Beware the WireMin scammers

Wiremin is an app promoted by scammers, and those scammers are slowly getting smarter.

Originally, they tried promoting it via direct concern trolling across multiple Reddit threads.

When that became too obvious, they started doing “call and response” across a small handful of Reddit accounts, where one user would ask a leading question and the other one would respond "WireMin is the best, of course!"

  • On r/ChatGPT, Fun_Belt_29 makes a thread to promote it while disguising it as a post about ChatGPT.
    Top response: "Wow, you must really love wire min. Practically every single comment you’ve ever made is about it - often asking what it is even after you’ve already posted about it."
  • On r/conspiracy, NoPermit9887 posts about how the app is so great.
  • On r/Nostr, a deleted user (the web archive reveals it to be NoPermit9887) asks for differences between Nostr and WireMin.

But now, they’re here…

tioute: A case study in Lemmy

A user who goes by tioute(@)lemmy.world is a WireMin veteran.

I just joined Lemmy, and I never expected to see people discussing WireMin here. Considering its super small user base, hardly no one I know uses it. So I usually use to store all my dark moods since it is secure and complete anonymous… I use ChatGPT on WireMin anonymously…

  • tioute, September 8, 2023 (deleted)

Scuttlebutt decentralised social network, and yes, Wiremin.

  • tioute, September 18, 2023 (deleted)

But suddenly, tioute has severe memory loss and can only ask questions about Wiremin:

I’ve heard of Mastodon and Misskey… But what is WireMin?

  • tioute, November 3, 2023 (deleted)

Is @WireMin also a chat app?

  • tioute, November 20, 2023 (deleted)

After deleting these comments, tioute has started aiming for a lower profile by only linking to people talking about WireMin. Like this comment on an innocuous post made by bachalxyz(@)lemmy.world, which is innocuously Just Asking about Wickr alternatives.

It would be really funny if bachalxyz also had a history promoting Wiremin, wouldn’t it?

WireMin happens to be one of the encrypted software I’ve been following. What makes WireMin special is [nobody cares about the spyware features]

  • bachalxyz, Tue, 29 Aug 2023 (deleted)

People should seriously consider migrating to alternative platforms such as Mastodon WireMin [link removed]

  • bachalxyz, 18 Oct 2023 (deleted)

(In case you’re wondering how I got my hands on deleted comments, you can DM me to ask, but I would prefer to keep these methods relatively quiet for now.)

01189998819991197253,
@01189998819991197253@infosec.pub avatar

The wiremin crew saw your post, and promptly downvoted it lol

Thanks for the heads up!!

possiblylinux127,

Someone should do a in depth report

TheAnonymouseJoker,
@TheAnonymouseJoker@lemmy.ml avatar

Just a reminder that the privacy related subreddits are the equivalent of a graveyard and a dumpsite. They all more or less died when the Reddit exodus happened.

I am using Reddit for very specific niche things, and no longer check the privacy graveyards and powermod hijacked shill boards that they are, so thanks for alerting. Happy to see there are a few vigilantes in my absence.

dfc09,

That’s funny, I saw that first comment by toiute in the wild and thought it was really strange. Lemmy seems like such a waste of time as a platform to promote scams. Very low population (relative to other social media) and a mostly tech-savvy crowd.

Good work! Glad to know

dessalines,

Thx for this, I took care of em. Keep reporting these scammers in the future and we’ll get to it as soon as we can.

driving_crooner,
@driving_crooner@lemmy.eco.br avatar

What’s that app and what supposed to do?

LWD, (edited )

What’s the app? A messaging app. What does it do? In addition to the purported messaging feature, it seems to turn your phone into some kind of proxy that routes traffic. From where, to where, and for what purpose, I don’t know (and I don’t think anyone else does either).

driving_crooner,
@driving_crooner@lemmy.eco.br avatar

And what’s the endgame for the scammers?

LWD, (edited )

I have no idea. One possibility is they are reselling the free bandwidth, using your device within an onion network to distribute illicit content…

All I do know for certain is that you can’t take their actual claims at face value. Don’t just assume the creators of an app have the key to decrypt your data, assume it’s never encrypted to begin with. They don’t explain how, they don’t show their work, they don’t show their source code, so there’s no reason to assume they ever did.

TheOSINTguy,

Sounds like a bot net.

bionicjoey,

I love your username. There’s gotta be some way to make money off that!

driving_crooner,
@driving_crooner@lemmy.eco.br avatar

It’s just too good!

possiblylinux127,

That’s what I’m asking

LWD,

Extra notes: by controlling the posts they create, the scammers might be able to better control the blowback from getting discovered. For example:

lemmy.world/comment/6032277
Commenter: Jat620DH27
Poster: bachalxyz

lemm.ee/comment/1544162
Commenter: woshang (banned)
Poster: Jat620DH27

It’s probably just one person cycling between accounts, but it’s interesting how cyclical it really is.

HonkTonkWoman,

For those of us who have no idea what Wire Min is… what is it?

I was going to google it, but that doesn’t seem so smart given this thread.

LWD,

From what I remember seeing on Reddit, a messaging app that is big on promises and small on features, and it might turn your phone into a proxy for internet traffic.

Despite the stuff I was able to find here, I wasn’t able to find the posts remarking on that.

HonkTonkWoman,

Thanks, appreciate the info!

long_chicken_boat,

Oh I answered the wiremin asshole a bunch of times and they deleted their posts when I told how wiremin was suspicious as hell and shouldn’t be trusted.

LWD,

I would recommend copying your comments out of your own profile and putting them somewhere else… In a community just for you, for example. That way, you can just link to them and not have to search for/recreate them later

  • All
  • Subscribed
  • Moderated
  • Favorites
  • privacy@lemmy.ml
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #