Sock Puppets (Covert Accounts)

- Email

Starting fresh with a brand-new email account dedicated toward use for covert profiles.

I do not recommend GMX, Proton Mail, Yahoo, Gmail, MSN, or any other extremely popular providers. These are heavily used by spammers and scammers,

The preference is to create a free email account at Fastmail (https://ref.fm/u14547153).

It does not require a pre-existing email address in order to obtain a new address.

They are fairly "off-radar from big services such as Facebook, and are not scrutinized for malicious activity.

Fastmail will provide anyone unlimited free accounts on a 30-day trial. I suggest choosing an email address that ends in fastmail.us instead of fastmail.com, as that domain is less used than their official address.

- Facebook

Providing VOIP numbers such as a Google Voice account will not work anymore. I have found only one solution. Turn off any VPN, Tor Browser, or other IP address masking service and connect from a residential or business internet connection. Make sure you have cleared out all of your internet cache and logged out of any accounts. Instead of creating a new account on facebook.com, navigate directly to m. facebook.com. This is the mobile version of their site which is more forgiving on new accounts. During account creation, provide the Fastmail email address that you created previously.

In most situations, you should bypass the requirement to provide a cellular number. If this method failed, there is something about your computer or connection that is making Facebook unhappy.

I find public library Wi-Fi our best internet option during account creation. Instagram is similar.

- Twitter

As long as you provide a legitimate email address from a residential or business internet connection, you should have no issues.

- Google/Gmail/Voice

Google will likely block any new accounts that are created over Tor or a VPN. Providing your Fastmail address as an alternative form of contact during the account creation process usually satisfies their need to validate your request.

It is more accommodating during account creation if you are connected through a Chrome browser versus a privacy-customized Firefox browser.

- Network

Creating accounts through a VPN often alerts the service of your suspicious behavior. Creating accounts from public Wi-Fi, such as a local library or coffee shop, are typically less scrutinized. A day after creation from open Wi-Fi, I attempt to access while behind VPN. I then consistently select the same VPN company and general location upon every usage of the profile. This builds a pattern of my network and location, which helps maintain access to the account.

- Phone Number

The moment any service finds your new account to be suspicious, it will prompt you for a valid telephone number. Landlines and VOIP numbers are blocked, and they will demand a true cellular number. Today, I keep a supply of Mint Mobile SIM cards, which can be purchased for $0.99 from Amazon (https://amzn.to/2MRbGTI). Each card includes a telephone number with a one-week free trial. I activate the SIM card through an old Android phone, select a phone number, and use that number to open accounts across all of the major networks. As soon as the account is active, I change the telephone number to a VOIP option and secure the account with two-factor authentication (2FA).

- 2FA

Once I have an account created, I immediately activate any two-factor authentication options. This behavior tells the service that you are a real person behind the account.

- Activity

After the account is created and secured, it is important to remain active, it is less likely to be blocked.

- Profile Content

Lack of persona details might appear suspicious to both the provider and your target.

Images: This Person Does Not Exist (thispersondoesnotexist.com). We should generate numerous images for future use in the event the site should disappear.

Name and Background: ElfQrin (elfgrin.com/fakeid php) and Fake Name Generator (fakenamegenerator.com)

Resume: To add another layer of realism to your new online identity, you might consider posting a resume online.

Physical Space: This Rental Does Not Exist (thistentaldoesnotexist.com) to generate fake interior views of a home. We can then emulate a rental home or Airbnb profile, they could be used also if you ever need to post pictures of your "home".

Links of interest:

Intro to Creating an Effective Sock Puppet (wayback archive): https://web.archive.org/web/20210307173507/https://jakecreps.com/sock-puppets/

The Art Of The Sock - https://www.secjuice.com/the-art-of-the-sock-osint-humint/

My Process for Setting up Anonymous Sock Puppet Accounts(reddit) - https://www.reddit.com/r/OSINT/comments/dp70jr/my_process_for_setting_up_anonymous_sockpuppet/

Fake Name Generator - https://www.fakenamegenerator.com/

This Person Does not Exist - https://www.thispersondoesnotexist.com/

Privacy.com - https://privacy.com/join/LADFC *$5 credit given on signup

Last updated