this post was submitted on 09 Apr 2025
147 points (96.2% liked)

Nicole [LOCKED]

366 readers
4 users here now

Due to recent developments, we've had to lock down this community until further notice. For more information, please take a look at this post: https://feddit.org/post/10515288

Thank you for your understanding.

founded 1 month ago
MODERATORS
 

What happened?

Due to the recent developments, I have decided to make this community moderator-only. There has been a mass spam attack involving gore and nudity. This is now a very serious situation and it is clear that something has to be done to stop this from happening. The new messages might be from a different, psychopathic spammer.

What we decided to do about it

To have better control of this situation, we decided to lock down the community, except for the comment section on this very post. (Please let me know if I've missed a post)

Rules

  • Please refrain to further spread the newest spam image, especially uncensored versions of it.
  • The "It's my girlfriend!"-joke is long gone. Be respectful, stop using it.

Going forward

Our main goal now is to stop the spread of spam on Lemmy. This seems like a major problem in Lemmy's concept, so we need to work together to create a working solution to the spam and potential defacing of users.

Update: The source of the gore images has been identified, so it's safe to say it's not actually the same person as "Nicole". Still fucked up, though.

top 50 comments
sorted by: hot top controversial new old
[–] oce@jlai.lu 13 points 4 days ago* (last edited 4 days ago) (2 children)

Just wanted to report that the latest Nicole spam I received 10 min ago is asking for crypto "donations".
So this may be finally the reason for the phishing, getting crypto donations from gullible people.

Looks like this:

https://i.imgur.com/....png (the usual stolen webcam shot and description)

Please donate to help me pay for next semester!

BTC: ...

LTC: ...

XMR: ...

By the way, has anyone contacted Imgur about this? I think they would take it pretty seriously.

[–] DakRalter@thelemmy.club 4 points 3 days ago* (last edited 3 days ago) (1 children)

I got one just now as well. I suspect it might even be a different person using the Nicole spam as a cover?

Edit: does anyone know, are there any plans to allow users to disable DMs? It feels like it should be a basic privacy feature and would have stopped all this. Mastodon has the same issue (apparently there's an option to stop non followers DMing you, but I can't find it).

[–] myrrh@ttrpg.network 4 points 3 days ago (2 children)

...i received the same message yesterday with a new image, so i suspect it's the original spammer finally firing his payload...

[–] DakRalter@thelemmy.club 2 points 2 days ago (1 children)

more Nicole spam

This was the username (already reported). The Nicole text was part of the image (green text on black) and the message body was the bitcoin IDs. I find targeting the Fediverse for this type of scam to be a bit pointless. I doubt there are many people on here who would fall for this sort of scam. The only advantage I can see to targeting the Fediverse is the inability to restrict private messages.

I got the message a few mins after logging on. Both times on Lemmy, I got the Nicole spam when online (I can't remember if that was the case on Mastodon). I don't know if that's coincidence.

[–] myrrh@ttrpg.network 3 points 2 days ago

...i've received nine nicole messages, each from different usernames, but the payload message was from goldeneyeitemis@lemmy.laitinlok.com...

[–] DonaldJMusk -2 points 2 days ago* (last edited 2 days ago) (1 children)

I think the orginal spammer was a loser who got shunned by her, wanted his revenge and posted her pics and info all over to get revenge. (I also think it was the same person who got pissed at me and stalked me all over lemmy for several months, then started using spam bots to track and downvote my posts. As soon as someone mentioned he may have had ties to nicole spam, he deleted his account and disappeared.)

The new spammer is taking advantage and trying to get a payload. Because the whole vibe is different in the new ones.

[–] UnwittingSenior@leminal.space 4 points 2 days ago (1 children)

What makes you think they're linked?

[–] DonaldJMusk -3 points 2 days ago* (last edited 2 days ago) (1 children)

I wrote about it earlier in this same thread: https://lemmy.today/post/27138344/15514958

Basically, the guy who was stalking me had this obsessive, relentless vibe. He’d actually brag about using alt accounts to follow me so I wouldn’t know it was him, and even admitted to “poking” me just to try and make me "snap." Eventually, someone looked into his behavior and discovered he was using a spambot army to follow and mass-downvote me. During that investigation, someone noticed that the domain names tied to the bots matched the ones used in the infamous Nicole spam when it first started. His account also happened to be created right around the time that spam started.

As soon as that slight connection was made public, and after stalking me, trolling me, and downvoting me for months, he suddenly deleted his account (PapaSkwat@lemy.lol -- the account has been deleted, so I feel I can actually name it).

So maybe it’s just coincidence. But his obsessive behavior, his refusal to let anything go, and the way he bragged about using multiple accounts to bug me, and bragging about trying to run me off Lemmy, lines up exactly with the kind of person who might launch a spiteful spam campaign against the girl who is victim of the Nicole spam.

