@ZySoua I think it's automated... Here's what I think happens: Malware author uses Mastodon account for C&C. Malware analytics service runs malware and tracks which connections it makes, publishes public report. Mastodon domain / IP is in list of connections, gets picked up by Spamhaus.
@Gargron You still should be aware. This is now started happening more often