
A phishing campaign known as the Nasty List is spreading through Instagram by turning compromised accounts into advertisements for the scam. Its message is designed to provoke an immediate emotional response: a friend appears to warn that the recipient has been ranked on an insulting list circulating on the service.
The first message often comes from an account the recipient already follows. It may claim that the person appears at a particular number on the list and point to a profile with a name such as The Nasty List followed by changing digits. Familiarity with the sender and curiosity about the supposed ranking make the link more convincing than an unsolicited message from a stranger.
How the Nasty List trap works
The linked Instagram profile contains no real list. Instead, its biography directs visitors to an outside website that promises to reveal the rankings. The page copies the appearance of Instagram’s login screen and asks for a username and password before it will display the alleged content.
The important clue is the address bar. One domain observed during the campaign was nastylist-instatop50[.]me, not instagram.com. A convincing logo, familiar colors and a mobile-sized form do not make a page genuine; the actual domain identifies which organization controls it.
When a victim submits credentials, the attackers can sign in to the real Instagram account. They then use that trusted identity to send the same Nasty List message to its followers. Each stolen account supplies a new audience and a believable sender, giving the campaign a self-propagating pattern similar to an old-fashioned social-network worm.
The technique relies on social engineering rather than a vulnerability in the Instagram app. It combines embarrassment, urgency and curiosity so that a person acts before checking the destination. The changing profile names and numbered claims also make individual scam accounts easy to replace after one is reported.
What users should do
The safest response is to ignore the message, avoid the profile link and report the sending account and Nasty List profile to Instagram. Users should enter Instagram credentials only on the official app or a page whose domain is instagram.com. A password manager can also help because it normally refuses to fill saved credentials on an unrelated domain.
Anyone who entered a password on the fake page should change it immediately, sign out unfamiliar sessions and review the email address, phone number and connected applications associated with the account. The password should also be changed anywhere else it was reused. Enabling two-factor authentication adds a second barrier if an attacker later tries the stolen password.
- Use Instagram’s official password-reset or hacked-account process if access has already been lost.
- Warn followers that recent direct messages may have been sent by an attacker.
- Do not trust a message merely because it came from someone you know; their account may be the victim.
The Nasty List does not exist, but the stolen accounts are real. Its success depends on making a fake login feel like the natural next step in an Instagram conversation. Slowing down long enough to inspect the domain breaks that chain before one compromised account becomes many.
Recent Comments