Pith. sign in

REVIEW 3 major objections 5 minor 42 references

An Exploratory Study of Malicious Link Posting on Social Media Applications

T0 review · 3 major / 5 minor · reviewed 2026-07-11 · grok-4.5

Pith's one-line read Most top Android social apps let verified phishing links be posted with little or no blocking.

desk verdict Clean, small-N pilot that shows four of five popular Android social apps block almost no verified phishing URLs at post time; useful snapshot, not a new attack or defense. read the letter →

arxiv 2607.04042 v1 pith:H2ZNWKBV submitted 2026-07-04 cs.SI cs.CR

classification cs.SIcs.CR
keywords maliciousURLsphishingsocialmediasecuritylinksharingAndroidappsURLfilteringusablePhishTank
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This exploratory study tests whether the five most popular Android social apps actually stop users from sharing known malicious links. Researchers created throwaway accounts, drew 35 phishing URLs from PhishTank over three months, double-checked them with Google Safe Browsing and VirusTotal, and tried to post both the original URLs and shortened redirect versions. TikTok, Instagram and Mastodon accepted every original link; Facebook blocked only a handful and those were easily bypassed with redirects; only Twitter blocked a substantial share (about 69 percent of its attempts). Overall just 23.8 percent of the harmful links were stopped. The paper therefore claims that everyday link-sharing features on these platforms constitute a real, usable attack surface that attackers or careless users can exploit, and that platform security design has not kept pace with that risk.

What carries the argument

A controlled posting pipeline: sample five PhishTank URLs every two weeks for three months, re-verify each with Safe Browsing and VirusTotal, attempt to post the original URL from a private test account, and, only if blocked, re-post a TinyURL redirect of the same destination. Success or failure of each post is the measured outcome.

What would settle it

Re-run the identical sampling and posting protocol on the same five apps today (or on a larger set of URLs) and record whether the block rates for original and redirected links remain as low as the 2022 figures; any large rise in blocking would falsify the claim of systemic weakness.

Watch

Extended reading notes

Core claim

When verified phishing URLs drawn from PhishTank are posted on the five highest-ranked Android social apps, the large majority are accepted: only Twitter performs meaningful blocking, and the aggregate block rate across all apps and both original and redirected forms is just 23.8 percent. The study therefore concludes that most of these platforms lack an effective defense against the posting and spreading of malicious links.

Load-bearing premise

A single post-time check of 35 already-flagged phishing URLs is treated as a fair proxy for each platform's real filtering behavior, including any later removal or differences between profile posts and private messages.

Editorial extensions

If this is right

  • Attackers can currently seed phishing or malware links on TikTok, Instagram and Mastodon with near-certainty of successful posting.
  • Even the modest blocking present on Facebook is defeated by ordinary URL shorteners, so redirect chains remain an open bypass.
  • Google Play Store malware-policy language is not strong enough to force apps to stop the spread of known-bad URLs.
  • Usable-security redesigns that preserve link-sharing while still intercepting known-malicious destinations are still needed.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same low post-time filtering likely extends to other high-traffic platforms not in the top-five list, widening the practical attack surface.
  • Retroactive deletion of already-posted links, if it occurs at all, arrives after the window of highest engagement and therefore does little to reduce initial harm.
  • A public, continuous monitoring dashboard that re-tests the same pipeline weekly could pressure platforms to close the gap without waiting for new regulation.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper reports an exploratory measurement of post-time filtering of known malicious URLs on five Android social apps (TikTok, Instagram, Twitter, Facebook, Mastodon). Over seven dates spanning three months the authors sample 35 PhishTank URLs, dual-validate them with Google Safe Browsing and VirusTotal, create isolated test accounts, and attempt to post each original URL (plus a TinyURL redirection if the original is blocked). Tables II–IV and the appendix show that TikTok, Instagram and Mastodon blocked none of the 35 originals, Facebook blocked four (~10 %), and Twitter blocked the large majority of both originals and redirections (~69 %), yielding an overall block rate of 23.8 % driven almost entirely by Twitter. The authors conclude that most of the examined platforms lack effective defenses against malicious-link posting, discuss security–usability trade-offs, and list several limitations as future work.

