惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
雷峰网
雷峰网
Last Week in AI
Last Week in AI
T
Tailwind CSS Blog
V
Visual Studio Blog
Jina AI
Jina AI
博客园 - 司徒正美
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
小众软件
小众软件
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
WordPress大学
WordPress大学
爱范儿
爱范儿
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏

Kaspersky official blog

Protecting your smart TV and set-top box from hacking ChatGPT Computer History: the risks and a safe setup How to completely uninstall apps on Mac and free up storage Hacking the Boeing 737: inside the Bus Driver attack | Kaspersky official blog Getting AI for schoolwork right: 25 helpful prompts + usage tips This Android malware steals banking credentials even without an internet connection Detection blind spots: non-standard file formats in malicious email campaigns What to do if you find someone else's bank card How to spot scam websites that your browser says are safe Malware in car infotainment systems: how infection occurs How to protect yourself from webcam spying: five simple steps ClickFix on Steam forums: how malicious PowerShell commands install a crypto miner How to tell an AI-written book from an expert's What we know about the cryptocurrency theft through Adform ads Detection blind spots: polyglot file formats in mass mailings and targeted attacks How to prevent autonomous agents from breaching corporate infrastructure CrashStealer, a new infostealer for macOS: how it works and how to stay safe ScreenConnect leveraged in cyberattacks ClickFix on macOS: how the Terminal-based attack works, and how to protect yourself Why live chat agents can read your messages before you hit “Send” Real-world attacks on corporate AI agents How Google phone number verification works, and whether you should turn it off ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts How to protect your data after a breakup Email hijacking via OAuth Prompt attacks on the Gemini AI-assistant and Google Workspace with Gemini Key vulnerabilities of Microsoft’s July 2026 Patch Tuesday Meta launched and almost instantly rolled back a feature that trained its AI image generator on Instagram user content. What’s wrong with Meta's NameTag feature and why you should be wary of it Targeted phishing attacks on manufacturing companies
Survey-based scams
2026-03-26 · via Kaspersky official blog

Spammers are constantly seeking new ways to reach the widest audience possible while dodging email filters — all to ensure their “tempting” offers land in your inbox rather than the spam folder. To pull this off, bad actors are increasingly pivoting to legitimate platforms, dreaming up sophisticated ways to weaponize them for their own gain.

We’ve previously covered scam attacks using Google Forms, where fraudulent emails were sent directly from Google’s mail servers. In those cases, links were shielded by the reputable forms.gle domain, allowing them to breeze past spam filters. Now, a similar tactic has been implemented using Yandex Surveys. Here’s a look at how this new scam works, and how you can stay safe.

Everything looks fine at first glance…

Online survey tools are fairly common these days. Marketing professionals use them to gather feedback, HR departments use them for employee engagement, and researchers use them to study target audiences. But how are scammers getting in on the action?

They create a survey, embed links to fraudulent websites within the body, and blast out emails containing the survey link to their mailing lists. Standard anti-spam filters see URLs like yandex.com/poll/… as legitimate. Recipients often have the same reaction, reasonably assuming, “It’s a link to a well-known service — what could go wrong?”

Our experts have tracked a massive spike in these emails. In January, Kaspersky Premium blocked just over 2200 of these messages; by February, that number soared to over 32 000. We’re looking at aggressive scaling here — nearly a 15-fold increase in just one month.

A poll page created on Yandex Surveys featuring a message and fraudulent link

Here’s a survey page containing a scam message and link. The visible portion features a well-known crypto exchange logo and an active link to the attackers’ site. At the bottom, you’ll notice a couple of dots — more on these later

Spammers distribute these survey links through their own channels, often hijacking website feedback forms that lack sender verification. The fact that the message originates from a legitimate network provides yet another green flag for anti-spam filters to let these emails slide right through.

A crypto scam email in English sent through a feedback form on a Greek website

A crypto scam email in English sent through a feedback form on a Greek website

The most popular themes for this type of spam currently involve crypto scams — promising users a windfall in digital currency — and links to sketchy dating sites.

How scammers exploit Yandex Surveys

To build a survey that doesn’t actually look like one, attackers take advantage of the platform’s extended survey mode.

Yandex Surveys allows users to swap out a simple question for a text block, which can include descriptions, images, or videos. This is exactly where scammers embed their pitch and the link to their phishing site. They use the built-in “Upload media” feature to add official-looking logos and other embellishments that sell the illusion.

To make sure the victim doesn’t see the “Next” button or the standard disclaimer — which warns that surveys are created by third parties and that Yandex isn’t responsible for the content — the scammers pad the space below the scam block with invisible characters. For instance, they might add dozens of lines of transparent emojis; you can’t see them, but they still take up screen real estate. Further down, past the point where most people would stop scrolling, they simply drop in punctuation marks, one per line.

Transparent emojis and punctuation marks used in the surveys

To understand how these surveys are built, we used a test survey to retrace the scammers’ steps. Transparent emojis are used to create dead space under the scam block, followed by punctuation marks further down where few users are likely to scroll

The result? The user sees nothing but the fraudulent offer and the link, while everything else is pushed off-screen. It’s the same technique we’ve seen used with Google Forms.

Beyond the benefit of using legitimate URLs, another perk for the scammers is that this method doesn’t cost them a dime. They aren’t paying the service for promotion, or using the built-in targeting tools; they simply blast the link to their own database. In this scenario, the service is essentially being used as good-reputation web page hosting.

To top it off, the scammers can jump into the “Statistics” section of the survey to track click-through rates in real-time and then export the data into a spreadsheet. This is basically a turnkey analytics suite.

Once a victim clicks the link in the survey and lands on the attackers’ website, they are greeted by a professional-looking site running a classic “prize giveaway” scheme.

How to avoid taking the bait:

  • Don’t blindly trust “reputable domain names”. Seeing yandex.com or forms.gle in the address bar is no longer a guarantee that the content is safe. Anyone can create a survey at those addresses.
  • Stay alert if you receive an unexpected email. Be especially wary if it promises a payout, a prize, or asks you to “confirm” something urgently. These are scammers’ tricks of choice.
  • Always scroll to the bottom of the page. If the content abruptly cuts off and you’re left with a wall of empty space, that should set off alarm bells. Check the footer — you’ll often find service disclaimers or other clues that prove you’re looking at a fraudulent survey.
  • Don’t click links in suspicious surveys. If you do happen to click through, never enter any personal or financial information on the resulting site.
  • Use a trusted security tool. Kaspersky Premium detects these fraudulent sites and blocks access before you have a chance to hand over your data or risk infecting your device through a zero-click vulnerability.

Finally, it’s worth noting that scammers didn’t actually hack Yandex Surveys; instead, they took a creative — albeit malicious — approach to repurposing the tool for their own ends. Since Yandex Surveys is scheduled to shut down on April 6, 2026, this specific scheme will soon hit a dead end. Still, scammers are constantly hunting for the next loophole to exploit. Your best defense remains a healthy dose of skepticism toward any unexpected email — even if the links point to a domain you know and trust.

Other tricks spammers use: