<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Store and Forward]]></title><description><![CDATA[Store and Forward explores the infrastructure, security, and strange corners of the internet. From how the internet actually works to how it breaks, we follow the packets wherever they lead.]]></description><link>https://www.safwire.net</link><image><url>https://substackcdn.com/image/fetch/$s_!Xtwk!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7656046f-64c9-4f66-8684-150ce11fb1f3_1125x1125.png</url><title>Store and Forward</title><link>https://www.safwire.net</link></image><generator>Substack</generator><lastBuildDate>Sun, 10 May 2026 12:04:21 GMT</lastBuildDate><atom:link href="https://www.safwire.net/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jim Yan]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[storeandforward@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[storeandforward@substack.com]]></itunes:email><itunes:name><![CDATA[Jim Yan]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jim Yan]]></itunes:author><googleplay:owner><![CDATA[storeandforward@substack.com]]></googleplay:owner><googleplay:email><![CDATA[storeandforward@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jim Yan]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[China’s Great Firewall May Be Poisoning the Entire .icu Top-Level Domain Infrastructure Nationwide]]></title><description><![CDATA[DNS interference may have reached the registry nameserver layer, threatening connectivity for millions of .icu domains inside China]]></description><link>https://www.safwire.net/p/gfw-icu-tld</link><guid isPermaLink="false">https://www.safwire.net/p/gfw-icu-tld</guid><dc:creator><![CDATA[Jim Yan]]></dc:creator><pubDate>Tue, 28 Apr 2026 06:43:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_Zpp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Editor&#8217;s note, April 28, 2026:</strong> Users began reporting on the evening of April 27 Beijing time that .icu domain resolution appeared to be recovering inside mainland China. SAFWire tested and confirmed the restoration. As of 16:00 UTC on April 28, 99.38% of itdog.cn testing nodes inside China were returning the correct IP addresses for the .icu authoritative nameservers, with only 0.63% of nodes still returning polluted values. The DNS pollution event now appears to have largely cleared, though the cause of the disruption and its precise duration remain unconfirmed. The original story below stands as a record of the incident.</p><div><hr></div><p><em>Users inside mainland China report that the nameservers for the .icu top-level domain are resolving to the wrong IP addresses &#8212; a disruption that, if confirmed at the registry level, could affect millions of registered names</em></p><p>Users in mainland China are reporting that .icu domains are failing to resolve correctly, with network checks suggesting the problem may reach deeper than a typical registrable domain-based censorship block &#8212; pointing to interference at the level of the .icu registry&#8217;s own authoritative nameservers.</p><p>Unlike blocking individual websites, DNS poisoning that reaches the top-level domain (TLD) authoritative nameserver layer can propagate through the TLD&#8217;s entire DNS infrastructure, affecting not just targeted users but the caching servers that serve them.</p><h3><strong>What the records show</strong></h3><p>According to IANA &#8212; the Internet Assigned Numbers Authority, which maintains the global DNS root &#8212; the .icu top-level domain is delegated through four nameservers: a.nic.icu, b.nic.icu, c.nic.icu, and d.nic.icu, which should resolve to specific IP addresses operated by CentralNic on behalf of the registry.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Zpp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Zpp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png 424w, https://substackcdn.com/image/fetch/$s_!_Zpp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png 848w, https://substackcdn.com/image/fetch/$s_!_Zpp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png 1272w, https://substackcdn.com/image/fetch/$s_!_Zpp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Zpp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png" width="1456" height="867" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:867,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:146885,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.safwire.net/i/195717320?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Zpp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png 424w, https://substackcdn.com/image/fetch/$s_!_Zpp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png 848w, https://substackcdn.com/image/fetch/$s_!_Zpp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png 1272w, https://substackcdn.com/image/fetch/$s_!_Zpp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9555a27-9acd-41fb-a523-af90dc0310d4_1705x1015.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">IP addresses of authoritative nameservers listed at IANA&#8217;s website, https://www.iana.org/domains/root/db/icu.html</figcaption></figure></div><p>Users testing from Chinese network nodes, using tools like itdog.cn, are instead receiving different IP addresses entirely &#8212; including addresses that bear no relation to the registry&#8217;s published infrastructure. </p><p>At 6:22 a.m. UTC on Tuesday, April 28, 2026, when this publication was written, testing using itdog.cn against one of the authoritative servers, b.nic.icu, by resolving the A record through local ISP DNS servers produced the following result: only 58.13% of attempts resolved to the designated IP address, 185.24.64.108, while the others were polluted.</p><p>Among the reported responses, 31.13.94.37 is a known Facebook IP range, consistent with a well-documented pattern in which China&#8217;s Great Firewall redirects queries for censored domains to random real IP addresses, a technique that makes anti-poisoning countermeasures significantly harder to deploy than when a fixed set of fake IPs is used.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nIcA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nIcA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png 424w, https://substackcdn.com/image/fetch/$s_!nIcA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png 848w, https://substackcdn.com/image/fetch/$s_!nIcA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png 1272w, https://substackcdn.com/image/fetch/$s_!nIcA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nIcA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png" width="954" height="363" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:363,&quot;width&quot;:954,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69243,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.safwire.net/i/195717320?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nIcA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png 424w, https://substackcdn.com/image/fetch/$s_!nIcA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png 848w, https://substackcdn.com/image/fetch/$s_!nIcA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png 1272w, https://substackcdn.com/image/fetch/$s_!nIcA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82f3f87-3d41-4081-ba96-5e89913e3cc2_954x363.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">At 6:22 a.m. UTC on Tuesday, April 28, 2026, when this publication was written, testing using itdog.cn against one of the authoritative servers, b.nic.icu, by resolving the A record through local ISP DNS servers produced the following result: only 58.13% of attempts resolved to the designated IP address, 185.24.64.108, while the others were polluted.</figcaption></figure></div><p>Shortdot SA, the Luxembourg-based registry operator for .icu, and CentralNic, which handles its technical infrastructure, had not responded to requests for comment.</p><h3><strong>Why TLD-level nameserver pollution is different</strong></h3><p>Most DNS censorship in China operates at the level of individual domains &#8212; a query for a particular website returns a wrong or blocked IP, while the rest of the internet continues normally. When the Great Firewall observes DNS queries to certain domains, it responds by injecting a poisoned DNS response to the requesting resolver. Due to its position in the network, this typically reaches the requesting resolver before the response from the actual DNS server.</p><p>Poisoning the registry&#8217;s own nameservers &#8212; the a.nic.icu, b.nic.icu, c.nic.icu addresses &#8212; is a different order of disruption. Those servers are not individual websites; they are the infrastructure that tells the global DNS system where to find <em>any</em> .icu domain. If those records are being intercepted or misdirected inside China, no .icu query resolved through a Chinese resolver can complete correctly, regardless of whether the individual domain was ever on a blocklist.</p><p><a href="https://dl.acm.org/doi/10.1145/2994620.2994636">Research</a> into the GFW has documented that even when poisoned responses are set aside, the DNS caches of servers inside China can themselves become poisoned &#8212; suggesting the attack is not always targeted at individual users, but at the underlying DNS infrastructure.</p><p>This is not without precedent. In 2010, a root name server operated inside China <a href="https://www.computerworld.com/article/1509544/after-dns-problem-chinese-root-server-is-shut-down.html">began returning poisoned DNS results</a> to global users, preventing users in Chile and the United States from accessing sites including Facebook. The server was shut down to stop the poisoning. In 2014, two-thirds of China&#8217;s DNS infrastructure began resolving unrelated domains to a single US-based IP address, causing a widespread internet outage inside China.</p><h3><strong>The .icu domain and China&#8217;s censorship history</strong></h3><p>The .icu extension is not simply a generic low-cost domain with an outsized presence in China. It carries specific political history.</p><p>The <a href="https://github.com/996icu/996.ICU">996.ICU project</a> was initiated by an anonymous user on GitHub on 26 March 2019. The person complained that the &#8220;996&#8221; work schedule &#8212; 9am to 9pm, six days a week &#8212; recently advocated by some prominent entrepreneurs in the Chinese tech industry risked sending employees straight to the intensive care unit. The name of the domain was the protest itself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nL5M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nL5M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png 424w, https://substackcdn.com/image/fetch/$s_!nL5M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png 848w, https://substackcdn.com/image/fetch/$s_!nL5M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png 1272w, https://substackcdn.com/image/fetch/$s_!nL5M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nL5M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png" width="1297" height="912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:912,&quot;width&quot;:1297,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:89620,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.safwire.net/i/195717320?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nL5M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png 424w, https://substackcdn.com/image/fetch/$s_!nL5M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png 848w, https://substackcdn.com/image/fetch/$s_!nL5M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png 1272w, https://substackcdn.com/image/fetch/$s_!nL5M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a7d686-65f2-4718-812a-4a19eec991c8_1297x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">a screenshot of the 996.icu website</figcaption></figure></div><p>The project spread fast. By 30 April, it had received 240,000 stars on GitHub. Chinese domestic browsers &#8212; including Tencent&#8217;s QQ browser, Alibaba&#8217;s UC browser, and Qihoo&#8217;s 360 browser &#8212; restricted access to the 996.ICU repository, saying the website contained illegal or malicious information.</p><p>In response, workers at Microsoft and GitHub launched a public petition calling on the company to keep the 996.ICU repository uncensored and available to everyone, citing solidarity with Chinese tech workers.</p><p>The .icu extension became a template. 611Study.ICU &#8212; standing for &#8220;study from 6 AM to 11 PM, and end up in ICU&#8221; &#8212; was launched as a crowdsourced documentation project targeting the enforced schedules of Chinese high school students, with countless students suffering both physically and mentally from the schedule. The project&#8217;s revelations that over 2,000 schools had illegally forced students back early for extended study hours triggered public outrage, prompting authorities in at least one Chinese city to issue directives banning early returns.