Instagram and TikTok comment sections flood with keh92 spam links
Instagram and TikTok Feed Comments Flood With keh92 Links
Social media users across France and Switzerland are encountering a massive wave of spam comments promoting suspicious URLs under posts by major media outlets, with Journal du Geek and Watson reporting coordinated drops of identical phrases that direct traffic to domains like keh92.com, keh92.fun, and tepu.lol.
-
The Tech TL;DR:
- Spam comments containing domains like keh92.com and tepu.lol are actively targeting comment sections on Instagram and TikTok.
- According to technical analysis by Paul Such of Swiss Post Cybersecurity, clicking these links leads to credential-harvesting phishing forms designed to steal user logins.
- Platforms and creators are combating the wave using automated keyword filtering and manual account reporting, while security firms flag the destination domains as high-risk.
The Mechanics of the keh92 and tepu.lol Spam Campaign
The infiltration relies on social engineering tactics, utilizing catchy hooks and sensational claims to lure curious users. Watson reported that commenters frequently state phrases like I wasn’t ready for keh92.com
or promise exclusive leaks regarding public figures such as Léa Elui, Shana, and Ovsie. Journal du Geek noted that the campaign accelerated sharply in late September 2026, with tepu.lol registered on September 17, keh92.com on September 28, and keh92.fun on September 29. When users visit these domains, the landing pages drive traffic toward a private Telegram channel boasting over 14,000 members. That channel subsequently distributes payment links, fake login interfaces, and malicious payloads designed for data theft.
Hijacked Accounts Bypass Automated Spam Filters
Unlike traditional botnets consisting of blank profiles, the accounts posting these comments possess established avatars, biographies, followers, and sometimes even Threads profiles. Paul Such, director of Swiss Post Cybersecurity, explained to Watson that these are legitimate user accounts previously hijacked by cybercriminals through credential stuffing attacks. Because the profiles have real histories, they bypass initial automated spam detection filters used by platforms like Instagram and TikTok, allowing the coordinated campaign to persist and spread.
Mitigation Strategies and Domain Verification Tools
Content creators and platform users are currently forced to handle the moderation workload manually or via platform filters. Journal du Geek outlined that Instagram’s hidden-words feature can block specific terms, though spammers bypass these filters by inserting invisible characters into the domains. Users can check suspicious domains via threat intelligence services like Flairsafe.ch, which flags keh92.com as carrying a high and potentially malicious risk. Security experts advise anyone who has interacted with these links to immediately update account passwords, enable multi-factor authentication, and report the offending accounts.
# Example command to check domain reputation and headers via CLI
curl -I https://keh92.com
nslookup keh92.com
Victims Must Revoke Sessions and Change Passwords
For individuals who have already fallen victim to the phishing scheme by submitting credentials into the fake forms, immediate remediation is required. Affected users must revoke active sessions across connected applications, alter passwords on any services sharing the same credentials, and notify contacts if automated messages begin broadcasting from their accounts. Confirmed platform breaches can be reported directly to local law enforcement or national cybersecurity authorities.
Disclaimer: The technical analyses and security protocols detailed in this article are for informational purposes only. Always consult with certified IT and cybersecurity professionals before altering enterprise networks or handling sensitive data.