this post was submitted on 12 Nov 2023
60 points (76.8% liked)

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

53370 readers
661 users here now

⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don't request invites, trade, sell, or self-promote

3. Don't request or link to specific pirated titles, including DMs

4. Don't submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder


💰 Please help cover server costs.

Ko-FiLiberapay


founded 1 year ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 34 points 9 months ago

Low effort speculation:

That's a vodaphone portugal IP, but this is likely traffic routing though their customer cellular network and not their corporate. It's possible that someone in PT has a similar username for this service and is fat fingering it. It's also possible that you're seeing a tiny sliver of a larger attack.

Spur.us tracks that IP as an egress point for openproxy and windscribe ResIP networks so it's worth considering that the origin of the authentications you're seeing may not be Portuguese cellphone but someone hiding behind those services.

Here's a paper describing the difficulties such a service creates for folks trying to secure accounts with traditional IP reputation based rules. "Resident Evil: Understanding Residential IP Proxy as a Dark Service" https://ieeexplore.ieee.org/document/8835239

Shooting in the dark for how a bad actor would monetize account takeover for this service if this is in fact an attack.... They could try to sell your invitation to that private tracker. They could also look to scoop up a bunch of folks to try and blackmail based on what victims are download/seeding. Other more creative options I'm not thinking of might be on the table.