Sohan Dsouza
@sohandsouza
🥼 @MPIB-Berlin.bsky.social; 📚 computational social science, disinformation/polarization, crowdsourcing, OSINT; 🎓 @MIT.edu @MediaLab.bsky.social, @DFRLab.bsky.social #DigitalSherlocks; 📍 London, England;
Though I'm surprised that this tactic persists, given that ad revenue share was moved from replies to timeline (which I doubt many visit, especially verified users). Since before 2026/APR, it seems. Perhaps it will take some time before they adapt, but I wonder how precisely they might do.
Unfortunately, reply bait is effective, because far too many people unthinkingly bite.
And one Pakistan-based grifter account copy-posting engagement-bait AI slop off another. Seriously, the amount of garbage on that platform.
Meanwhile, in the actual Bible, Jeremiah's "jeremiads" were proven correct in the end. It appears that self-described "cultural Catholic" Lord Young of Acton is adhering to "Catholic culture" e'en to the point of not reading the bloody scripture.
😈📈🧑💻💸 @san.com just published a piece about the recent burst of ads using deepfaked images of media figures and big corporation executives to lure social media users onto webpages impersonating the BBC. It cites my relevant investigation and views extensively. 🧵
… But the same app (TKvZKKkc) and referrer (AFF-ZEOZRQY0DU) at "beautyhairloss.com" deflects scans from both archive•today and URLScan for NeoCapital referrals. Interesting.
It appears some of the sketchy domains are in fact using scanner/crawler deflectors. Though some scan attempts are slipping through. For example, an app at "britishcurrentnews.com" lets in both scan attempts for Garlenix referrals, and blocks only the URLScan attempt for Crest-Fundgrove referrals. …
I took this picture at the Isabella Stewart Gardner Museum in Boston. "From land near or far, thou mayest seed societies with divisive bullshite through mine Book of Faces, and I shall continue to pretend to be concerned while I am greatly enriched by it."
Found an unusual one. Same ad and clickthrough images, and same BBC-impersonating site. Not only a new domain, though, but a new domain registrar and providers, and referral signature. Still a referral to Garlenix, but also subbing (algo trading tool?) "fathbot". New identity, or new operator?
One of the Farage ones is still up since last week, and so is its domain. Clearly this is not a matter of great urgency for the hosting/CDN services.
I was able to find more by searching for the referral signature. Though only the linked posts (all of which use the same fake thumbnail image), and not the ad posts (which use from among a set of variant images).
Another one, with a server down. All of the impersonator domains are registered (anonymised) at @dynadot.com and running through @cloudflare.social. If possible, I'd suggest blocking traffic matching the "name=garlenix" pattern.
Interestingly, this burst of ads uses variations of the same scene. I wonder if some kind of A/B testing is going on behind the scenes. I'd also be interested in knowing what software might be used for deployment and analysis.
And another one! You've gotta be kidding me. Literally in the same thread. But the impersonator server seems to be down now. Or detected that it is being accessed by scanners, and shut down (domain not responding to ping, though the other impersonator domains still do).
Crazy thing is, yet *another* such ad appeared in the thread *for the very post* calling out the ad. This time with an indicator of possible VPN location obfuscation into Finland.
Another one, at a different URL. Same tactic of linking to another post that also has cryptic text and a fake video thumbnail.
Another deceptive Garlenix BBC-impersonating referral ad, this time conscripting @maitlis.bsky.social (links in images' ALTs)
I made a collage at an art workshop today. You can see what's on my mind.
Getting between a fox and a bin? Ya boi's already giving London vibes.