I have made a post about some Mastodon instances being associated with malware and explaining what I found: https://github.com/mastodon/mastodon/discussions/18688
I think it can be interesting for people who are #mastoadmin + would love to have people from #cybersecurity have a look and share any feedback. Thanks.
@cambridgeport90 I just read that... Upvoted all posts in the discussion.
@hugo around 20 years ago various large IRC channels were shut down because they were being used for C&C. I then wrote a test program that made Twitter usable as a C&C frontend. At that time there was still an RSS feed and you could easily search it for commands. I then steganographically hid the commands in cat images that were delivered as PNG.
Since I got the hang of it with my little knowledge and in a few days, I'm sure that such or similar methods are probably widespread.
@hugo wait so mastodon safe to use? Also one of my old friends is a cyber security expert that researchers these sort of thing an also crazy about crypto security.