How scammers use legitimate surveys to link to malicious sites | Kaspersky official blog
Scammers are exploiting legitimate online survey platforms, specifically Yandex Surveys, to embed phishing links within seemingly authentic surveys. These fraudulent surveys bypass spam filters due to their use of reputable domains, tricking users into clicking links that lead to malicious sites, often involving crypto scams or dubious dating offers. Attackers use advanced techniques like invisible characters to hide disclaimers and navigation buttons, making the survey appear legitimate and focused solely on the scam content. Once victims engage, they are lured into prize schemes requiring payment or personal data submission, resulting in financial loss and credential theft. This method leverages free hosting and analytics provided by the survey platform, enabling large-scale, low-cost campaigns. Although Yandex Surveys is shutting down soon, the tactic highlights a growing trend of weaponizing trusted platforms for phishing. Organizations and users must remain vigilant, scrutinize unexpected emails even from trusted domains, and avoid interacting with suspicious surveys or links.
AI Analysis
Technical Summary
This threat involves scammers leveraging legitimate survey platforms, notably Yandex Surveys, to conduct phishing attacks by embedding malicious links within surveys that appear authentic. The attackers create surveys using Yandex's extended survey mode, replacing typical questions with text blocks containing scam pitches and embedded links to fraudulent websites. They enhance credibility by uploading official logos and images, often related to cryptocurrency exchanges, to lure victims. To conceal the survey's standard navigation elements and disclaimers, scammers insert invisible characters such as transparent emojis and punctuation marks to push these elements off-screen, ensuring victims only see the scam content. These surveys are then distributed via mass emails or hijacked website feedback forms, which lack sender verification, allowing the messages to bypass spam filters due to the legitimate yandex.com domain. Victims clicking the embedded links are directed to professional-looking scam sites, typically prize giveaways promising large cryptocurrency rewards but requiring upfront fees or personal information, leading to financial theft. The attackers benefit from free hosting and built-in analytics on the survey platform to track engagement and optimize campaigns. Although Yandex Surveys is scheduled to shut down shortly, this attack exemplifies a broader trend of abusing trusted platforms to evade detection and increase phishing success rates. The campaign has seen rapid scaling, with Kaspersky Premium blocking over 32,000 such emails in February 2026 alone, indicating aggressive expansion. The threat does not involve platform compromise but rather creative misuse of legitimate services, underscoring the need for heightened user awareness and advanced detection strategies.
Potential Impact
This phishing scheme poses significant risks to organizations and individuals worldwide by facilitating credential theft, financial fraud, and potential malware infections if victims interact with malicious payloads. The use of legitimate domains to host phishing content undermines traditional email filtering and web reputation systems, increasing the likelihood of successful attacks. Financial losses can be substantial, especially in cryptocurrency scams where victims pay fees or disclose wallet credentials. The campaign's scalability and low cost enable widespread distribution, potentially affecting large user bases across sectors. Organizations may face increased incident response costs, reputational damage, and regulatory scrutiny if employees fall victim. Additionally, the tactic erodes trust in legitimate survey platforms, complicating genuine marketing and research efforts. Although the immediate threat from Yandex Surveys will diminish after its shutdown, the underlying method of abusing trusted services for phishing is likely to persist and evolve, necessitating ongoing vigilance.
Mitigation Recommendations
Organizations should implement advanced email filtering solutions that incorporate behavioral and contextual analysis beyond domain reputation to detect phishing attempts using legitimate platforms. Security awareness training must emphasize skepticism toward unexpected emails, even those containing links to well-known domains, and instruct users to verify survey legitimacy by checking for unusual page layouts, disclaimers, and excessive empty space. IT teams should deploy web filtering policies that block access to known phishing URLs and monitor for unusual outbound traffic patterns indicative of phishing engagement. Employ multi-factor authentication to reduce the impact of credential compromise. Incident response plans should include procedures for rapid identification and containment of phishing incidents originating from trusted domains. Collaboration with survey platform providers to report abuse and request removal of fraudulent content can help reduce exposure. Finally, encourage users to verify survey requests through alternative communication channels before participation and avoid entering personal or financial information on unsolicited survey sites.