The timeline, the tools he used, and the general attitude; it all fits. Then again, there are plenty of unstable people online, so who really knows. Just my take.

[–] UnwittingSenior@leminal.space 4 points 2 days ago (1 children)

Wow, you're the only person I've heard being targeted by the same person. What'd you do to piss them off?

[–] DonaldJMusk -5 points 2 days ago* (last edited 2 days ago) (1 children)

I posted news articles from conservative sources to conservative communities. lol

He was so mad about it, he'd follow me to non-political communities just to mention it, then would downvote. Then he ramped up his campaign and started using the spambots.

For example, in a Positivity community, I posted a short post about my scooting on a nice day, "Great day for a simple scoot." He unleashed the bot on it and it has 60 downvotes. https://lemmy.today/post/27013791

Notice that after he got called out and deleted his acount, now my posts there eventurally get up to the regular-ish 5 upvotes that those sort of posts typically get. (They always start out early with a "0" though, because there is still another person that downvotes all my posts. But that person doesn't unleash bots on me, so all good) !positivity@lemmy.today

In the middle of his hate campaign against me, I actually asked him why didn't he just block me or the 3 conservative communities I posted to. And he said that he wanted to keep bugging me to make sure that I left Lemmy.

It was weird. I never even thought of leaving Lemmy, so not that big of a deal to me. But it's super fascinating to me that there are people out there who actively want to hate and be unhappy. So strange. Lemmy is just an online forum, no idea why so many take it so seriously.

Obviously me being a conservative on Lemmy means I get plenty of downvotes and spite. I'm fine with that. It's expected. After ragging on me a few times, most get bored and realize that I'm not going anywhere, so they just block me and/or conservative communities.

But that dude was on a whole 'nother level. LMAO

Again, I don't know for sure he was the same guy who's behind the Nicole campaign, just that the timing and his behavior totally lines up with it all. Just my personal theory and I have no solid proof at all.

[–] UnwittingSenior@leminal.space 4 points 2 days ago (2 children)

hate campaign

You're blameless and think other people take Lemmy too seriously?

[–] Flax_vert@feddit.uk 6 points 4 days ago

It's clearly not the same as the gore spammer if real nicole spam is still happening

[–] Coelacanth@feddit.nu 7 points 5 days ago (2 children)

I just received a DM from a new account following the same pattern as the gore spam, 2+ year old account and the image link named after my username. This time it was a red anime picture saying "Do you like insanity?". Same person as the second actor?

[–] Flax_vert@feddit.uk 7 points 5 days ago* (last edited 5 days ago) (3 children)

Got that dm as well. They are posting the dead nicole image. I reverse image searched it and it's from a gore website.

It's description is

Murdered woman on autopsy table CHINA Leaked footage from a Chinese morgue shows a woman who died after being attacked with a machete. The attacker stabbed her neck several times and almost cut off her ear. Other details are unknown.

Caution, full link has a dead body

[–] Flax_vert@feddit.uk 7 points 5 days ago* (last edited 5 days ago) (1 children)

It has a pastebin link

https://pastebin.com/m2skUXKN

Pgp public key

`-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEZ/ltsRYJKwYBBAHaRw8BAQdAirxngMSSqXGY0goRu5FeYPoSz6lGJPloz47n AKE4LIC0FUx1Y3kgPGx1Y3lAbHVjeS5sdWN5PoiTBBMWCgA7FiEEJmm9ee5H8hQN ujkVxRtYJXxnnZQFAmf5bbECGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AA CgkQxRtYJXxnnZRMdAD/ZTLsn1ece6qnGdNXodRdo9Eow4gOYbxq4AC8i4aaZZUB APOWxTjeK+YTsJu8Si3yEFrA7D6iCMnNS4yu0Kh4JrsGuDgEZ/ltsRIKKwYBBAGX VQEFAQEHQET+MYK1cO9X2eH5jPx5bKyjgY+NCJ7gCBHntxyATBA8AwEIB4h4BBgW CgAgFiEEJmm9ee5H8hQNujkVxRtYJXxnnZQFAmf5bbECGwwACgkQxRtYJXxnnZTw IgEAzjCEEcCnezg291terQ7/2nDar50S2UM+MHVJvllMqp0A/3oOmeKLPwZY9fwh oev5mxZRkrxq4Ori1i+bqhOh45sN =BA26 -----END PGP PUBLIC KEY BLOCK-----`

[–] Flax_vert@feddit.uk 7 points 5 days ago

Key's registered owner

[–] Olgratin_Magmatoe@slrpnk.net 5 points 5 days ago

I looked it up, and the other pictures on that site show the woman's face in it's entirety up close. It definitely isn't Nicole.

