I spent some time creating this mind map to sum up everything you’d want to know about the scam messages, as well as the common theories. I will try to keep it updated. If you have anything to add to this or critique, please let me know.

Might take a while to load, it’s a very high res image. Here’s a link alternative: https://files.catbox.moe/csls12.jpg

This should be obvious, but due to the recent developments I want to have this here as a warning:

Don’t send the scammer any money, even as a joke.

  • qupada@fedia.io
    link
    fedilink
    arrow-up
    2
    ·
    3 days ago

    I got one with crypto addresses for “donations” for the first time today. That seems to be a new addition, messages from 2, 3, and 5 weeks ago didn’t have them.

    I have also received some “alternate” versions from pseudo-random usernames (ones not on your chart) from the sh.itjust.works instance. Mostly the same copy as always, but delivered entirely in an image rather than image+text. Thought that was interesting.

    • FQQD! @lemmy.ohaa.xyzOPM
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      3 days ago

      The crypto adresses are back? As far as I’m aware, they were being sent out a week ago, but then stopped again. God damn it. But yeah, I have to add the new usernames

  • originalucifer@moist.catsweat.com
    link
    fedilink
    arrow-up
    20
    ·
    16 days ago

    i love everything about this… huge diagram fan…

    my only criticism is the lack of mbin… ive been nicoled ~5 times directly on an mbin instance.

    only really pertinent because im on a small instance with ~ 180 user accounts. how does she knooooow

  • ShadowA
    link
    fedilink
    arrow-up
    19
    ·
    edit-2
    16 days ago

    I can add a few data points… https://lemmy.ca/u/fujinamilo was the nicole spammer on lemmy.ca, they used this account to test getting through filters. They logged into it from a VPN, and logged out (destroyed their session) when they were done.

    They seem to message in batches of users, notice how both batches went to the same users in the same order at the top here: https://lemmy.ca/pictrs/image/b40f9e02-a162-4e56-8b5e-79b563a786c9.png

    They like to spam the same users repeatedly: https://lemmy.ca/pictrs/image/ffd36fbd-2452-4806-960a-6d291b9c6d1a.png

    Seeing as they actively joined lemmy.ca and tried to get through my filters after I made a post about them, it’s reasonable to say they’re watching us and probably having a lot of fun playing with everyone. Have we tried just asking for an AMA?

    • morbidcactus
      link
      fedilink
      arrow-up
      8
      ·
      16 days ago

      It’s kinda interesting that they seem to be targeting specific users, glad your filters are working.

      I really want to know how people are being targeted. I’ve only received one, have zero idea if it was a specific post or community? I think mine was after a post rather than a comment, but I can’t recall.

  • Nougat@fedia.io
    link
    fedilink
    arrow-up
    9
    ·
    16 days ago

    The first one I received here was about a month ago from “missy29” at lemmings.world. Body of the message still said “Nicole” though, with some very early boilerplate text.

    For completeness sake, I’ve also gotten from a nicole101 and a nicole40.

        • Nicht BurningTurtle@feddit.org
          link
          fedilink
          arrow-up
          6
          ·
          16 days ago

          Most of the used instances are abandoned without active moderation and even with the email requirement, there isn’t a built-in way for lemmy to filter out temp mails. The abused instances are unlikely to have automod running.

      • ShadowA
        link
        fedilink
        arrow-up
        6
        arrow-down
        1
        ·
        16 days ago

        I mean if i was doing this I’d add crypto addresses just for the lols, and wouldn’t actually expect any.

    • Olgratin_Magmatoe@slrpnk.net
      link
      fedilink
      English
      arrow-up
      12
      ·
      edit-2
      16 days ago

      The picture doesn’t seem to be AI, and it’s unlikely to be the person from the picture. I highly doubt someone would use an innocent person’s face for spam across the fediverse for the sake of improving security.

      Especially because the security against spam was always going to be put to the test no matter what.

  • Okuyasu@lemmy.ml
    link
    fedilink
    English
    arrow-up
    5
    ·
    16 days ago

    Ok, i’ve been thinking about this since the first time i received a nicole spam message because of the timing and what i was i doing and saying at that moment on another lemmy account and maybe i’m just paranoid, but you don’t go and pull a pig butchering scam on a platform like this or any scam that is so obvious.

    What i think is this is a mass surveilance attempt and in this thread https://lemmy.today/post/25826615 someone try to explain what might be happening. The bitcoin scam and everything else are probably a decoys in my opinion.

    I could be wrong but this is all too fishy.

  • Captain Aggravated@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    3
    ·
    15 days ago

    It would be really cool if Lemmy, or some similar ActivityPub platform, could host brainstorming apps like that.

    I remember being part of r/celebritynumbersix and it was basically impossible to maintain any kind of database.

  • Sibshops@lemm.ee
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    16 days ago

    The crypto scam may be a copycat. If you sort by new in this community, the latest messages don’t have a crypto address in it.

    • FQQD! @lemmy.ohaa.xyzOPM
      link
      fedilink
      arrow-up
      5
      ·
      16 days ago

      Possibly, but I think there was also proof provided by multiple people that it is real. I think it’s not only in the messages, but also on the matrix server.