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y_2D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y_2D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png 424w, https://substackcdn.com/image/fetch/$s_!y_2D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png 848w, https://substackcdn.com/image/fetch/$s_!y_2D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png 1272w, https://substackcdn.com/image/fetch/$s_!y_2D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y_2D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png" width="1456" height="1037" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1037,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:448455,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.safwire.net/i/195717320?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y_2D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png 424w, https://substackcdn.com/image/fetch/$s_!y_2D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png 848w, https://substackcdn.com/image/fetch/$s_!y_2D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png 1272w, https://substackcdn.com/image/fetch/$s_!y_2D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3459b7b-9c4a-42c6-97ed-715117263613_1689x1203.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">a screenshot of the 996.icu website</figcaption></figure></div><p>The .icu extension is also deeply embedded in the Chinese internet commercially. According to domainnamestat.com, the .icu zone has 1,107,698 registered domains to date.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QnWc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QnWc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png 424w, https://substackcdn.com/image/fetch/$s_!QnWc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png 848w, https://substackcdn.com/image/fetch/$s_!QnWc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png 1272w, https://substackcdn.com/image/fetch/$s_!QnWc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QnWc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png" width="1218" height="887" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:887,&quot;width&quot;:1218,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91103,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.safwire.net/i/195717320?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QnWc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png 424w, https://substackcdn.com/image/fetch/$s_!QnWc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png 848w, https://substackcdn.com/image/fetch/$s_!QnWc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png 1272w, https://substackcdn.com/image/fetch/$s_!QnWc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc556d5d4-c016-47ab-ab93-e66160eabc51_1218x887.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">According to domainnamestat.com, the .icu zone has 1,107,698 registered domains to date.</figcaption></figure></div><h3><strong>What remains unconfirmed</strong></h3><p>The reports are circulating on Chinese-language technical forums, with testing tool results as the primary evidence. The claims have not been verified by independent measurement platforms such as OONI or Censored Planet, and no statement has come from Shortdot, CentralNic, or ICANN. It is also possible that what some users are observing reflects localized resolver-level pollution rather than interference at the registry nameserver tier itself &#8212; a distinction that matters for the scope of any disruption.</p><p>Researchers and domain operators with access to Chinese network nodes can test the behavior directly by querying a.nic.icu from within mainland China and comparing results against the IANA-published delegation record.</p><div><hr></div><p><em>Shortdot SA and CentralNic were contacted for comment. This story will be updated as additional information becomes available.</em></p>]]></content:encoded></item><item><title><![CDATA[Who Authorized .edu.eu? Nobody Did.]]></title><description><![CDATA[How a private company created an unofficial "European educational domain" that became a haven for degree mills and fraud]]></description><link>https://www.safwire.net/p/who-authorized-edueu-nobody-did</link><guid isPermaLink="false">https://www.safwire.net/p/who-authorized-edueu-nobody-did</guid><dc:creator><![CDATA[Jim Yan]]></dc:creator><pubDate>Wed, 02 Jul 2025 04:53:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xqUR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A simple <a href="https://www.google.com/search?q=site:edu.eu">Google search</a> using <code>site:edu.eu</code> reveals numerous &#8220;educational&#8221; websites using the &#8220;.edu.eu&#8221; suffix. This domain extension, which appears to be official, frequently conveys the impression that educational institutions are EU-certified; however, the truth might be considerably more intricate. My basic investigation indicates that this so-called &#8220;European educational domain&#8221; may be plagued by substantial issues, which raises doubts regarding its credibility.</p><h2><strong>The Hollow &#8220;Official&#8221; Status</strong></h2><p>&#8220;.edu.eu&#8221; is not an official educational domain recognized by the European Union or any member state government. Simply put, it&#8217;s claimed to be a commercial project <a href="https://web.archive.org/web/20250702054817/https://register.edu.eu/index.php/announcements/17/Press-release-Building-trust-and-preventing-international-educationscam.html?language=turkish">launched in 2018</a> by a private company called Euro Education Domains Registry Limited (EEDRL).</p><p>The company&#8217;s claimed business model is straightforward: they registered the &#8220;edu.eu&#8221; domain and now sell subdomains to educational institutions, such as &#8220;school.edu.eu.&#8221; This means all &#8220;.edu.eu&#8221; websites are actually third-level domains, completely controlled by this private enterprise and having no connection to EURid, the official EU domain registry.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xqUR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xqUR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png 424w, https://substackcdn.com/image/fetch/$s_!xqUR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png 848w, https://substackcdn.com/image/fetch/$s_!xqUR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png 1272w, https://substackcdn.com/image/fetch/$s_!xqUR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xqUR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png" width="1456" height="905" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:905,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1673116,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://storeandforward.substack.com/i/180297794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xqUR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png 424w, https://substackcdn.com/image/fetch/$s_!xqUR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png 848w, https://substackcdn.com/image/fetch/$s_!xqUR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png 1272w, https://substackcdn.com/image/fetch/$s_!xqUR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6520ea7b-195b-4526-8fcd-4f00c303195b_1728x1074.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Homepage of Register.edu[.]eu</figcaption></figure></div><p>The European Commission has never authorized any organization to use &#8220;.edu.eu&#8221; as an official educational identifier. While EEDRL claims in its <a href="https://web.archive.org/web/20210306075942/https://register.edu.eu/eligibility-criteria">policy documentation</a> to review applicants&#8217; educational credentials, this review process is purely commercial and carries no legal authority.</p><h2><strong>The Telling Absence of Legitimate Institutions</strong></h2><p>A revealing phenomenon is that Europe&#8217;s most prestigious public universities&#8212;Oxford, Cambridge, Sorbonne, Heidelberg, and others&#8212;do not use &#8220;.edu.eu&#8221; domains. These institutions continue to use their respective national domain suffixes like &#8220;.ac.uk,&#8221; &#8220;.fr,&#8221; &#8220;.de,&#8221; and others.</p><p>The majority of organizations that use &#8220;.edu.eu&#8221; are obscure private schools or self-proclaimed &#8220;international institutes&#8221; and training providers. The European Institute of Leadership and Management in Dublin (eilm.edu.eu) and the International Business Academy of Switzerland (ibas.edu.eu) are two examples. These institutions frequently advertise impressive-sounding accreditations; however, upon closer examination, it becomes apparent that these credentials are typically obtained from private organizations or industry associations rather than national education departments.</p><p>This phenomenon speaks volumes: if &#8220;.edu.eu&#8221; were truly an authoritative educational identifier, why wouldn&#8217;t Europe&#8217;s finest universities use it? The answer is simple&#8212;it lacks such authority entirely.</p><h2><strong>A Breeding Ground for Educational Fraud</strong></h2><p>The fact that &#8220;.edu.eu&#8221; domains have become a haven for educational scams is even more concerning. In multiple instances, fraudsters have used or exploited this domain suffix that appears to be &#8220;official&#8221; in order to deceive students.</p><h3><strong>The Italian &#8220;University&#8221; Scam</strong></h3><p>A <a href="https://www.reddit.com/r/Scams/comments/1cmf0wc/i_paid_for_tuition_fees_to_a_private_university/">Reddit user report</a> (<a href="https://web.archive.org/web/20250317022940/https://www.reddit.com/r/Scams/comments/1cmf0wc/i_paid_for_tuition_fees_to_a_private_university/">archive</a>) exposed a typical fraud: a student paid full tuition to a supposed Italian private university hosted on &#8220;iep.edu.eu,&#8221; only to have the program suddenly canceled with the &#8220;university&#8221; disappearing entirely and refusing refunds. Users analyzing the site discovered it was filled with generic templates and stock photos, with no actual campus facilities.</p><h3><strong>The Scandinavian Degree Mill Network</strong></h3><p>More serious is a long-running degree-selling operation. According to <a href="https://www.linkedin.com/posts/behzadlimooie_mba-dba-doctorate-activity-7285378681751883777-5VH3">scholar Dr. Ben Limooie&#8217;s LinkedIn disclosure</a>, an individual named &#8220;Martin Nielsen&#8221; controls multiple &#8220;.edu.eu&#8221; websites, including &#8220;ibss.edu.eu&#8221; and &#8220;ibas.edu.eu,&#8221; specifically to sell fraudulent MBA and DBA degrees. These entities even established fake accreditation bodies to boost credibility, with victims paying thousands of dollars for worthless &#8220;degrees.&#8221;</p><h3><strong>Misleading Accreditation Claims</strong></h3><p>Another troubling pattern involves institutions using impressive-sounding but ultimately meaningless accreditation lists. The European Institute of Management and Technology (eimt.edu.eu) exemplifies this practice. <a href="https://www.degreeforum.net/mybb/Thread-EIMT-Doctorate-Program-reputation?page=2">Forum discussions</a> (<a href="https://web.archive.org/web/20250326171617/https://www.degreeforum.net/mybb/Thread-EIMT-Doctorate-Program-reputation?page=2">archive</a>) reveal how these institutions exploit public confusion about accreditation.</p><p>EIMT lists numerous credentials including EURASHE, ACBSP candidate status, OTHM, QAHE, DRPF, and others. They claim membership in EAI Malta, which itself holds certain recognitions. However, as education experts point out, these are largely memberships in private organizations rather than official government accreditation. As one forum user succinctly explained: &#8220;It&#8217;s like, I&#8217;ve got a Costco membership, now I&#8217;m accredited by Costco, membership doesn&#8217;t equal accreditation, ever...&#8221;</p><p>The fundamental issue is that these institutions &#8220;aren&#8217;t recognized in the country they are in&#8221; and are &#8220;going through loopholes of other country recognition&#8221; while padding their credentials with &#8220;false accreditation fluff.&#8221; This strategy deliberately confuses prospective students who may not understand the difference between meaningful government recognition and private organizational memberships.</p><p>These cases demonstrate that EEDRL&#8217;s claimed &#8220;rigorous vetting&#8221; is essentially meaningless. Fraudsters can easily create &#8220;.edu.eu&#8221; subdomains and use their &#8220;educational&#8221; veneer to implement scams.</p><h2><strong>Suspicious Infrastructure Patterns</strong></h2><p>Technical analysis of &#8220;.edu.eu&#8221; domains reveals concerning patterns that further undermine their credibility. A small dataset examination shows multiple institutions using Chinese DNS infrastructure (DNSPod/Tencent Cloud), which raises questions about their claimed locations and operations.