About this session
Masarah Paquet-Clouston of Université de Montréal and Olivier Bilodeau, then research director at GoSecure, revisit their 2019 Black Hat and DEF CON research on the supply chain of social media manipulation and check what has changed. At the bottom sit IoT botnets such as Linux/Moose, now joined by the leaked Russian Fronton botnet built for the FSB and used for political campaigns in Kazakhstan. Residential proxy services follow: RSocks was taken down by the FBI and European police in June 2022 as a botnet of millions; Luminati became Bright Data with its EarnApp; and a new opportunistic actor, the residential proxy enabler, installs traffic-monetising software on badly secured RDP hosts. Automation software, account creators such as PVA Creator and bulk account sellers are still sold openly. Reseller panels still cluster on sixteen IP addresses behind one panel-as-a-service provider, and customer-facing sellers like Devumi are back despite a New York settlement. A live purchase of 22,500 followers for four dollars arrived within hours. The ecosystem is cheaper and stronger, law enforcement is finally engaged, and the trade is overwhelmingly commercial.
Social media manipulation, the deliberate act of increasing the visibility of specific social media posts or accounts, is as relevant as ever. Used to divide a population’s opinion, increase the popularity of influencers, or manipulate product ratings, such manipulation is a dangerous form of fraud that should be studied and monitored. In 2019, Masarah and Olivier presented at Black Hat USA and DEF CON the culmination of four years of research on social media manipulation driven by malware. They unveiled an industry in which many actors are involved in the supply chain of such online manipulation, from customer-facing sellers, bulk resellers, reseller panel providers, residential proxy providers, automation software providers and botnet operators. In this presentation, they will review their research findings in light of today’s ecosystem, three years later. What else has been uncovered about social media manipulation? Are the actors above still active? Are there news actors involved? Attend this interactive session to learn the current state of affairs on security research about social media manipulation, a critical-yet-overlooked factor in the current divide of our society.
Key takeaways
- Residential proxy services are the hinge of the ecosystem: assume a cheap residential IP is either an infected consumer device or a monetised app, and block known proxy ranges accordingly.
- Secure exposed RDP with strong credentials and MFA; opportunistic attackers now install traffic-monetising proxy software rather than writing malware, and your servers become fake-follower infrastructure.
- Passive DNS on a single reseller panel domain still exposes the whole cluster: thousands of panels share sixteen IPs behind one panel-as-a-service provider, useful pivots for investigators.
- Treat follower counts as meaningless signals of credibility; 22,500 followers cost four dollars and arrived within hours, and the fake profiles now carry photos and bios.
- Platforms purge fake accounts in periodic sweeps rather than blocking at creation, so manipulation is an arms race driven by commercial motives, with an estimated 90 percent of bought engagement serving products and influencers.
Speakers
Masarah is an assistant professor at Université de Montréal and a research collaborator at the Stratosphere Laboratory affiliated with the Czech Technical University in Prague. She holds a Ph.D. in criminology and is specialized in the study of… Read moreRead less
Masarah is an assistant professor at Université de Montréal and a research collaborator at the Stratosphere Laboratory affiliated with the Czech Technical University in Prague. She holds a Ph.D. in criminology and is specialized in the study of profit-driven crime enabled by technologies. Previously, she worked five years at GoSecure as a researcher and has presented at international conferences including NorthSec, BlackHat, DEFCON and RSA.

Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur… Read moreRead less
Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur passionné, Olivier a présenté lors de conférences telles que AtlSecCon, BlackHat, DEFCON, SecTor, Derbycon, et bien d’autres. Très impliqué dans sa communauté, il coorganise MontréHack, est président de NorthSec, et anime son Hacker Jeopardy.
