly automated process to create tens of thousands of fake proxy accounts on Instagram. Each account had its own avatar, bio and ‘persona,’ appearing to join Instagram from all over the world,” said vpnMentor.

“Each fake account would then publish posts, view others’ posts, follow, react and engage with profiles. The click farm was also using proxy servers and IP addresses to hide its activity.”

Operated from either Armenia or Kazakhstan, this C&C server contained usernames, passwords, proxy IP addresses and email addresses for the fake accounts, as well as related SMS verification codes and phone numbers.

The researchers tied the operation back to central Asia as many of the IP addresses and mobile phone numbers used to authenticate and run the fake accounts were from Armenia and Kazakhstan.

“Click farms are often paid by individuals or companies to inflate their followers and engagement. The people hiring click farms then use this to leverage sponsorship posts and other forms of income from the app. In doing so, they’re defrauding any company or third party that pays them based on followers and engagement,” explained vpnMentor.

“Click farms are also used to spread fake news and misinformation. There is plenty of evidence that this is already a widespread practice and a popular form of election interference, manipulation and indirect attack on rivals by governments like Russia, China, Iran and their allies.”

After notifying Facebook about the server on September 21, it was shut down the following day.
 
Ad End 1 February 2024
Top