</p><p>For example, institutions with names suggesting diverse geographic presence&#8212;Southern Technical University Colorado (stu.edu.eu), The Asia Pacific School of Business (apsb.edu.eu), and Eurasian Higher Education and Social Studies (ehess.edu.eu)&#8212;all use identical Chinese DNS servers and share the same IP address (<code>203.86.233[.]139</code>). This suggests these &#8220;separate&#8221; institutions may actually be operated by the same entity.</p><p>Even more telling is institutions like The Asia Pacific School of Business, which <a href="https://web.archive.org/web/20240606140406/https://www.apsb.edu.eu/">boasts</a> about having &#8220;globally recognized domain name systems&#8221; across multiple extensions (apsb.edu.eu, apsb.edu.vn, apsb.edu.ky, apsb.ac.nz, apsb.ac.cn), seemingly focusing more on domain collection than actual educational activities. However, this claim is misleading&#8212;none of these domains require educational accreditation to register. Unlike registry-restricted domains like the U.S. &#8220;.edu&#8221; or U.K. &#8220;.ac.uk,&#8221; these subdomains can be purchased by anyone willing to pay the registration fee.</p><p>WHOIS data reveals further deception: the <code>apsb.ac.cn</code> domain listed on APSB&#8217;s website is registered to &#8220;&#28023;&#24402;&#25945;&#32946;&#36164;&#35759;&#65288;&#28145;&#22323;&#65289;&#26377;&#38480;&#20844;&#21496;&#8221; (Returnee Education Information Shenzhen Co., Ltd.), a Chinese company, not an international educational institution. The registrant contact email &#8220;ceo@microbolg.com&#8221; contains a typo. This evidence suggests APSB may be a Chinese company targeting overseas education markets rather than the international academic institution it presents itself to be.</p><p>Additional patterns emerge across the .edu.eu space: EURACA (euraca.edu.eu), European University (european.edu.eu), and Arab University (alarabia.edu.eu) all use the same webhostbox.net hosting service, with some sharing identical IP addresses (<code>162.241.85[.]111</code>). Multiple &#8220;universities&#8221; including Avicenna University (avicenna.edu.eu), College.edu.eu, and European University College (euc.edu.eu) share the exact same IP address (<code>52.28.46[.]27</code>) and nameserver configuration.</p><h2><strong>Subdomain Analysis</strong></h2><p>The investigation on subdomains reveals a pattern of fraudulent educational institutions using the edu.eu domain. Common red flags include: use of non-existing, virtual or residential addresses as official locations, misleading claims about accreditation and partnerships, hosting infrastructure shared across supposedly separate institutions, misalignment between registered business information and website claims, news media exposure and reports, user reports of scams and degree mills, and attempts to mimic legitimate universities.</p><p>All of these institutions appear to target international students with promises of European credentials while lacking proper accreditation or facilities.</p><p><strong>Registry:</strong></p><ul><li><p><code>register.edu[.]eu</code> - The domain registry itself (EURO EDUCATION DOMAINS REGISTRY LIMITED) shows highly suspicious characteristics. Registry operated by EURO EDUCATION DOMAINS REGISTRY LIMITED. Virtual Dublin address. Email from mail.ru servers, fails authentication. Irish company using Russian email hosting.</p></li></ul><p><strong>Active Fraudulent Institutions and Degree Mills:</strong></p><ul><li><p><code>stu.edu[.]eu</code> - Southern Technical University Colorado. Residential address in Franktown CO. Same IP (203.86.233.139) as apsb and ehess domains. Misappropriates legitimate Iraqi university name.</p></li><li><p><code>eibm.edu[.]eu</code> - European Institute of Leadership and Management. <a href="https://www.reddit.com/r/PhD/comments/18ssh8i/anyone_at_eimt_switzerland/">Flagged on Reddit</a> as &#8220;scam institution run by Indians.&#8221;</p></li><li><p><code>eam.edu[.]eu</code> - European Academy of Medical Sciences. UK registration mismatch. Residential/HVAC contractor addresses. Invalid US nonprofit number format.</p></li><li><p><code>american.edu[.]eu</code> - University of America in Paris. Residential building address. Member of suspicious global-edu.eu network. Name confusion with legitimate American University of Paris.</p></li><li><p><code>ieu.edu[.]eu</code> - International European University Kiev. <a href="https://theshiftnews.com/2024/12/03/education-authorities-ignore-reports-of-scam-university-in-gzira/">Major news coverage</a>. Multiple Reddit warnings. Conditional accreditation only. Poland campus investigated.</p></li><li><p><code>knu.edu[.]eu</code> - Fake &#8220;Open University of Taras Shevchenko.&#8221; <a href="https://www.degreeforum.net/mybb/Thread-Open-University-of-Taras-Shevchenko-National-University-of-Kyiv">Flagged on degreeforum</a> as scam. Misappropriates legitimate KNU address. No affiliation with real university.</p></li><li><p><code>eilm.edu[.]eu</code> - European Institute of Leadership &amp; Management. Residential Dublin address. No Irish company registration. <a href="https://www.trustpilot.com/review/eilm.edu.eu?stars=1&amp;stars=2">Negative Trustpilot reviews</a> citing AI-generated content.</p></li><li><p><code>alzette.edu[.]eu</code> - Alzette University. Misappropriates Crescent College and Mbway Lyon addresses. Multiple fake social profiles.</p></li><li><p><code>euu.edu[.]eu</code> - European Union University. <a href="https://facts.ibcindia.co.in/index.php/news/12-facts-blog/78-degree-mill-in-world">Listed in degree mill databases</a>. Wikipedia unaccredited institutions list.</p></li><li><p><code>eimt.edu[.]eu</code> - European Institute of Management And Technology. <a href="https://www.degreeforum.net/mybb/Thread-EIMT-Doctorate-Program-reputation?page=2">Questioned on degreeforum</a>. Invalid accreditation claims. Swiss registration but suspicious practices.</p></li><li><p><code>egs.edu[.]eu</code> - European Global School. <a href="https://www.andrew-drummond.com/2024/02/14/uk-immigration-watchdog-linked-to-worldwide-scams/">UK media coverage linking to scams</a>. Misappropriates Istanbul USM address. False accreditation claims.</p></li><li><p><code>euraca.edu[.]eu</code> - European Academy for Sustainable Development. Same IP (162.241.85.111) as european and alarabia domains. Misappropriated VAT number.</p></li><li><p><code>european.edu[.]eu</code> - European University. Misappropriates London Strength and Conditioning address. Same hosting as euraca/alarabia.</p></li><li><p><code>aiu.edu[.]eu</code> - Amsterdam International College. <a href="https://www.reddit.com/r/eindhoven/comments/13e0wtw/amsterdam_international_college_legit/">Reddit users visited address</a> - building manager denied existence. False campus claims.</p></li><li><p><code>eim.edu[.]eu</code> - European Institute of Management. Same Reddit reports as eimt. &#8220;Scam institution run by Indians.&#8221;</p></li><li><p><code>douglas.edu[.]eu</code> - Douglas Business School. Warehouse address. <a href="https://www.facebook.com/degree.sg/reviews">Facebook user reports</a> &#8220;scamming everywhere.&#8221; Targets Chinese students.</p></li><li><p><code>aic.edu[.]eu</code> - Amsterdam International College (alternative domain). WordPress errors. Same reports as aiu domain. Fake LinkedIn credentials.</p></li><li><p><code>hgu.edu[.]eu</code> - Harold Gillies University. Florida registration document found. Login-only access. Minimal verification possible.</p></li><li><p><code>aue.edu[.]eu</code> - American University of Europe. Misappropriates AUE-FON University New York address.</p></li><li><p><code>wpunu.edu[.]eu</code> - World Peace of United Nations University. Account suspended. <a href="https://indiankanoon.org/doc/141500426/">Indian court document</a> confirms not UGC recognized.</p></li><li><p><code>iis.edu[.]eu</code> - Institute For International Studies. Convenience store address in Brooklyn. Registry&#8217;s press release highlights this domain.</p></li><li><p><code>wsu.edu[.]eu</code> - Western State University. Claims Curacao licensing but not in NL registers. WhatsApp-only contact.</p></li><li><p><code>wilmingtonmu.edu[.]eu</code> - Wilmington Metropolitan University. Mall/Regus address. Not found in UK QUALIFI database despite claims.</p></li><li><p><code>aaguc.edu[.]eu</code> - AAGUC-APSB and GAFM United College. New Zealand address but no company registration found. AI/stock images only.</p></li><li><p><code>apsb.edu[.]eu</code> - Asia Pacific School of Business. Same IP (203.86.233.139) as stu/ehess. Chinese company owns related domains. Multiple TLD collection focus.</p></li><li><p><code>ehess.edu[.]eu</code> - Eurasian Higher Education And Social Studies. Same infrastructure cluster as stu/apsb. No physical address.</p></li><li><p><code>huparis.edu[.]eu</code> - Horizons University. <a href="https://www.reddit.com/r/paris/comments/szjorm/has_anyone_heard_of_horizons_university/">Multiple Reddit flags</a>. Misappropriates Academy Geopolitics De Paris address.</p></li><li><p><code>psychologicalsafetyacademy.edu[.]eu</code> - Psychological Safety Academy. No contact info. Stock images only. Limited content.</p></li><li><p><code>ibas.edu[.]eu</code> - International Business Academy of Switzerland. <a href="https://www.linkedin.com/posts/behzadlimooie_mba-dba-doctorate-activity-7285378681751883777-5VH3">LinkedIn professional identifies</a> as controlled by &#8220;Martin Nielsen&#8221; for fake degree sales.</p></li><li><p><code>cmu.edu[.]eu</code> - California Metropolitan University. Misappropriates legitimate CMU name. Non-existent San Francisco address.</p></li><li><p><code>ibss.edu[.]eu</code> - International Business School of Scandinavia. Same LinkedIn disclosure as ibas - controlled by &#8220;Martin Nielsen.&#8221; <a href="https://www.andrew-drummond.news/education-scammers-worldwide-were-approved-by-uk-govermment-watchdog/">Media coverage of scam network</a>.</p></li><li><p><code>rcu.edu[.]eu</code> - Reading Century University. <a href="https://www.martialtalk.com/threads/reading-century-university.139897/">Technical analysis on forums</a> shows Chinese infrastructure. Fake California location claims.</p></li><li><p><code>eae.edu[.]eu</code> - European Academy of Engineering. Antique store address in Gothenburg. Multiple Chinese academic connections found.</p></li><li><p><code>ceu.edu[.]eu</code> - Colorado Economics University. Building directory doesn&#8217;t list university. Chinese media coverage with misleading content.</p></li><li><p><code>avicenna.edu[.]eu</code> - Avicenna University. Same IP (52.28.46.27) as college/euc domains. Redirects to .hu domain.</p></li><li><p><code>euroamerican.edu[.]eu</code> - EuroAmerican Education. No Swiss company registration found. Stock content only. Associated with eimt findings.</p></li><li><p><code>winncollege.edu[.]eu</code> - Winn College. California address not in building directory.</p></li><li><p><code>iep.edu[.]eu</code> - IEP Italy International Education Partners. <a href="https://www.reddit.com/r/Scams/comments/1cmf0wc/i_paid_for_tuition_fees_to_a_private_university/">Reddit user paid tuition</a>, program canceled, no refunds. SSL expired. Rome address not in directory.</p></li><li><p><code>amu.edu[.]eu</code> - American Management University. <a href="https://www.usatoday.com/story/news/investigations/2024/05/09/zombie-colleges-taking-applications/73546247007/">USA Today &#8220;zombie colleges&#8221; investigation</a>. <a href="https://www.andrew-drummond.news/education-scammers-worldwide-were-approved-by-uk-govermment-watchdog/">Multiple scam network coverage</a>.</p></li></ul><h2><strong>An Elegantly Packaged Deception</strong></h2><p>Weighing all evidence, the true nature of &#8220;.edu.eu&#8221; domains is clear: this is a commercial project operated by a private company with neither official authority nor effective oversight.</p><p>Even more detrimentally, it has either been designed for educational fraud and degree mills or has become one.</p><p>For students, seeing a &#8220;.edu.eu&#8221; domain should raise red flags rather than provide reassurance. This suffix cannot validate any educational credentials and may actually serve as a warning signal. When choosing educational institutions, focus on:</p><ul><li><p>Whether the institution has formal accreditation from its country&#8217;s education department</p></li><li><p>Whether degrees are internationally recognized</p></li><li><p>Whether there&#8217;s a physical campus and complete educational infrastructure</p></li><li><p>Whether there&#8217;s verifiable faculty and alumni networks</p></li></ul><p>The existence of &#8220;.edu.eu&#8221; domains serves as an illustration of a more extensive issue: commercial packaging frequently takes the place of authoritative identifiers when legitimate channels are unable to provide them. However, for students, appealing packaging can never serve as a substitute for genuine educational value.