Significance. If the modest claim holds, the work supplies concrete, previously sparse evidence that several high-install social platforms perform little or no real-time filtering of known phishing URLs at the moment of posting. That observation is directly relevant to usable-security design, platform policy, and the residual attack surface for link-based social-engineering. Credit is due for the transparent pipeline (Fig. 1), dual external black-list validation, ethical isolation of test accounts, and the fully tabulated per-app/per-date outcomes that let a reader verify the headline numbers. As explicitly labeled pilot work the study usefully surfaces a measurement gap rather than claiming a definitive audit.

major comments (3)
  1. [§III-C, §IV, Tables II–III] §III-C, §IV and Tables II–III: the central claim that most apps ‘did not have an effective defense against the posting and spreading’ of malicious URLs rests solely on one-time post-time checks of 35 URLs. The authors themselves flag in §VI that retroactive removal and profile-versus-DM differences were never measured. Without those data the stronger language of ‘spreading’ and of ‘non-existent’ defenses for three apps is not fully supported; either the experiment must be extended or the conclusions must be substantially qualified to the post-time window actually observed.
  2. [§III-B] §III-B: the two-week sampling gap is presented as sufficient for platforms to have ingested the latest blacklist entries, yet no evidence is offered that the five apps consult PhishTank, Safe Browsing or VirusTotal, nor that they update on that cadence. This untested assumption underpins the inference that non-blocking equals inadequate defense rather than delayed or alternative detection; it should be either validated or removed as a load-bearing premise.
  3. [Table III, §IV-A] Table III and §IV-A: the headline 23.8 % block rate is almost entirely Twitter’s contribution (46 of the blocked instances). Aggregating without stronger per-app emphasis or simple statistical context risks overstating uniformity of the vulnerability across ‘most’ platforms; the discussion should more carefully separate Twitter’s relatively robust behavior from the near-zero rates of the other four apps.
minor comments (5)
  1. [Abstract] Title and abstract: ‘that usability into account’ is missing a verb; several other sentences in the abstract and introduction contain missing articles or run-on constructions.
  2. [§III, Table III] Section heading ‘METHODOLGY’ is misspelled; Table III header ‘EVLUATIONMATRIX’ is likewise misspelled and inconsistently capitalized.
  3. [Tables II–IV] Inconsistent orthography of ‘Redirectional’ / ‘redirectional’ / ‘transformed’ throughout Tables II–IV and the text; pick one term and use it uniformly.
  4. [Fig. 1] Fig. 1 caption and body text contain several typographic glitches (‘InProcess1&2we’, ‘createtransformedversion’, missing spaces). Clean for camera-ready.
  5. [§I] Introduction: ‘for personally identifiable informationPIIssuch’ lacks spaces and punctuation; similar concatenation errors appear elsewhere.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: purely observational measurement of external blacklists against five apps; no fitted parameters, self-definitions, or load-bearing self-citations.

full rationale

The paper is an exploratory empirical study. Its central claim (most of the five Android social apps lack effective post-time defenses against verified phishing URLs; only 23.8 % of the tested links were blocked, almost all by Twitter) is obtained by (1) sampling 35 URLs from the external PhishTank database at two-week intervals, (2) re-validating them with Google Safe Browsing and VirusTotal, (3) posting the original and (when blocked) TinyURL-shortened versions from test accounts, and (4) counting successes/failures in Tables II–IV and the appendix. None of these steps defines a quantity in terms of itself, fits a free parameter that is later re-labeled a prediction, or rests on a uniqueness theorem or ansatz imported from the authors’ prior work. The few self-citations that appear (e.g., [32], [34], [40]) are background or related-work references and are not load-bearing for the numerical result. The authors themselves label the work “exploratory/pilot” and list the obvious sampling limitations (post-time only, profile vs. DM, no retroactive checks) as future work; those limitations affect external validity, not circularity. Consequently the derivation chain is self-contained against external benchmarks and scores 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The central claim rests only on standard empirical assumptions of security measurement; no free parameters are fitted and no new theoretical entities are introduced.

assumptions (3)
  • domain assumption URLs flagged by PhishTank and confirmed by Google Safe Browsing plus VirusTotal are treated as ground-truth malicious for the purpose of the experiment.
    Stated in §III-B; the entire blocked/posted metric depends on this external oracle.
  • ad hoc to paper A two-week sampling gap is long enough for platforms to have ingested the latest blacklist entries.
    Explicit design choice in §III-B; if false, the measured block rates would understate true filtering capability.
  • domain assumption Test-account posting behavior is representative of ordinary user posting for the purpose of measuring filter presence.
    Implicit throughout §III-C; platforms may apply different rules to new or low-reputation accounts.

