Digg Hit With Massive Comment Spam Attack

February 10, 2009

The granddaddy of all social marking sites Digg was hit with a massive comment spam attack according to Panda, with nearly a million spam comments dropped.

Over the past few months we have noticed attacker efforts to maximize blackhat SEO tactics and increase infection rates at the same time by abusing the popular social news aggregate site Digg.com. Digg allows users to create, vote, and comment on news stories.

Malware distributors have been creating false stories with catchy subject lines as an attempt to bait users into clicking links which lead to Malware. In some cases the attackers do not create the news story themselves, rather linking to others relevant content.

The idea was to lure users to a site to see controversial video then tell them they needed a video codec to see it…  Of course it wasn’t a codec it was malware.

Dancho Danchev has the complete list of domains used and the number of bogus comments pointing to each.