</p><h2><strong>References</strong></h2><p>This article is based on the following public sources:</p><ul><li><p><a href="https://web.archive.org/web/*/https://register.edu.eu/index.php/announcements/17/Press-release-Building-trust-and-preventing-international-educationscam.html">EEDRL&#8217;s official announcement about &#8220;.edu.eu&#8221; launch</a></p></li><li><p><a href="https://web.archive.org/web/*/https://register.edu.eu/">Register.edu.eu official website policy documentation</a></p></li><li><p><a href="https://web.archive.org/web/*/https://register.edu.eu/eligibility-criteria">Domain application eligibility requirements</a></p></li><li><p><a href="https://www.reddit.com/r/Scams/comments/1cmf0wc/i_paid_for_tuition_fees_to_a_private_university/">Reddit scam case discussion</a></p></li><li><p><a href="https://www.linkedin.com/posts/behzadlimooie_mba-dba-doctorate-activity-7285378681751883777-5VH3">LinkedIn degree mill exposure post</a></p></li><li><p><a href="https://www.trustpilot.com/review/eilm.edu.eu">EILM institutional review page</a></p></li><li><p><a href="https://www.facebook.com/story.php?story_fbid=932159359027&amp;id=100067958139746">Fake university monitoring organization report</a></p></li><li><p><a href="https://www.degreeforum.net/mybb/Thread-EIMT-Doctorate-Program-reputation?page=2">Degree forum related discussion</a></p></li></ul><h3><strong>Dataset</strong></h3><p>A list of 224 <code>edu.eu</code> subdomains detected through OSINT methods. Approximately 61 of them host live websites:</p><ul><li><p><a href="https://gist.github.com/jimyy23/c9b4cfcef40a6302ba84ef5b2f20aca2">List of 224 edu.eu subdomains</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[When Charity Domains Run Casinos: The .NGO/.ONG TLD's Gambling Problem]]></title><description><![CDATA[One in nineteen .NGO/.ONG domains may be associated with gambling operations&#8212;undermining the credibility of legitimate nonprofits]]></description><link>https://www.safwire.net/p/when-charity-domains-run-casinos</link><guid isPermaLink="false">https://www.safwire.net/p/when-charity-domains-run-casinos</guid><dc:creator><![CDATA[Jim Yan]]></dc:creator><pubDate>Sat, 21 Jun 2025 04:47:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!c60C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When the <a href="https://icannwiki.org/.ngo">.ngo and .ong top-level domains</a> were launched in 2015, they represented something groundbreaking in the digital nonprofit world. Unlike the wide-open .org domain that anyone could register, these new domains required validation of an organization&#8217;s non-governmental status. The idea was simple but powerful: make a safe online space where donors could be sure they were giving to real causes and not fake charities that were pretending to be real ones.</p><p>Nearly a decade later, my recent analysis of domain registration data suggests this trust may be eroding in ways that would surprise even the most cynical observers. After examining zone files from ICANN&#8217;s Centralized Zone Data Service (CZDS) for both .ngo and .ong domains, I discovered that over 5% of all registered domains in these supposedly protected spaces appear to be associated with online gambling operations.</p><p>The numbers: <strong>out of 9,193 total .ngo/.ong domains currently registered, my analysis identified 471 domains that likely involve online gambling activities.</strong> That&#8217;s roughly one in every 19 domains &#8211; a proportion that raises serious questions about the effectiveness of current validation processes.</p><p>It&#8217;s important to note that this analysis represents a preliminary examination rather than a comprehensive, peer-reviewed study. The findings presented here are based on keyword identification and basic website verification to rule out false positives, which while suggestive, may not capture the full complexity of domain usage patterns. This preliminary look is intended to highlight potential concerns and prompt further investigation rather than serve as definitive proof of systematic abuse. More rigorous analysis would require deeper verification methods, manual review of borderline cases, and consultation with domain registry operators.</p><h2><strong>The Analysis</strong></h2><p>I analyzed the complete zone files for both .ngo and .ong domains, looking for telltale signs of gambling operations.</p><p>The simple lookup started with keyword matching to find domains that looked suspicious. Then, Python scripts were used to check live websites to get rid of false positives. The keywords were numbers and words that are often used in the names of online gambling sites, such as &#8220;88,&#8221; &#8220;68,&#8221; &#8220;33,&#8221; &#8220;bet,&#8221; &#8220;win,&#8221; &#8220;vip,&#8221; &#8220;casino,&#8221; and &#8220;poker.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c60C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c60C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png 424w, https://substackcdn.com/image/fetch/$s_!c60C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png 848w, https://substackcdn.com/image/fetch/$s_!c60C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png 1272w, https://substackcdn.com/image/fetch/$s_!c60C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c60C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png" width="1213" height="476" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:476,&quot;width&quot;:1213,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image description&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image description" title="Image description" srcset="https://substackcdn.com/image/fetch/$s_!c60C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png 424w, https://substackcdn.com/image/fetch/$s_!c60C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png 848w, https://substackcdn.com/image/fetch/$s_!c60C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png 1272w, https://substackcdn.com/image/fetch/$s_!c60C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd54803-2aa1-4187-8166-121bd4a3b8be_1213x476.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While this methodology isn&#8217;t definitive (some legitimate organizations might use these terms in non-gambling contexts), the subsequent verification of live websites strongly suggests the majority of flagged domains are indeed operating gambling services.</p><p>Examples of suspect domains include:</p><ul><li><p>188bet[.]ngo and 188bet[.]ong</p></li><li><p>bet365[.]ngo, bet365[.]ong, 888poker[.]ong</p></li><li><p>fun88[.]ngo, win88[.]ong, lucky88[.]ngo</p></li><li><p>gamebaidoithuong[.]ngo - Vietnamese gambling terminology</p></li><li><p>1xbet[.]ngo, m88[.]ong, w88[.]ngo - popular international betting brands</p></li><li><p>vip79[.]ngo, 333win[.]ong, 98win[.]ngo - VIP and winning-themed sites</p></li></ul><p>The full list of suspect domains reveals a concerning pattern of what appears to be systematic abuse of domains meant to serve the public good.</p><h2><strong>How We Got Here: The Erosion of Validation</strong></h2><p>Understanding how gambling operations infiltrated spaces reserved for nonprofits requires looking at the evolution of .ngo/.ong registration policies. When these domains first launched, they featured rigorous pre-validation requirements. Organizations had to provide extensive documentation proving their NGO status, and domains were immediately placed on server hold while the <a href="https://pir.org/">Public Interest Registry (PIR)</a> directly verified legitimacy. The process required meeting seven specific criteria, including acting in the public interest, being non-profit-focused, and having limited government influence.</p><p>The original system also included <a href="https://www.viget.com/work/ongood/">OnGood</a>, a comprehensive community platform that served as a global directory of validated NGOs. This platform allowed organizations to showcase their missions, connect with supporters, and even collect donations &#8211; all within a verified ecosystem that provided additional legitimacy.</p><p>However, the landscape changed dramatically around 2020 when PIR implemented significant policy changes to &#8220;simplify&#8221; the registration process. The new system replaced pre-validation with self-certification, allowing domains to go live immediately upon registration. Instead of submitting documentation, registrants now only need to check a box stating they understand and agree to the policies and certify their organization meets eligibility requirements.</p><p>This shift from proactive verification to reactive auditing created the vulnerability that gambling operations appear to have exploited. While PIR retains the right to conduct audits and cancel domains for policy violations, the current system essentially operates on an honor system &#8211; asking bad actors to police themselves.</p><h2><strong>What This Means for the Future</strong></h2><p>Gambling sites getting into .ngo and .ong domains is more than just a technical policy failure; it&#8217;s a breach of trust that these domains were meant to build. People who donate to organizations with .ngo domains should reasonably expect them to be real nonprofit organizations. Not only do gambling operations in this space trick users, but they could also hurt trust in the whole nonprofit digital ecosystem.</p><p>The timing of these changes also raises questions about priorities. The elimination of the <a href="https://www.nonprofitpro.com/article/new-ngo-ong-domains-now-available-ngos-worldwide/">OnGood platform</a> and the relaxation of validation requirements in 2020 coincided with PIR&#8217;s efforts to streamline operations and reduce costs. While operational efficiency is important, the cost of reduced trust and potential fraud may far exceed any savings from simplified processes.</p><h2><strong>What This Means for Donors and NGOs</strong></h2><p>For donors and supporters, this analysis suggests treating .ngo/.ong domains as a positive indicator rather than a definitive guarantee of legitimacy, particularly for domains registered after 2020. The validation that once made these domains trustworthy has been significantly weakened, requiring the same due diligence you&#8217;d apply to any other domain.</p><p>For legitimate NGOs using these domains, the situation creates an unfortunate association problem. Organizations that chose .ngo/.ong domains specifically for their credibility benefits now find themselves sharing digital space with gambling operations. This may prompt some organizations to reconsider their domain strategy or advocate for stronger validation requirements.</p><p>The bigger lesson here is that it&#8217;s hard to keep trust in digital spaces, not just with domain names. The .ngo/.ong experiment shows how quickly trust can fade when verification systems are weakened, even with good intentions. As we increasingly rely on digital indicators of legitimacy, the systems that create and maintain these indicators become critical infrastructure for trust in the digital age.</p><p>Moving forward, the question isn&#8217;t just whether PIR will address this specific abuse, but whether the nonprofit sector will demand the validation standards necessary to preserve the trust these domains were meant to create. The alternative &#8211; a digital landscape where legitimate charities and gambling operations are indistinguishable by their domain names &#8211; serves no one except those seeking to exploit the goodwill of donors.</p><p><strong><a href="https://gist.github.com/jimyy23/0496848c8a64bae0b972e43c17b7f491">Complete list of suspect domains identified in this analysis - 471 domains</a></strong></p><p><em>Note: This analysis represents a snapshot in time based on publicly available zone file data. Domain usage can change, and some domains may have legitimate explanations for keyword matches. The findings should be considered indicative rather than definitive proof of gambling operations.</em></p>]]></content:encoded></item><item><title><![CDATA[The GoogleAPIs.com Typosquatting Threat]]></title><description><![CDATA[How a single mistyped character in googleapis.com may compromise healthcare systems and expose sensitive data]]></description><link>https://www.safwire.net/p/the-googleapiscom-typosquatting-threat</link><guid isPermaLink="false">https://www.safwire.net/p/the-googleapiscom-typosquatting-threat</guid><dc:creator><![CDATA[Jim Yan]]></dc:creator><pubDate>Sat, 08 Mar 2025 05:15:00 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="4368" height="2912" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2912,&quot;width&quot;:4368,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;black typewriter&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="black typewriter" title="black typewriter" srcset="https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1556968262-9014ddf533c4?