how reviews work

0 comments
Cite this review

Pith. "Pith review of An Exploratory Study of Malicious Link Posting on Social Media Applications." pith.science (2026). https://pith.science/paper/H2ZNWKBV

@misc{pith2026260704042,
  author       = {Pith},
  title        = {Pith review of: An Exploratory Study of Malicious Link Posting on Social Media Applications},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/H2ZNWKBV}},
  note         = {Machine review of arXiv:2607.04042}
}
read the original abstract

Social network platforms are now widely used as a mode of communication globally due to their popularity and their ease of use. Among the various content-sharing capabilities made available via these applications, link-sharing is a common activity among social media users. While this feature provides a desired functionality for the platform users, link sharing enables attackers to exploit vulnerabilities and compromise users' devices. Attackers can exploit this content-sharing feature by posting malicious/harmful URLs or deceptive posts and messages which are intended to hide a dangerous link. However, it is not clear how the most common social media applications monitor and/or filter when their users share malicious URLs or links through their platforms. To investigate this security vulnerability, we designed an exploratory study to examine the top five android social media applications' performance when it comes to malicious link sharing. The aim was to determine if the selected applications had any filtering or defenses against malicious URL sharing. Our results show that most of the selected social media applications did not have an effective defense against the posting and spreading of malicious URLs. While our results are exploratory, we believe our study demonstrates the presence of a vital security vulnerability that malicious attackers or unaware users can use to spread harmful links. In addition, our findings can be used to improve our understanding of link-based attacks as well as the design of security measures that usability into account.

Figures

Figures reproduced from arXiv: 2607.04042 by the authors.

Figure 1
Figure 1. Design and workflow of our pipeline. In Process 1 & 2 we collect flagged URLs from PhishTank and verify them being harmful from Google Safe Browsing and Virus Total. Next, we create transformed version of every original link and store them in Process 3 and post using the test accounts at Process 4. heuristic link analysis have been proposed and employed by social networks to mitigate these threats. Jiwon Hong et. al… view at source ↗

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

42 extracted references · 1 linked inside Pith

  1. [1]

    https://www.phishing.org/phishing-examples

    Phishing examples. https://www.phishing.org/phishing-examples

  2. [2]

    https://www.bbc.com/news/technology-53607374

    Twitter hack: Staff tricked by phone spear-phishing scam. https://www.bbc.com/news/technology-53607374

  3. [3]

    Cyber security in mobile social networks

    Fadi Al-Turjman and Ramiz Salama. Cyber security in mobile social networks. InSecurity in IoT Social Networks, pages 55–81. Elsevier, 2021

  4. [4]

    Security in social-media: Awareness of phishing attacks techniques and countermeasures

    Amera Alharbi, Afnan Alotaibi, Lujain Alghofaili, Mona Alsalamah, Nora Alwasil, and Salim Elkhediri. Security in social-media: Awareness of phishing attacks techniques and countermeasures. In2022 2nd International Conference on Computing and Information Technology (ICCIT), pages 10–16. IEEE, 2022

  5. [5]

    Civility and trust in social media.Journal of Economic Behavior & Organization, 160:83–99, 2019

    Angelo Antoci, Laura Bonelli, Fabio Paglieri, Tommaso Reggiani, and Fabio Sabatini. Civility and trust in social media.Journal of Economic Behavior & Organization, 160:83–99, 2019

  6. [6]

    Phishing activity trends report 2nd quarter 2022

    APWG. Phishing activity trends report 2nd quarter 2022. url- https://apwg.org/trendsreports/, 2022

  7. [7]

    Less is more: quantifying the security benefits of debloating web applications

    Babak Amin Azad, Pierre Laperdrix, and Nick Nikiforakis. Less is more: quantifying the security benefits of debloating web applications. In28th USENIX Security Symposium (USENIX Security 19), pages 1697–1714, 2019

  8. [8]

    Social engineering: revisiting end-user awareness and susceptibility to classic attack vectors

    Taimur Bakhshi. Social engineering: revisiting end-user awareness and susceptibility to classic attack vectors. In2017 13th International Conference on Emerging Technologies (ICET), pages 1–6. IEEE, 2017

Show all 42 references
  1. [9]

    Susanne Barth, Menno DT de Jong, Marianne Junger, Pieter H Hartel, and Janina C Roppelt. Putting the privacy paradox to the test: Online privacy and security behaviors among users with technical knowledge, privacy awareness, and financial resources.Telematics and informatics, ...