[–] Coelacanth@feddit.nu 4 points 5 days ago

Same account that just messaged me.

[–] Olgratin_Magmatoe@slrpnk.net 6 points 5 days ago* (last edited 5 days ago)

I just got the same shit. And I'm guessing the previous two DMs were also the same. I didn't realize that the links were to something other than my profile.

It looks like they're now posting the 1st gore image directly to communities everywhere.

[–] Coelacanth@feddit.nu 8 points 5 days ago (1 children)

Has anyone been getting "regular" Nicole spam since the gore picture event? If so, do they resemble the old style of spam in terms of content and instance it's sent from?

[–] IndieSpren@lemmy.blahaj.zone 3 points 5 days ago* (last edited 5 days ago) (1 children)
[–] Coelacanth@feddit.nu 4 points 5 days ago

More indication then that the gore spammer was a secondary actor.

[–] Irelephant@lemm.ee 12 points 6 days ago

I would like to thank the instance admins dealing with this. I haven't seen any apart from the initial wave.

[–] coldsideofyourpillow@lemmy.cafe 10 points 6 days ago* (last edited 4 days ago)

Yikes, the fun is over now. This has escalated too much.

[–] DonaldJMusk 2 points 5 days ago* (last edited 5 days ago) (2 children)

So I may have a distant and weird connection to the originator of the Nicole spam. No proof, but here's my case.

I had this weird stalker on Lemmy—PapaSkwat@lemy.lol (account’s deleted now, so I think it’s fine to name him). Someone else did some digging and found out he was using a bot army to follow me around and downvote my posts.

While people were investigating that, they noticed something strange: the domains used by his bots matched the original Nicole spam domains.

Then, right after that investigation thread dropped, PapaSkwat suddenly deleted his profile. The same profile that had been active since around the time the Nicole spam started. And he’d been trolling and stalking me for months. One of his comments even admitted he was deliberately poking me to make me "snap.”

There’s this theory that the whole Nicole spam thing might’ve started as revenge. Like, maybe some guy got dumped or rejected, got obsessed, and started blasting her pics everywhere because he couldn’t let it go.

That kinda lines up with my stalker’s behavior. He’d get mad, obsessive, and go out of his way to tell people how awful I was. He even bragged about using alt accounts just to mess with me.

It was bizarre.

So here’s the chain: weird stalker gets outed for running downvote bots → bots are tied to Nicole spam domains → stalker suddenly vanishes → and now Nicole is “dead” (not for real, but metaphorically, like the spam just ends).

Maybe the guy realized the jig was up and decided to kill off the whole Nicole thing too?

I have no clue, no proof other that people's assumptions. It just seems a strange coincidence that my weird stalker guy disappears right after rumblings come up of him being involved in Nicole spam. Then right after he disappears, this dead nicole spam comes up.

Here’s the bot investigation post (2 Instances are being used for coordinated vote manipulation, and should be defederated. chinese.lol lemmy.doesnotexist.club): https://hackertalks.com/post/8713785

And here's a screenshot where he brags to someone about trying to make me "snap" and another where he brags to me directly about having alt names to stalk me too:

[–] Coelacanth@feddit.nu 6 points 4 days ago* (last edited 4 days ago) (1 children)

I sincerely doubt this has anything to do with you at all, and the only link is that those instances seem to have absentee admins who aren't taking action to ban users. Which is attractive to both spammers and botters.

So here’s the chain: weird stalker gets outed for running downvote bots → bots are tied to Nicole spam domains → stalker suddenly vanishes → and now Nicole is “dead” (not for real, but metaphorically, like the spam just ends).

Maybe the guy realized the jig was up and decided to kill off the whole Nicole thing too?

No. That is in fact not the chain of events as both regular "Nicole" spam and the gore spam (and now the anime picture spam) have continued well past your "stalker" got banned. In fact, both types of spam seem to still be ongoing.

Regular "Nicole" spam and the gore/anime spam have also occurred (and is still occurring) in parallel, with culprits using different origin instances.

Everything suggests this is (at least) two different, separate actors.

load more comments (1 replies)
[–] FQQD@feddit.org 3 points 4 days ago (1 children)

This might actually be a very good hint on who the spammer is. Thank you a lot for sharing.

[–] Coelacanth@feddit.nu 6 points 4 days ago

Is it? Aren't both regular Nicole spam and the potential "second actor" spam still ongoing?

I do believe those instances were chosen for the same reason though, as they seem to have absentee admins who aren't banning spammers and botters.

[–] fyzzlefry@retrolemmy.com 5 points 6 days ago

The end of an era

load more comments
view more: next ›