How scammers use legitimate surveys to link to malicious sites | Kaspersky official blog
Spammers are disguising fraudulent links within legitimate survey platforms — emails containing these links easily bypass standard spam filters. We analyze the scheme, highlight the red flags, and provide defensive strategies.
AI Analysis
Technical Summary
This threat involves scammers leveraging legitimate survey platforms, notably Yandex Surveys, to conduct phishing attacks by embedding malicious links within surveys that appear authentic. The attackers create surveys using Yandex's extended survey mode, replacing typical questions with text blocks containing scam pitches and embedded links to fraudulent websites. They enhance credibility by uploading official logos and images, often related to cryptocurrency exchanges, to lure victims. To conceal the survey's standard navigation elements and disclaimers, scammers insert invisible characters such as transparent emojis and punctuation marks to push these elements off-screen, ensuring victims only see the scam content. These surveys are then distributed via mass emails or hijacked website feedback forms, which lack sender verification, allowing the messages to bypass spam filters due to the legitimate yandex.com domain. Victims clicking the embedded links are directed to professional-looking scam sites, typically prize giveaways promising large cryptocurrency rewards but requiring upfront fees or personal information, leading to financial theft. The attackers benefit from free hosting and built-in analytics on the survey platform to track engagement and optimize campaigns. Although Yandex Surveys is scheduled to shut down shortly, this attack exemplifies a broader trend of abusing trusted platforms to evade detection and increase phishing success rates. The campaign has seen rapid scaling, with Kaspersky Premium blocking over 32,000 such emails in February 2026 alone, indicating aggressive expansion. The threat does not involve platform compromise but rather creative misuse of legitimate services, underscoring the need for heightened user awareness and advanced detection strategies.
Potential Impact
This phishing scheme poses significant risks to organizations and individuals worldwide by facilitating credential theft, financial fraud, and potential malware infections if victims interact with malicious payloads. The use of legitimate domains to host phishing content undermines traditional email filtering and web reputation systems, increasing the likelihood of successful attacks. Financial losses can be substantial, especially in cryptocurrency scams where victims pay fees or disclose wallet credentials. The campaign's scalability and low cost enable widespread distribution, potentially affecting large user bases across sectors. Organizations may face increased incident response costs, reputational damage, and regulatory scrutiny if employees fall victim. Additionally, the tactic erodes trust in legitimate survey platforms, complicating genuine marketing and research efforts. Although the immediate threat from Yandex Surveys will diminish after its shutdown, the underlying method of abusing trusted services for phishing is likely to persist and evolve, necessitating ongoing vigilance.
Mitigation Recommendations
Organizations should implement advanced email filtering solutions that incorporate behavioral and contextual analysis beyond domain reputation to detect phishing attempts using legitimate platforms. Security awareness training must emphasize skepticism toward unexpected emails, even those containing links to well-known domains, and instruct users to verify survey legitimacy by checking for unusual page layouts, disclaimers, and excessive empty space. IT teams should deploy web filtering policies that block access to known phishing URLs and monitor for unusual outbound traffic patterns indicative of phishing engagement. Employ multi-factor authentication to reduce the impact of credential compromise. Incident response plans should include procedures for rapid identification and containment of phishing incidents originating from trusted domains. Collaboration with survey platform providers to report abuse and request removal of fraudulent content can help reduce exposure. Finally, encourage users to verify survey requests through alternative communication channels before participation and avoid entering personal or financial information on unsolicited survey sites.
Affected Countries
Russia, United States, India, Brazil, Germany, United Kingdom, France, Italy, Spain, Mexico, South Africa, Australia, Japan, China, Turkey
How scammers use legitimate surveys to link to malicious sites | Kaspersky official blog
Description
Spammers are disguising fraudulent links within legitimate survey platforms — emails containing these links easily bypass standard spam filters. We analyze the scheme, highlight the red flags, and provide defensive strategies.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves scammers leveraging legitimate survey platforms, notably Yandex Surveys, to conduct phishing attacks by embedding malicious links within surveys that appear authentic. The attackers create surveys using Yandex's extended survey mode, replacing typical questions with text blocks containing scam pitches and embedded links to fraudulent websites. They enhance credibility by uploading official logos and images, often related to cryptocurrency exchanges, to lure victims. To conceal the survey's standard navigation elements and disclaimers, scammers insert invisible characters such as transparent emojis and punctuation marks to push these elements off-screen, ensuring victims only see the scam content. These surveys are then distributed via mass emails or hijacked website feedback forms, which lack sender verification, allowing the messages to bypass spam filters due to the legitimate yandex.com domain. Victims clicking the embedded links are directed to professional-looking scam sites, typically prize giveaways promising large cryptocurrency rewards but requiring upfront fees or personal information, leading to financial theft. The attackers benefit from free hosting and built-in analytics on the survey platform to track engagement and optimize campaigns. Although Yandex Surveys is scheduled to shut down shortly, this attack exemplifies a broader trend of abusing trusted platforms to evade detection and increase phishing success rates. The campaign has seen rapid scaling, with Kaspersky Premium blocking over 32,000 such emails in February 2026 alone, indicating aggressive expansion. The threat does not involve platform compromise but rather creative misuse of legitimate services, underscoring the need for heightened user awareness and advanced detection strategies.
Potential Impact
This phishing scheme poses significant risks to organizations and individuals worldwide by facilitating credential theft, financial fraud, and potential malware infections if victims interact with malicious payloads. The use of legitimate domains to host phishing content undermines traditional email filtering and web reputation systems, increasing the likelihood of successful attacks. Financial losses can be substantial, especially in cryptocurrency scams where victims pay fees or disclose wallet credentials. The campaign's scalability and low cost enable widespread distribution, potentially affecting large user bases across sectors. Organizations may face increased incident response costs, reputational damage, and regulatory scrutiny if employees fall victim. Additionally, the tactic erodes trust in legitimate survey platforms, complicating genuine marketing and research efforts. Although the immediate threat from Yandex Surveys will diminish after its shutdown, the underlying method of abusing trusted services for phishing is likely to persist and evolve, necessitating ongoing vigilance.
Mitigation Recommendations
Organizations should implement advanced email filtering solutions that incorporate behavioral and contextual analysis beyond domain reputation to detect phishing attempts using legitimate platforms. Security awareness training must emphasize skepticism toward unexpected emails, even those containing links to well-known domains, and instruct users to verify survey legitimacy by checking for unusual page layouts, disclaimers, and excessive empty space. IT teams should deploy web filtering policies that block access to known phishing URLs and monitor for unusual outbound traffic patterns indicative of phishing engagement. Employ multi-factor authentication to reduce the impact of credential compromise. Incident response plans should include procedures for rapid identification and containment of phishing incidents originating from trusted domains. Collaboration with survey platform providers to report abuse and request removal of fraudulent content can help reduce exposure. Finally, encourage users to verify survey requests through alternative communication channels before participation and avoid entering personal or financial information on unsolicited survey sites.
Technical Details
- Article Source
- {"url":"https://www.kaspersky.com/blog/spammers-use-yandex-polls-for-scam-and-phishing/55496/","fetched":true,"fetchedAt":"2026-03-26T10:01:29.946Z","wordCount":1581}
Threat ID: 69c503f9f4197a8e3b5009f5
Added to database: 03/26/2026, 10:01:29 UTC
Last enriched: 03/26/2026, 10:01:44 UTC
Last updated: 07/31/2026, 13:29:31 UTC
Views: 443
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.