  2. [10]

    An analysis of phishing blacklists: Google safe browsing, openphish, and phishtank

    Simon Bell and Peter Komisarczuk. An analysis of phishing blacklists: Google safe browsing, openphish, and phishtank. InProceedings of the Australasian Computer Science Week Multiconference, pages 1–11, 2020

  3. [11]

    L. Ceci. Whatsapp global unique users 2022. https://www.statista.com/statistics/1306022/whatsapp-global-unique- users/

  4. [12]

    Mobile fact sheet

    Pew Research Center. Mobile fact sheet. url=https://www.pewresearch.org/internet/fact-sheet/social-media/, 2021

  5. [13]

    Usability, security and trust in password managers: A quest for user-centric properties and features.Computer Science Review, 33:69– 90, 2019

    Sunil Chaudhary, Tiina Schafeitel-T ¨ahtinen, Marko Helenius, and Eleni Berki. Usability, security and trust in password managers: A quest for user-centric properties and features.Computer Science Review, 33:69– 90, 2019

  6. [14]

    A sur- vey of phishing attacks: Their types, vectors and technical approaches

    Kang Leng Chiew, Kelvin Sheng Chek Yong, and Choon Lin Tan. A sur- vey of phishing attacks: Their types, vectors and technical approaches. Expert Systems with Applications, 106:1–20, 2018

  7. [15]

    J. Clement. Facebook mau worldwide 2020. https://www.statista.com/statistics/264810/number-of-monthly-active- facebook-users-worldwide/

  8. [16]

    S. Dixon. Social sharing - statistics & facts. https://www.statista.com/topics/2539/social-sharing/

  9. [17]

    Twitter mdau in the united states 2022

    S Dixon. Twitter mdau in the united states 2022. https://www.statista.com/statistics/970911/monetizable-daily-active- twitter-users-in-the-united-states/

  10. [18]

    friends:

    Nicole B Ellison, Charles Steinfield, and Cliff Lampe. The benefits of facebook “friends:” social capital and college students’ use of online social network sites.Journal of computer-mediated communication, 12(4):1143–1168, 2007

  11. [19]

    Android permissions: User attention, com- prehension, and behavior

    Adrienne Porter Felt, Elizabeth Ha, Serge Egelman, Ariel Haney, Erika Chin, and David Wagner. Android permissions: User attention, com- prehension, and behavior. InProceedings of the eighth symposium on usable privacy and security, pages 1–14, 2012

  12. [20]

    Fake person generator- faq

    Fake Person Generator. Fake person generator- faq. https://www.fakepersongenerator.com/Site/faq

  13. [21]

    Coordi- nated link sharing behavior as a signal to surface sources of problematic information on facebook

    Fabio Giglietto, Nicola Righetti, Luca Rossi, and Giada Marino. Coordi- nated link sharing behavior as a signal to surface sources of problematic information on facebook. InInternational Conference on Social Media and Society, pages 85–91, 2020

  14. [22]

    Phishing url detection with lexical features and blacklisted domains

    Jiwon Hong, Taeri Kim, Jing Liu, Noseong Park, and Sang-Wook Kim. Phishing url detection with lexical features and blacklisted domains. In Adaptive autonomous secure cyber systems, pages 253–267. Springer, 2020. 6

  15. [23]

    No}one can hack my {Mind

    Iulia Ion, Rob Reeder, and Sunny Consolvo.{“... No}one can hack my {Mind”}: Comparing expert and{Non-Expert}security practices. In Eleventh Symposium On Usable Privacy and Security (SOUPS 2015), pages 327–346, 2015

  16. [24]

    Advertising content and consumer engagement on social media: Evidence from facebook.Management Science, 64(11):5105–5131, 2018

    Dokyun Lee, Kartik Hosanagar, and Harikesh S Nair. Advertising content and consumer engagement on social media: Evidence from facebook.Management Science, 64(11):5105–5131, 2018

  17. [25]

    A critical genre analysis of covert advertising through short-videos in douyin: The chinese version of tik-tok.SAGE Open, 12(4), 2022

    Dongmei Li, Ung T’chiang Chow, and Cecilia Yin Mei Cheong. A critical genre analysis of covert advertising through short-videos in douyin: The chinese version of tik-tok.SAGE Open, 12(4), 2022

  18. [26]

    Google safe browsing

    Google LLC. Google safe browsing. https://safebrowsing.google.com/

  19. [27]