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyMnx8dHlwb3xlbnwwfHx8fDE3NjQ0NDMxNDR8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@camstejim">camilo jimenez</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><h2><strong>What is Typosquatting?</strong></h2><p><a href="https://oit.utk.edu/security/learning-library/article-archive/typosquatting/">Typosquatting</a> is a form of cybersquatting that targets users who incorrectly type a website address into their browser. This <a href="https://www.utsa.edu/techsolutions/Cyber-Awareness/Typosquatting.html">social engineering technique</a> relies on the predictable mistakes people make when manually entering URLs.</p><p>Common typosquatting methods include:</p><ul><li><p>Simple keyboard typos (pressing adjacent keys)</p></li><li><p>Character omission (forgetting a letter)</p></li><li><p>Character transposition (swapping letters)</p></li><li><p>Character replacement (using similar-looking characters)</p></li><li><p>Domain hyphenation (adding hyphens between words)</p></li><li><p>TLD variation (using <code>.co</code>, <code>.cm</code> instead of <code>.com</code>)</p></li></ul><p>According to a 2015 research, <a href="https://www.ndss-symposium.org/wp-content/uploads/2017/09/01_3_1.pdf">over one-fifth of all .com domain registrations are now typo domains</a>, with the number growing each year. This isn&#8217;t just annoying &#8211; it&#8217;s potentially devastating for both individuals and organizations.</p><h2><strong>Google&#8217;s </strong><code>googleapis.com</code><strong> Domain</strong></h2><p>Before getting into the findings, let&#8217;s understand what makes <code>googleapis.com</code> particularly valuable to attackers.</p><p>The <code>googleapis.com</code> domain serves as one of the primary endpoints that developers integrate into their applications. This includes high-volume services like:</p><ul><li><p><a href="https://developers.google.com/fonts/docs/getting_started">Google Fonts API</a></p></li><li><p><a href="https://cloud.google.com/storage/docs/json_api">Cloud Storage</a> (e.g. Google&#8217;s version of S3)</p></li></ul><p>When developers make API calls to these services, they typically use endpoints like </p><p>https://domains.googleapis.com</p><p> or other service-specific subdomains. The domain handles billions of API requests daily from applications worldwide.</p><p>A simple example for Google Fonts usage:</p><pre><code><code>&lt;link rel=&#8221;stylesheet&#8221; href=&#8221;https://fonts.googleapis.com/css?family=Tangerine&#8221;&gt;</code></code></pre><p>A simple example for Google-hosted Bootstrap and JQuery usage:</p><pre><code><code>&lt;script src=&#8221;https://ajax.googleapis.com/ajax/libs/bootstrap/5.3.3/js/bootstrap.min.js&#8221;&gt;&lt;/script&gt;
&lt;script src=&#8221;https://ajax.googleapis.com/ajax/libs/jquery/3.7.1/jquery.min.js&#8221;&gt;&lt;/script&gt;</code></code></pre><h2><strong>Keyboard Proximity Search &amp; WHOIS Data</strong></h2><p>I began looking into potential typosquatting vectors for <code>googleapis.com</code> using keyboard proximity analysis to identify likely typos. Using a combination of algorithm-generated typo permutations and manual analysis of common developer mistakes, I identified a list of high-risk domain variations.</p><p>The next step was querying WHOIS servers to determine registration status, ownership patterns, and potential malicious indicators for these domains.</p><p>Here&#8217;s what I found when analyzing key typosquatting domains:</p><ul><li><p>gogleapis[.]com - created on 2014-09-09</p></li><li><p>googleapis[.]net - created on 2024-12-18</p></li><li><p>googleapk[.]com - created on 2010-11-16</p></li><li><p>googleapjs[.]com - created on 2019-08-31</p></li><li><p>gooogleapis[.]com - created on 2020-02-1</p></li><li><p>googeapis[.]com - created on 2022-07-18</p></li><li><p>googleapi[.]com - created on 2004-04-02</p></li><li><p>googlepis[.]com - created on 2016-07-13</p></li><li><p>googleapp[.]com - created on 2008-05-15</p></li><li><p>googleqpis[.]com - created on 2024-03-13</p></li><li><p>gogleapi[.]com - created on 2024-03-07</p></li><li><p>googieapis[.]com - created on 2017-05-13</p></li><li><p>gogleapi[.]com - created on 2024-03-07</p></li><li><p>googlrapis[.]com - created on 2016-03-07</p></li><li><p>googapis[.]com - created on 2016-03-08</p></li><li><p>googpeapi[.]com - created on 2024-07-05</p></li><li><p>googleapls[.]com - created on 2019-04-23</p></li><li><p>googleapics[.]com - created on 2024-11-0</p></li><li><p>googleapls[.]com - created on 2019-04-23</p></li><li><p>googleaips[.]com - created on 2024-08-26</p></li><li><p>googlaepis[.]com - created on 2017-01-27</p></li></ul><h2><strong>Findings</strong></h2><ol><li><p><strong>Legitimate Google Domains vs. Typosquats</strong>:</p><p>The domains registered by Google LLC through MarkMonitor (<code>googleapis[.]com</code>, <code>googleapi[.]com</code>, <code>googlepis[.]com</code>, <code>googleapp[.]com</code>, <code>googleqpis[.]com</code>) all use Google&#8217;s nameservers. This is expected as it&#8217;s possible that Google proactively registers common typos to protect users.</p><p>However, I identified 17 typosquatted variations present in the dataset that aren&#8217;t likely controlled by Google.</p></li><li><p><strong>Recently Registered Domains (Potential Threats)</strong>:</p><p>Several domains were registered in the past year, suggesting active typosquatting campaigns:</p><ul><li><p><code>googleapis[.]net</code> (Dec 2024) - Alibaba Cloud, using Cloudflare nameservers</p></li><li><p><code>gogleapi[.]com</code> (Mar 2024) - NAMECHEAP, using Namecheap hosting</p></li><li><p><code>googpeapi[.]com</code> (Jul 2024) - NameCheap, using Cloudflare nameservers</p></li><li><p><code>googleapics[.]com</code> (Nov 2024) - NameSilo, using Host-WW nameservers</p></li><li><p><code>googleaips[.]com</code> (Aug 2024) - REGISTER S.P.A., using Register.it nameservers</p></li></ul></li><li><p><strong>Long-lived Typosquats</strong>:</p><p>Some typosquatting domains have been active for surprisingly long periods:</p><ul><li><p><code>gogleapis[.]com</code> (since 2014)</p></li><li><p><code>googleapk[.]com</code> (since 2010)</p></li></ul><p>These long-established domains may have built significant traffic over time.</p></li><li><p><strong>Very Recent Activity</strong>:</p><p>The domain <code>googleqpis[.]com</code> was updated on March 14, 2025 (today!)</p></li></ol><h2><strong>My Experiment</strong></h2><p>To quantify the real-world impact of typosquatting against <code>googleapis.com</code>, I conducted a controlled experiment:</p><p><strong>Methodology</strong>:</p><p>The particular typo I targeted (.cm instead of .com) has been documented as a frequent typosquatting vector. According to <a href="https://krebsonsecurity.com/2018/04/dot-cm-typosquatting-sites-visited-12m-times-so-far-in-2018/">research by Brian Krebs</a>, .<code>.cm</code> typosquatting sites received over 12 million visits in just the first quarter of 2018.</p><ol><li><p>I registered the domain <code>googleapis[.]cm</code> (Cameroon TLD)</p></li><li><p>Implemented a <a href="https://matomo.org/">Matomo</a> instance to track visitors</p></li><li><p>Created a minimal PHP endpoint, using Matomo PHP SDK, at <code>*.googleapis[.]cm</code></p></li></ol><p><strong>Results</strong>:</p><p>Within just 24 hours, my typosquatted domain received connections from several surprising sources:</p><ul><li><p>A United States-based medical service organization that provides services to more than 20,000 healthcare organizations</p></li><li><p>An Indonesian government organization</p></li><li><p>A water purification facility</p></li><li><p>A media publication tool</p></li><li><p>A small social media website</p></li><li><p>An online education platform</p></li></ul><p>The affected organizations have been notified about the vulnerability in their code.</p><h2><strong>Exploitation Methods</strong></h2><p>Had a malicious actor controlled any typosquatted variant of googleapis.com&#8212;whether through TLD confusion (.cm, .co, .net), character omission (googleapi.com), character insertion (gooogleapis.com), or character transposition (googelapis.com)&#8212;they could exploit any website that accidentally referenced these misspelled domains in their code. These attack vectors aren&#8217;t limited to the .cm TLD example from my experiment; they apply to any typosquatted variant that appears in a website&#8217;s HTML, CSS, or JavaScript. Here&#8217;s how attackers could exploit different types of mistyped Google API endpoints:</p><ol><li><p><strong>For fonts.googleapis[.]cm (CSS resources):</strong> Attackers controlling this domain could return weaponized CSS using <a href="https://research.securitum.com/stealing-data-in-great-style-how-to-use-css-to-attack-web-application/">attribute selectors to exfiltrate sensitive data</a> from form fields and page content, effectively creating data-stealing stylesheets. They might deploy <a href="https://research.securitum.com/stealing-data-in-great-style-how-to-use-css-to-attack-web-application/">specially crafted font files</a> with malicious ligatures that capture and leak information when specific character combinations are displayed, or implement CSS-based keyloggers that track user input through clever selector combinations and background image requests that encode captured keystrokes in the requested URL parameters.</p></li><li><p><strong>For ajax.googleapis[.]cm (JavaScript libraries):</strong> By controlling this domain, attackers could serve compromised versions of popular JavaScript libraries like jQuery or Angular with embedded backdoors or tracking code that executes in the context of the victim site. These malicious scripts could harvest form data, cookies, and authentication tokens; manipulate the DOM to alter page content, insert convincing phishing forms, or redirect users to fraudulent sites; and even inject cryptojacking scripts that silently mine cryptocurrency using visitors&#8217; CPU resources, all while appearing to come from a trusted Google domain.</p></li><li><p><strong>For storage.googleapis[.]cm:</strong> Controlling this domain would allow attackers to serve malicious executables, libraries, or container images in place of legitimate software that developers and applications expect to download from Google&#8217;s storage. This creates a particularly dangerous vector for software supply chain attacks where deployment pipelines, CI/CD systems, or automated update mechanisms unknowingly pull and integrate compromised packages, potentially affecting thousands of downstream systems and providing persistent access that survives beyond the initial compromise.</p></li></ol><p>The impact of such an attack could be especially severe as the malicious code would execute with the privileges of the trusted website domain, bypassing same-origin policy protections. For websites handling sensitive information&#8212;like the healthcare organization in my findings&#8212;this could lead to <a href="https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business">HIPAA violations</a> and exposure of protected health information.</p><h2><strong>Conclusion</strong></h2><p>A single mistyped character in a domain name can lead to data breaches, credential theft, and malware distribution. The financial and reputational damage from such attacks can be enormous, especially when they impact critical infrastructure or healthcare organizations.</p>]]></content:encoded></item><item><title><![CDATA[Technical Analysis Reveals Coordinated Network of Chinese-Language News Sites in Canada]]></title><description><![CDATA[Investigation finds common WordPress accounts, shared servers, and identical content distribution across Chinese-language news websites covering Canadian elections and local community affairs]]></description><link>https://www.safwire.net/p/technical-analysis-reveals-coordinated</link><guid isPermaLink="false">https://www.safwire.net/p/technical-analysis-reveals-coordinated</guid><dc:creator><![CDATA[Jim Yan]]></dc:creator><pubDate>Sat, 15 Jun 2024 05:19:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dADU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2><strong>Background</strong></h2><p>As a Chinese-speaking immigrant living in Canada, like many others, I often use Chinese keywords to search for news on Google. This is how I stumbled upon a series of Chinese-language websites that appear to be local Chinese news platforms. These sites are frequently updated and have strong ties to local Chinese communities and organizations, particularly those connected to Beijing. The news content on these websites generally supports Beijing&#8217;s perspective, presenting themselves as official news sources to the Chinese community in Canada, portraying an image of authoritative news providers in Chinese.