Affected Countries
Russia, United States, India, Brazil, Germany, United Kingdom, France, Italy, Spain, Mexico, South Africa, Australia, Japan, China, Turkey
How scammers use legitimate surveys to link to malicious sites | Kaspersky official blog
Description
Scammers are exploiting legitimate online survey platforms, specifically Yandex Surveys, to embed phishing links within seemingly authentic surveys. These fraudulent surveys bypass spam filters due to their use of reputable domains, tricking users into clicking links that lead to malicious sites, often involving crypto scams or dubious dating offers. Attackers use advanced techniques like invisible characters to hide disclaimers and navigation buttons, making the survey appear legitimate and focused solely on the scam content. Once victims engage, they are lured into prize schemes requiring payment or personal data submission, resulting in financial loss and credential theft. This method leverages free hosting and analytics provided by the survey platform, enabling large-scale, low-cost campaigns. Although Yandex Surveys is shutting down soon, the tactic highlights a growing trend of weaponizing trusted platforms for phishing. Organizations and users must remain vigilant, scrutinize unexpected emails even from trusted domains, and avoid interacting with suspicious surveys or links.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves scammers leveraging legitimate survey platforms, notably Yandex Surveys, to conduct phishing attacks by embedding malicious links within surveys that appear authentic. The attackers create surveys using Yandex's extended survey mode, replacing typical questions with text blocks containing scam pitches and embedded links to fraudulent websites. They enhance credibility by uploading official logos and images, often related to cryptocurrency exchanges, to lure victims. To conceal the survey's standard navigation elements and disclaimers, scammers insert invisible characters such as transparent emojis and punctuation marks to push these elements off-screen, ensuring victims only see the scam content. These surveys are then distributed via mass emails or hijacked website feedback forms, which lack sender verification, allowing the messages to bypass spam filters due to the legitimate yandex.com domain. Victims clicking the embedded links are directed to professional-looking scam sites, typically prize giveaways promising large cryptocurrency rewards but requiring upfront fees or personal information, leading to financial theft. The attackers benefit from free hosting and built-in analytics on the survey platform to track engagement and optimize campaigns. Although Yandex Surveys is scheduled to shut down shortly, this attack exemplifies a broader trend of abusing trusted platforms to evade detection and increase phishing success rates. The campaign has seen rapid scaling, with Kaspersky Premium blocking over 32,000 such emails in February 2026 alone, indicating aggressive expansion. The threat does not involve platform compromise but rather creative misuse of legitimate services, underscoring the need for heightened user awareness and advanced detection strategies.
Potential Impact
This phishing scheme poses significant risks to organizations and individuals worldwide by facilitating credential theft, financial fraud, and potential malware infections if victims interact with malicious payloads. The use of legitimate domains to host phishing content undermines traditional email filtering and web reputation systems, increasing the likelihood of successful attacks. Financial losses can be substantial, especially in cryptocurrency scams where victims pay fees or disclose wallet credentials. The campaign's scalability and low cost enable widespread distribution, potentially affecting large user bases across sectors. Organizations may face increased incident response costs, reputational damage, and regulatory scrutiny if employees fall victim. Additionally, the tactic erodes trust in legitimate survey platforms, complicating genuine marketing and research efforts. Although the immediate threat from Yandex Surveys will diminish after its shutdown, the underlying method of abusing trusted services for phishing is likely to persist and evolve, necessitating ongoing vigilance.
Mitigation Recommendations
Organizations should implement advanced email filtering solutions that incorporate behavioral and contextual analysis beyond domain reputation to detect phishing attempts using legitimate platforms. Security awareness training must emphasize skepticism toward unexpected emails, even those containing links to well-known domains, and instruct users to verify survey legitimacy by checking for unusual page layouts, disclaimers, and excessive empty space. IT teams should deploy web filtering policies that block access to known phishing URLs and monitor for unusual outbound traffic patterns indicative of phishing engagement. Employ multi-factor authentication to reduce the impact of credential compromise. Incident response plans should include procedures for rapid identification and containment of phishing incidents originating from trusted domains. Collaboration with survey platform providers to report abuse and request removal of fraudulent content can help reduce exposure. Finally, encourage users to verify survey requests through alternative communication channels before participation and avoid entering personal or financial information on unsolicited survey sites.
Technical Details
- Article Source
- {"url":"https://www.kaspersky.com/blog/spammers-use-yandex-polls-for-scam-and-phishing/55496/","fetched":true,"fetchedAt":"2026-03-26T10:01:29.946Z","wordCount":1581}
Threat ID: 69c503f9f4197a8e3b5009f5
Added to database: 3/26/2026, 10:01:29 AM
Last enriched: 3/26/2026, 10:01:44 AM
Last updated: 3/26/2026, 11:11:48 AM
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.