    The future development of e-commerce in tiktok

    Jianyu Ma and Siwei Yu. The future development of e-commerce in tiktok. In2021 International Conference on Public Relations and Social Sciences (ICPRSS 2021), pages 241–246. Atlantis Press, 2021

  20. [28]

    With twitter in chaos, mastodon is on fire — cnn business, Nov 2022

    Rachel Metz. With twitter in chaos, mastodon is on fire — cnn business, Nov 2022

  21. [29]

    Framing and counter-framing a peace march in russia: the use of twitter during a hybrid war.Social Movement Studies, 18(5):602–621, 2019

    Olena Nikolayenko. Framing and counter-framing a peace march in russia: the use of twitter during a hybrid war.Social Movement Studies, 18(5):602–621, 2019

  22. [30]

    Us- ability analysis of shared device ecosystem security: informing support for survivors of iot-facilitated tech-abuse

    Simon Parkin, Trupti Patel, Isabel Lopez-Neira, and Leonie Tanczer. Us- ability analysis of shared device ecosystem security: informing support for survivors of iot-facilitated tech-abuse. InProceedings of the new security paradigms workshop, pages 1–15, 2019

  23. [31]

    Michael Rubin. Evolution of iranian surveillance strategies toward the internet and social media.The Digital Age, Cyber Space, and Social Media The Challenges of Security & Radicalization, page 191, 2020

  24. [32]

    To- wards characterizing covid-19 awareness on twitter.arXiv preprint arXiv:2005.08379, 2020

    Muhammad Saad, Muhammad Hassan, and Fareed Zaffar. To- wards characterizing covid-19 awareness on twitter.arXiv preprint arXiv:2005.08379, 2020

  25. [33]

    Shafahi, L

    M. Shafahi, L. Kempers, and H. Afsarmanesh. Phishing through social bots on twitter. In2016 IEEE International Conference on Big Data (Big Data), 2016

  26. [34]

    Phishing email detection method: Leveraging data across different organizations

    Tanusree Sharma, Priscilla Ferronato, and Masooda Bashir. Phishing email detection method: Leveraging data across different organizations. 2021

  27. [35]

    A survey of trust in social networks.ACM Computing Surveys (CSUR), 45(4):1–33, 2013

    Wanita Sherchan, Surya Nepal, and Cecile Paris. A survey of trust in social networks.ACM Computing Surveys (CSUR), 45(4):1–33, 2013

  28. [36]

    PhD thesis, 2020

    Jason Sibrian.Sensitive Data? Now That’s a Catch! the Psychology of Phishing. PhD thesis, 2020

  29. [37]

    Deceptive previews: A study of the link preview trustworthiness in social platforms

    Giada Stivala and Giancarlo Pellegrino. Deceptive previews: A study of the link preview trustworthiness in social platforms. 2020

  30. [38]

    Thispersondoesnotexist

    ThisPersonDoesnotExist. Thispersondoesnotexist. https://thispersondoesnotexist.com/

  31. [39]

    Virustotal - how it works

    VirusTotal. Virustotal - how it works. https://support.virustotal.com/hc/en-us/articles/115002126889-How- it-works

  32. [40]

    Gaming apps’ and social media partnership: A privacy perspective

    Tian Wang and Masooda Bashir. Gaming apps’ and social media partnership: A privacy perspective. InHCI for Cybersecurity, Privacy and Trust: Third International Conference, HCI-CPT 2021, Held as Part of the 23rd HCI International Conference, HCII 2021, Virtual Event, July 24–29...

  33. [41]

    Mobile banking: evolution and threats: malware threats and security solutions

    Mohammad Wazid, Sherali Zeadally, and Ashok Kumar Das. Mobile banking: evolution and threats: malware threats and security solutions. IEEE Consumer Electronics Magazine, 8(2):56–60, 2019

  34. [42]

    The importance of trending topics in the gatekeeping of social media news engagement: A natural experiment on weibo.Communication Research, 49(7):994–1015, 2022

    Tian Yang and Yilang Peng. The importance of trending topics in the gatekeeping of social media news engagement: A natural experiment on weibo.Communication Research, 49(7):994–1015, 2022. VIII.APPENDIX 7 TABLE IV RESULTS OFORIGINAL ANDREDIRECTIONAL(Transformed) MALICIOUSURLS ...

Pith tools

Reviewed July 11, 2026 · model on record in the stance chip above.