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dADU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dADU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dADU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dADU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dADU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dADU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg" width="1024" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A Network of Pro-Beijing News Websites Originating from Canada&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A Network of Pro-Beijing News Websites Originating from Canada" title="A Network of Pro-Beijing News Websites Originating from Canada" srcset="https://substackcdn.com/image/fetch/$s_!dADU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dADU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dADU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dADU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885a177d-8f66-47e0-a450-a1aaab35e801_1024x720.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>An initial investigation of backlinks and keyword analysis has discovered that around 200 websites, featuring similar content in Chinese and targeting a global audience, potentially share a common agenda. It&#8217;s important to note that this analysis report has not verified all ~200 websites, as our focus was only on a small subset of them.</p><blockquote><p><strong>Note</strong>: In February 2024, the Citizen Lab at the University of Toronto <a href="https://citizenlab.ca/2024/02/paperwall-chinese-websites-posing-as-local-news-outlets-with-pro-beijing-content/">revealed</a> that at least 123 websites, originating from the People&#8217;s Republic of China and masquerading as local news outlets in 30 countries across Europe, Asia, and Latin America, were spreading pro-Beijing disinformation and ad hominem attacks amidst a plethora of commercial press releases. This operation was named &#8220;Paperwall.&#8221; However, the Chinese websites discussed in our specific analysis are <strong>not part of the &#8220;Paperwall&#8221; campaign</strong> identified by the Citizen Lab. They are all Chinese-language publications and do not share any characteristics with the &#8220;Paperwall&#8221; websites. There is no clear evidence to suggest any connection between them.</p></blockquote><p>An analysis of the infrastructure and content of a small subset of these websites has been performed below, focusing primarily on those targeting Canada, especially the Greater Toronto Area. We will explore how these websites have been used to influence the ideologies within the Chinese Canadian communities and affect the political landscape.</p><h2><strong>Key Findings</strong></h2><ol><li><p><strong>Widespread Network</strong>: The analysis identified over 200 potentially related websites actively publishing content that aligns with Beijing&#8217;s geopolitical interests. This analysis examined a small subset of these outlets. These outlets not only target local communities but also connect with global audiences, suggesting a coordinated effort to shape perceptions on a larger scale.</p></li><li><p><strong>Centralized Control and Common Infrastructure</strong>: Evidence from technology stack analysis, such as shared WordPress themes and user accounts across multiple sites, suggests a centralized operational structure. This commonality points to a concerted effort to maintain and control the narrative dispersed through these channels.</p></li><li><p><strong>Direct Ties to Pro-Beijing Organizations</strong>: Links have been established between these media outlets and organizations like CTCCO and Easyca.ca, which are known for their pro-Beijing stances. Such associations are indicative of an organized attempt to utilize community media as a tool for political influence and community manipulation.</p></li><li><p><strong>Potential Impact on Local Elections and Community Relations</strong>: The content distributed by these outlets often focuses on promoting specific political figures and policies favorable to Beijing, which could influence voter perceptions and decisions in local Canadian elections.</p></li></ol><h2><strong>A Network of Pro-Beijing News Websites Originating from Canada</strong></h2><p>An initial search uncovered the following websites, which represent just a subset of hundreds of similar sites. These were identified through connections such as backlinks, identical DNS infrastructure, site builders, user accounts, or WHOIS records.</p><ul><li><p><code>CC.NEWS - ccmedia[.]news/</code></p></li><li><p><code>&#22269;&#38469;&#33402;&#26415;&#26032;&#38395;&#32593; -- International Arts News: Arts without Borders - www[.]artnewsnet[.]com/</code></p></li><li><p><code>&#21152;&#25343;&#22823;&#21644;&#19990;&#30028;&#25253;&#36947; -- Canada &amp; World Report - www[.]canadanewsreport[.]com/</code></p></li><li><p><code>&#22810;&#20262;&#22810;&#26032;&#38395;&#32593; -- &#36830;&#25509;&#22810;&#20262;&#22810;&#21644;&#19990;&#30028; - www[.]torontonewsnet[.]com/</code></p></li><li><p><code>&#32445;&#32422;&#37117;&#24066;&#26032;&#38395;&#32593; -- &#26469;&#33258;&#19990;&#30028;&#20043;&#37117;&#30340;&#28145;&#24230;&#25253;&#36947; - www[.]newyorknewsnet[.]com/</code></p></li><li><p><code>&#19990;&#30028;&#21326;&#25991;&#23186;&#20307;-World Chinese Media -- &#20840;&#29699;&#20013;&#25991;&#23186;&#20307;&#20043;&#23186;&#20307; - www[.]worldchinesemedia[.]com/</code></p></li><li><p><code>ChineseCanadianVoice[.]ca - www[.]chinesecanadianvoice[.]ca/</code></p></li><li><p><code>&#22269;&#23478;&#30005;&#35270;&#26032;&#38395;&#32593; - www[.]ntvnewsnet[.]com/</code></p></li><li><p><code>&#20581;&#24247;&#29983;&#27963;&#25253;&#36947;-&#20581;&#24247;&#12289;&#20307;&#32946;&#12289;&#29983;&#27963;&#26032;&#38395; -- Health Life Report - www[.]healthlifereport[.]com/</code></p></li><li><p><code>&#32654;&#22269;&#35199;&#37096;&#26032;&#38395; -- &#35199;&#37096;&#26032;&#38395;&#23613;&#25910;&#30524;&#24213; - www[.]uswestnews[.]com/</code></p></li><li><p><code>&#29615;&#29699;&#21326;&#35821;&#26032;&#38395;&#20013;&#24515; - www[.]cgctv[.]com/</code></p></li></ul><h2><strong>Mimicking Legitimacy: The Strategic Naming and Presentation of Pro-Beijing News Sites</strong></h2><p>An important aspect of the influence exerted by the network of pro-Beijing news sites in Canada is their strategic naming and presentation, which meticulously mimics the appearance of legitimate and authoritative news sources. This tactic is evidently designed to enhance credibility and trust among the target audiences, particularly within the Chinese Canadian community.</p><h3><strong>Packaging to Appear Authoritative</strong></h3><p>Another site, <code>cntvcanada[.]com</code>, styles itself as &#8220;&#21152;&#25343;&#22823;&#22269;&#23478;&#30005;&#35270;&#21488; (Canada National Television),&#8221; packaging itself in a manner that closely mirrors <a href="https://en.wikipedia.org/wiki/China_Central_Television">China&#8217;s state broadcaster, CCTV</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bC0S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bC0S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png 424w, https://substackcdn.com/image/fetch/$s_!bC0S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png 848w, https://substackcdn.com/image/fetch/$s_!bC0S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png 1272w, https://substackcdn.com/image/fetch/$s_!bC0S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bC0S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png" width="1024" height="307" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:307,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!bC0S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png 424w, https://substackcdn.com/image/fetch/$s_!bC0S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png 848w, https://substackcdn.com/image/fetch/$s_!bC0S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png 1272w, https://substackcdn.com/image/fetch/$s_!bC0S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe159ee3f-e507-40d2-bf89-0eb83739be3d_1024x307.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The &#21152;&#25343;&#22823;&#22269;&#23478;&#30005;&#35270;&#21488; (Canada National Television) website</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3wpT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3wpT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3wpT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3wpT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3wpT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3wpT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg" width="600" height="304" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:304,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A Canada National TV news truck&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A Canada National TV news truck" title="A Canada National TV news truck" srcset="https://substackcdn.com/image/fetch/$s_!3wpT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3wpT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3wpT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3wpT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffc3b34-3981-402b-92be-9d2aca0c490b_600x304.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A Canada National TV news truck (Source: China Daily)</p><p>This nomenclature and styling are likely intended to confer upon it an unwarranted level of credibility akin to that of a national broadcaster, leveraging the formal tone and visual presentation typical of government-run entities.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xY3w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xY3w!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png 424w, https://substackcdn.com/image/fetch/$s_!xY3w!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png 848w, https://substackcdn.com/image/fetch/$s_!xY3w!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png 1272w, https://substackcdn.com/image/fetch/$s_!xY3w!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xY3w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png" width="1024" height="538" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:538,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xY3w!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png 424w, https://substackcdn.com/image/fetch/$s_!xY3w!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png 848w, https://substackcdn.com/image/fetch/$s_!xY3w!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png 1272w, https://substackcdn.com/image/fetch/$s_!xY3w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a032368-4d1c-4dda-a13c-72c96f661384_1024x538.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The TV Station is operated by the entity &#8220;CANADA NATIONAL TV INC.&#8221;, according to the Ontario Business Registry.</p><h3><strong>Imitation of Established Media Names</strong></h3><p>Many of the websites in this network have adopted names that resonate with well-known media outlets, both in style and substance.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y99n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y99n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png 424w, https://substackcdn.com/image/fetch/$s_!Y99n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png 848w, https://substackcdn.com/image/fetch/$s_!Y99n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png 1272w, https://substackcdn.com/image/fetch/$s_!Y99n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y99n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png" width="1024" height="488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&#22269;&#23478;&#30005;&#35270;&#26032;&#38395;&#32593; (National TV News Network)&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="&#22269;&#23478;&#30005;&#35270;&#26032;&#38395;&#32593; (National TV News Network)" title="&#22269;&#23478;&#30005;&#35270;&#26032;&#38395;&#32593; (National TV News Network)" srcset="https://substackcdn.com/image/fetch/$s_!Y99n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png 424w, https://substackcdn.com/image/fetch/$s_!Y99n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png 848w, https://substackcdn.com/image/fetch/$s_!Y99n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png 1272w, https://substackcdn.com/image/fetch/$s_!Y99n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e471c0-5ff7-4af1-ac26-e7b4040b8d7c_1024x488.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The &#8220;&#22269;&#23478;&#30005;&#35270;&#26032;&#38395;&#32593; (National TV News Network)&#8221; website</p><p>For example, &#8220;&#22269;&#23478;&#30005;&#35270;&#26032;&#38395;&#32593; (National TV News Network)&#8221; at <code>ntvnewsnet[.]com</code>, suggests an affiliation with national television, potentially leading visitors to believe it is a legitimate state or national news service.</p><h3><strong>Unauthorized Use of Official Symbols</strong></h3><p>The use of official symbols or logos without authorization is another tactic employed to gain unwarranted legitimacy.