Sockpuppet account creation, just like OSINT, is always changing. This page will be updated regularly. Please join the newsletter to be notified of updates.
What are sockpuppet accounts?
Sockpuppet accounts are anonymous or pseudonymous accounts used for various projects.
- In the news lately for political discord
- OSINT investigations
- HUMINT investigations
- Social engineering
- And more!
Are sockpuppet accounts ethical?
This is up to you. Honestly. But this is my blog so here’s my thoughts on it:
Sockpuppets, an an OSINT/HUMINT capacity, have generally been used in two ways:
- Passive reconnaissance. (Generally OSINT)
- Infiltration of groups. (Generally HUMINT)
I have absolutely no ethical qualms with using sockpuppet accounts for passive recon.
With HUMINT, infiltrating target groups is a common necessity. In this case, you often have to pretend to be someone you’re not.
For example, an investigator hired to collect data on a pedophilic ring on the dark web will have to create a persona and convince them they are one of them to get into the group.
I generally don’t do this sort of work. I would feel comfortable if I had law enforcement backing me in this because it could turn dangerous or illegal, and they’ll help me with making sure I’m not breaking any laws or getting into any trouble they can’t get me out of.
I also need to point out in the USA, it’s illegal to impersonate a government employee, especially law enforcement and military.
It’s also generally not cool to impersonate a real person. Keep your sockpuppets made-up.
Anonymous Sockpuppet Account Setup Process
This is my process for setting up an anonymous sockpuppet account.
- Come up with a persona for the sockpuppet account.
- Use Fake Name Generator to create a person whom you feel fits your sockpuppet persona.
- Use This Person Does Not Exist to generate an image. Make sure you inspect the image closely and get one that doesn’t have any obvious flaws, as they often do. It is worth picking up some Photoshop, GIMP, Affinity Photo or Designer, or other basic image manipulation skills to fix them and change the background of the image.
- Get a burner phone, completely wiped and fresh. Can be any brand that will accept a Mint Mobile SIM card.
- Get a burner credit card from Privacy.com to use for on Amazon and possible the Mint Mobile setup. They might need it to set up the account.
- Set up a burner Amazon account. We’re only going to use it once.
- Buy two Mint Mobile SIM cards. You can find them various places online and in stores near you, but you can get two of them for $5 on Amazon (aff). They also give you 1 week free trial with something like 100 text messages, which we’re going to use. This gives you two cards for two sockpuppet accounts for only $5.
- I like to use Amazon to have the card sent to an Amazon pickup box, which can be anonymous.
- Get a VPN that you can set to the physical area in which you want your sockpuppet to “exist.”
- Set up the Mint Mobile trial account somewhere away from your home; as far as you’re willing to go.
- Use this Mint Mobile trial phone number to set up all of the websites you need.
- I recommend at least set up a Google account and Protonmail account. Both will come in handy at different times.
- Once you’ve set up all the accounts with your trial Mint SIM, set up 2FA on all of the accounts.
- After setting up 2FA on all of the accounts, change the phone number to one you have more permanent access to, such as MySudo or Google Voice.
- Make sure everything works!
- Destroy the SIM card.
- Wipe the phone.
A lot of these websites are blocking MySudo, Google Voice, and other VoIP numbers. That’s why we go through the Mint phone number first.
They should be less stringent now.