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bPy4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bPy4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png 424w, https://substackcdn.com/image/fetch/$s_!bPy4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png 848w, https://substackcdn.com/image/fetch/$s_!bPy4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png 1272w, https://substackcdn.com/image/fetch/$s_!bPy4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bPy4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png" width="1024" height="271" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:271,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!bPy4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png 424w, https://substackcdn.com/image/fetch/$s_!bPy4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png 848w, https://substackcdn.com/image/fetch/$s_!bPy4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png 1272w, https://substackcdn.com/image/fetch/$s_!bPy4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb34fba50-778e-470f-a8f9-3d5ac621fa50_1024x271.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YwCd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YwCd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png 424w, https://substackcdn.com/image/fetch/$s_!YwCd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png 848w, https://substackcdn.com/image/fetch/$s_!YwCd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png 1272w, https://substackcdn.com/image/fetch/$s_!YwCd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YwCd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png" width="469" height="179" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:179,&quot;width&quot;:469,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!YwCd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png 424w, https://substackcdn.com/image/fetch/$s_!YwCd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png 848w, https://substackcdn.com/image/fetch/$s_!YwCd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png 1272w, https://substackcdn.com/image/fetch/$s_!YwCd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe879a9e8-a90c-455d-8051-161c1b0e6224_469x179.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>torontonewsnet[.]com uses the City of Toronto&#8217;s logo as its &#8220;favicon&#8221;</p><p>For instance, <code>torontonewsnet[.]com</code> uses the City of Toronto&#8217;s logo as its &#8220;favicon&#8221; without authorization, a clear strategy to mislead readers into associating the site with Toronto&#8217;s official communications.</p><h3><strong>Linguistic and Cultural Resonance</strong></h3><p>The names often include terms like &#8220;global,&#8221; &#8220;international,&#8221; &#8220;national,&#8221; or direct references to major cities or regions (e.g., New York, Toronto, Western U.S.), which are designed to resonate with diaspora communities from those regions.</p><h2><strong>Technology Stack Analysis</strong></h2><h3><strong>WordPress Themes / Site Builders</strong></h3><p>The majority of these sites employ the &#8216;colormag&#8217; theme, albeit with different version updates. This commonality could suggest a shared preference or guidance in their website design choices, potentially indicating a coordinated effort or common source of technical support.</p><h3><strong>Username Enumeration</strong></h3><p>We examined each site&#8217;s user accounts using a method known as user enumeration. The scan identified that a single account might be managing at least six WordPress sites, as indicated by the consistent use of usernames across these websites.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iEQr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iEQr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png 424w, https://substackcdn.com/image/fetch/$s_!iEQr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png 848w, https://substackcdn.com/image/fetch/$s_!iEQr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png 1272w, https://substackcdn.com/image/fetch/$s_!iEQr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iEQr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png" width="989" height="590" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2c198289-10fa-4678-9c28-9e6897e50517_989x590.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:590,&quot;width&quot;:989,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!iEQr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png 424w, https://substackcdn.com/image/fetch/$s_!iEQr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png 848w, https://substackcdn.com/image/fetch/$s_!iEQr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png 1272w, https://substackcdn.com/image/fetch/$s_!iEQr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c198289-10fa-4678-9c28-9e6897e50517_989x590.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The presence of common usernames across multiple sites, particularly when these usernames are associated with editorial roles, significantly strengthens the argument for a shared operational structure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rPdi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rPdi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png 424w, https://substackcdn.com/image/fetch/$s_!rPdi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png 848w, https://substackcdn.com/image/fetch/$s_!rPdi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png 1272w, https://substackcdn.com/image/fetch/$s_!rPdi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rPdi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png" width="1023" height="706" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:706,&quot;width&quot;:1023,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!rPdi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png 424w, https://substackcdn.com/image/fetch/$s_!rPdi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png 848w, https://substackcdn.com/image/fetch/$s_!rPdi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png 1272w, https://substackcdn.com/image/fetch/$s_!rPdi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80054c8b-38d1-4e78-8b6d-c9b151ffe8d7_1023x706.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For instance, the username <code>Editor</code> is linked to six different websites, suggesting that either a single individual or a group operating under this generic username has control over the content on these platforms. Similarly, the username <code>jzwgq</code> is associated with six sites, and <code>jzz</code> with three, indicating a pattern of recurring usernames across multiple platforms, which is less likely to be coincidental.</p><p>Note: The username <code>admin</code> is often chosen by system administrators for new WordPress installations and does not necessarily signify a connection between sites. However, <code>Editor</code> is not a default administrator username for WordPress.Dataframe: Most frequent usernames and associated websites</p><h2><strong>The Infrastructure</strong></h2><h3><strong>DNS Analysis</strong></h3><p>The examination of A records, nameservers, and TXT records for the listed websites offers valuable insights into their infrastructural connections and potential control dynamics.</p><h4><code>&#65313;</code><strong> Records</strong></h4><p>The <code>A</code> records reveal that several websites share the same IP address (<code>162.241.240[.]199</code>), suggesting they are hosted on the same server or within the same hosting environment. This commonality in hosting could indicate a centralized operational structure or shared administrative resources. However, the presence of unique IP addresses for other sites (<code>66.96.162[.]139</code>, <code>50.62.182[.]6</code>, and <code>52.60.232[.]75</code>) means these sites might be independently managed or hosted with different intentions or levels of control.</p><h4><strong>Nameservers</strong></h4><p>The nameservers provide further evidence of potential connections between the sites. Many of the websites use the same pair of nameservers (<code>ns1.server-602265.lifeandwealthhosting[.]com</code> and <code>ns2.server-602265.lifeandwealthhosting[.]com</code>), reinforcing the notion of a shared hosting or management environment.</p><h4><strong>TXT records</strong></h4><p>TXT records, particularly those specifying SPF (Sender Policy Framework) settings, highlight how these websites manage email sending and potentially share similar security or email handling policies. The inclusion of the same domain (<code>websitewelcome[.]com</code>) in several SPF records points to a shared approach to email management or a common service provider.</p><h3><strong>WHOIS Records Analysis</strong></h3><p>The WHOIS records analysis reveals intriguing details about the registration and administrative contacts of the domains.</p><ol><li><p><strong>Registrant Location</strong>: A significant number of the domains are registered in Ontario, Canada, with the registrant&#8217;s province listed as <code>ON</code> or <code>ONTARIO</code> and the country as <code>CA</code> (Canada). This geographic clustering suggests a centralized operation or a targeted strategy focused on the Canadian context, particularly relevant for those websites aimed at the Chinese Canadian community.</p></li><li><p><strong>Registrar Consistency</strong>: Many of the domains are registered through <code>ENOM, INC.</code>, a common registrar, which could indicate a preferencewith this particular service provider.</p></li><li><p><strong>Domain Creation and Expiration Dates</strong>: The dates when these domains were created and their expiration dates provide a timeline of the network&#8217;s development.</p></li></ol><h2><strong>The Content</strong></h2><h3><strong>Sustained presence since 2016</strong></h3><p>We structurely retrieved all posts across all target websites. The analysis illustrates the number of posts per month across the network of websites starting from 2016, according to WHOIS data.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fWsP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fWsP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png 424w, https://substackcdn.com/image/fetch/$s_!fWsP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png 848w, https://substackcdn.com/image/fetch/$s_!fWsP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png 1272w, https://substackcdn.com/image/fetch/$s_!fWsP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fWsP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png" width="852" height="547" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:547,&quot;width&quot;:852,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!fWsP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png 424w, https://substackcdn.com/image/fetch/$s_!fWsP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png 848w, https://substackcdn.com/image/fetch/$s_!fWsP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png 1272w, https://substackcdn.com/image/fetch/$s_!fWsP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F792c3cfb-9c86-455c-970b-f81eacc2fd91_852x547.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The graph shows an initial period of growth in posting frequency, with a particularly sharp peak around 2020. Despite the fluctuations, there is a sustained presence of activity, which suggests a consistent effort to maintain an active content feed over multiple years.</p><h3><strong>Proliferation of Repetitive Content Across the Network</strong></h3><p>One of the most interesting characteristics of the network of pro-Beijing news websites is their widespread use of identical articles across multiple platforms. This tactic not only amplifies the message but also suggests a coordinated approach to content distribution, designed to create an echo chamber effect. This analysis has identified several articles that have been repeatedly published across different sites, often verbatim. This pattern is indicative of a strategic dissemination aimed at maximizing reach and influence among Chinese-speaking audiences globally.</p><h3><strong>Framing the Hong Kong Protests</strong></h3><p>The examination of article titles from the network&#8217;s coverage of the Hong Kong protests provides a clear insight into the ideological tilt and narrative framing employed by these pro-Beijing news outlets operating within the Canadian Chinese community.</p><p>Relevant collection of articles from the &#8220;shadow network&#8221;:</p><ul><li><p><a href="https://web.archive.org/web/20240416053511/https://ccmedia.news/archives/12286">&#12298;&#22810;&#20262;&#22810;&#21326;&#20154;&#22242;&#20307;&#32852;&#21512;&#24635;&#20250;&#25903;&#25345;&#20013;&#22269;&#20154;&#22823;&#26377;&#20851;&#39321;&#28207;&#22269;&#23433;&#31435;&#27861;&#30340;&#22768;&#26126;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20230209102106/https://news.cgctv[.]com/2020/07/03/%E9%A6%99%E6%B8%AF%E7%BB%B4%E6%8A%A4%E5%9B%BD%E5%AE%B6%E5%AE%89%E5%85%A8%E6%B3%95-%E5%AE%88%E6%8A%A4%E7%89%B9%E5%8C%BA-%E6%89%AC%E5%B8%86%E8%BF%9C%E8%88%AA/">&#12298;&#39321;&#28207;&#32500;&#25252;&#22269;&#23478;&#23433;&#20840;&#27861; &#23432;&#25252;&#29305;&#21306; &#25196;&#24070;&#36828;&#33322;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20201202095048/https://www.cgctv[.]com/2020/06/29/%E4%BA%BA%E6%B0%91%E9%94%90%E8%AF%84%EF%BD%9C%E9%A6%99%E6%B8%AF%E8%AE%B0%E5%8D%8F%EF%BC%8C%E5%88%AB%E5%86%8D%E4%BD%9C%E5%A6%96%E4%BA%86/">&#12298;&#20154;&#27665;&#38160;&#35780;&#65372;&#39321;&#28207;&#35760;&#21327;&#65292;&#21035;&#20877;&#20316;&#22934;&#20102;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20201127151528/https://news.cgctv[.]com/2020/04/22/%E4%BB%A5%E7%96%AB%E4%B8%BA%E5%96%BB-%E9%A6%99%E6%B8%AF%E4%B8%8D%E5%BA%94%E5%86%8D%E8%AE%B3%E7%96%BE%E5%BF%8C%E5%8C%BB/">&#12298;&#20197;&#30123;&#20026;&#21947;------&#39321;&#28207;&#19981;&#24212;&#20877;&#35763;&#30142;&#24524;&#21307;&#12299;</a></p></li></ul><p>The articles themselves are revealing, showcasing a strong alignment with Beijing&#8217;s rhetoric regarding Hong Kong&#8217;s political dynamics.</p><h3><strong>Political Mobilization in the Chinese Canadian Community</strong></h3><p>One striking example of how these pro-Beijing websites attempt to influence the voting behaviors of the Chinese Canadian community is evident across multiple sites.</p><p>Relevant collection of articles from the &#8220;shadow network&#8221;:</p><ul><li><p><a href="https://web.archive.org/web/20180820220954/https://www.canadanewsreport[.]com/2018/06/01/2125/">&#12298;&#31215;&#26497;&#21161;&#36873;&#25237;&#31080;&#65292;&#25903;&#25345;&#21326;&#35028;&#20505;&#36873;&#20154;&#40644;&#32032;&#26757;&#31454;&#36873;&#36830;&#20219;&#23433;&#30465;&#35758;&#21592;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20240416053937/https://ccmedia.news/archives/22894">&#12298;&#23601;&#24046;&#20320;&#19968;&#31080;&#65281;&#20840;&#21152;&#21326;&#35028;&#31038;&#21306;&#25472;&#36215;&#25237;&#31080;&#23459;&#20256;&#39640;&#28526;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20230519193027/https://ccmedia.news/archives/22058">&#12298;&#21326;&#32852;&#24635;&#20250;&#21628;&#21505;&#21152;&#22269;&#21326;&#20154;&#29645;&#24796;&#27665;&#20027;&#26435;&#21033;&#36362;&#36291;&#25237;&#31080;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20200929035329/https://cgctv[.]com/2019/10/01/2019%E8%81%94%E9%82%A6%E9%80%89%E4%B8%BE%E5%85%AC%E5%BC%80%E8%AE%BA%E5%9D%9B%EF%BC%8C%E5%91%BC%E5%90%81%E5%8D%8E%E4%BA%BA%E7%A7%AF%E6%9E%81%E5%8F%82%E4%B8%8E%E6%8A%95%E7%A5%A8/">&#12298;2019&#32852;&#37030;&#36873;&#20030;&#20844;&#24320;&#35770;&#22363;&#65292;&#21628;&#21505;&#21326;&#20154;&#31215;&#26497;&#21442;&#19982;&#25237;&#31080;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20210927100438/https://www.canadanewsreport[.]com/2021/08/23/8979/">&#12298;&#35831;&#20026;&#31038;&#20250;&#27491;&#20041;&#21644;&#21152;&#25343;&#22823;&#22269;&#23478;&#21033;&#30410;&#25237;&#31080;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20180601020956/https://www.canadanewsreport[.]com/2018/05/13/1854/">&#12298;&#21326;&#20154;&#24212;&#35813;&#20026;&#33258;&#24049;&#30340;&#21033;&#30410;&#25237;&#31080;&#12299;</a></p></li></ul><p>One particularly notable article from the network of pro-Beijing news websites targets the Chinese Canadian community&#8217;s political engagement in Canada. Published on &#8220;Canada News Report,&#8221; the article titled &#8220;<a href="https://web.archive.org/web/20180820220954/https://www.canadanewsreport[.]com/2018/06/01/2125/">&#31215;&#26497;&#21161;&#36873;&#25237;&#31080;&#65292;&#25903;&#25345;&#21326;&#35028;&#20505;&#36873;&#20154;&#40644;&#32032;&#26757;&#31454;&#36873;&#36830;&#20219;&#23433;&#30465;&#35758;&#21592;</a>&#8220; directly appeals to readers to support Su-Mei Huang, a Chinese Canadian incumbent running for re-election as an Ontario provincial legislator.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WzYQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WzYQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png 424w, https://substackcdn.com/image/fetch/$s_!WzYQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png 848w, https://substackcdn.com/image/fetch/$s_!WzYQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png 1272w, https://substackcdn.com/image/fetch/$s_!WzYQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WzYQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png" width="1015" height="1023" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/deabbc27-b034-44b4-b722-5f639390464c_1015x1023.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1023,&quot;width&quot;:1015,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!WzYQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png 424w, https://substackcdn.com/image/fetch/$s_!WzYQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png 848w, https://substackcdn.com/image/fetch/$s_!WzYQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png 1272w, https://substackcdn.com/image/fetch/$s_!WzYQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdeabbc27-b034-44b4-b722-5f639390464c_1015x1023.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Su-Mei Huang is portrayed as a self-made politician who climbed the ranks from a nurse to a university professor and ultimately a provincial legislator, all without any political family background. The article highlights her dedication to vulnerable groups, healthcare, education, and public services, and outlines her achievements and future policy goals.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!65gu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!65gu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png 424w, https://substackcdn.com/image/fetch/$s_!65gu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png 848w, https://substackcdn.com/image/fetch/$s_!65gu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png 1272w, https://substackcdn.com/image/fetch/$s_!65gu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!65gu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png" width="1010" height="420" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:1010,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!65gu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png 424w, https://substackcdn.com/image/fetch/$s_!65gu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png 848w, https://substackcdn.com/image/fetch/$s_!65gu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png 1272w, https://substackcdn.com/image/fetch/$s_!65gu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c7162d-4f4c-4f8a-a3c1-3739165cd3a7_1010x420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Media Influence in Toronto&#8217;s Mayoral Election: The Case of Xiaohua Gong</strong></h3><p>The 2023 Toronto mayoral race showcased an intriguing examination of media influence and strategy, particularly through the <a href="https://globalnews.ca/news/9791100/xiao-hua-gong-who-is-toronto-election-mayor-campaign/">campaign of Xiaohua Gong</a>, a Chinese-Canadian businessman with a controversial past. His campaign&#8217;s extensive use of both Chinese and English media platforms highlighted unique approaches to targeting diverse demographic segments within Toronto&#8217;s electorate.</p><p>Relevant collection of articles from the &#8220;shadow network&#8221;:</p><ul><li><p><a href="https://web.archive.org/web/20230928164853/https://www.torontonewsnet[.]com/2023/08/12/13053/">&#12298;&#22810;&#20262;&#22810;&#24066;&#38271;&#20505;&#36873;&#20154;&#40858;&#26195;&#21326;&#65288;Xiaohua Gong&#65289;&#20030;&#21150;&#31572;&#35874;&#32852;&#27426;&#20250;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20230530084252/https://www.healthlifereport[.]com/2023/05/10/12227/">&#12298;&#22810;&#20262;&#22810;&#24066;&#38271;&#20399;&#36873;&#20154;&#40858;&#26195;&#21326;&#21644;&#24066;&#27665;&#20844;&#24320;&#23545;&#35805;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20240416054427/https://ccmedia.news/archives/39510">&#12298;&#22810;&#20262;&#22810;&#24066;&#38271;&#20505;&#36873;&#20154;&#40858;&#26195;&#21326;&#21644;&#24066;&#27665;&#21450;&#23567;&#26379;&#21451;&#20849;&#28193;&#8221;&#20845;&#19968;&#8221;&#20799;&#31461;&#33410;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20240416054447/https://ccmedia.news/archives/38698">&#12298;&#22810;&#20262;&#22810;&#24066;&#38271;&#20399;&#36873;&#20154;&#40858;&#26195;&#21326;&#31609;&#27454;&#26202;&#23476;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20230519040313/https://ccmedia.news/archives/38119">&#12298;&#40858;&#26195;&#21326;&#20170;&#23459;&#24067;&#31454;&#36873;&#22810;&#20262;&#22810;&#24066;&#38271;&#12299;</a></p></li><li><p><a href="https://web.archive.org/web/20230711123041/https://www.worldchinesemedia[.]com/2023/06/10/10207/">&#12298;&#32654;&#22269;&#36817;100&#23478;&#33521;&#25991;&#23186;&#20307;&#25253;&#36947;&#22810;&#20262;&#22810;&#24066;&#38271;&#20505;&#36873;&#20154;&#40858;&#26195;&#21326;(Xiao Hua Gong)&#12299;</a></p></li></ul><p>The network of pro-Beijing news outlets operating within Canada has shown a keen interest in the Toronto mayoral election, particularly in supporting the candidacy of <a href="https://en.wikipedia.org/wiki/Xiao_Hua_Gong">Xiaohua Gong</a>. The series of articles published across various platforms demonstrates a concerted effort to positively influence public perception of Gong within the Chinese Canadian community.</p><h2><strong>The &#8220;Shadow Network&#8221; and Its Ties to Local Pro-Beijing Organizations</strong></h2><p>This investigation into the network of pro-Beijing Chinese news outlets in Canada reveals a complex web of media influence and associations. Particularly notable is the strong connection these sites have with Easyca.ca, a prominent Chinese-language media company in Canada. Further scrutiny shows that Easyca.ca is closely tied to significant Chinese business and community organizations like the Canada Toronto Fuqing Business Association (&#21152;&#25343;&#22823;&#22810;&#20262;&#22810;&#31119;&#28165;&#21830;&#20250;) and the Confederation of Toronto Chinese Canadian Organizations (&#22810;&#20262;&#22810;&#21326;&#20154;&#22242;&#20307;&#32852;&#21512;&#24635;&#20250;, CTCCO).</p><p><strong>Read more:</strong></p><ul><li><p>National Post: <a href="https://nationalpost[.]com/news/china-friendly-candidates-canadian-elections">New group with Beijing links to promote friendly candidates in Canadian elections</a></p></li></ul><h3><strong>Media Influence and Business Ties</strong></h3><p><a href="https://web.archive.org/web/20240307002118/https://easyca.ca/">Easyca.ca</a> has established itself as a major player in the Chinese media landscape in Canada. However, it&#8217;s not just a media powerhouse; it also serves as a nexus connecting various elements of the Chinese community in Toronto, including business associations that have shown allegiance to Beijing.</p><h3><strong>Role of CTCCO in the Network</strong></h3><p>CTCCO&#8217;s frequent appearances in these outlets are particularly significant. As an organization, CTCCO has been <a href="https://globalnews.ca/news/9280974/china-interference-canada-election-investigation-toronto-businessman/">known to foster close ties</a> with Chinese consular offices and promote events and viewpoints that are strategically beneficial to China. The consistent coverage of CTCCO by the shadow network suggests a coordinated effort to bolster CTCCO&#8217;s credibility and influence among Chinese Canadians, which in turn supports Beijing&#8217;s diplomatic and cultural outreach initiatives.</p><h2><strong>Conclusion of the Investigation into Pro-Beijing Influence Operations in Canadian Chinese-Language Media</strong></h2><p>This report has unveiled a sophisticated network of Chinese-language news outlets operating in Canada, which appear to systematically propagate pro-Beijing narratives and potentially influence the Chinese Canadian communities, particularly within the Greater Toronto Area. The findings from this investigation highlight several key issues that pose concerns for both the integrity of local media landscapes and the broader democratic processes in Canada.</p><h2><strong>Final Word</strong></h2><p>As Canada navigates the complex landscape of global politics and local demographic changes, the importance of safeguarding the informational integrity and independence of its diverse communities cannot be overstated. This investigation into the shadow network of Chinese-language media serves as a critical call to action, urging all stakeholders---from government regulators to community leaders---to take decisive steps to protect the foundational principles of democracy and the diverse fabric of Canadian society.</p>]]></content:encoded></item></channel></rss>