Abstract
Malicious actors on online social networks (OSNs) use script-controlled social bots that engage users through replies or comments. These bots are programmed to activate only when specific trigger keywords appear in posts. We refer to such advanced context-aware campaigners as trigger bots (TB) agents, which aim to deceive users into making payments for illicit products or revealing sensitive financial credentials. This paper presents a systematic and data-driven study on the detection and characterization of TB agents. We introduce TBTrackerX, a novel framework designed to collect and analyze TB activity. Using this system, we captured 4,452 TB agent replies from 2,647 unique TB agents, targeting our honeypot account, and uncovered interactions with over 84K users on X. Our results show that TB agents evade detection by using contextually similar replies (with similarity scores up to 0.97), exhibiting intermittent posting patterns (in bursts ranging from 15 seconds to 5 minutes), and adopting dormant behavior after peak campaign activity. Furthermore, we identify a coordinated TB ecosystem, characterized by fake TB followers and shared TB masters. This study underscores the pressing need for better moderation and detection mechanisms to combat these sophisticated forms of social media manipulation.
| Original language | English |
|---|---|
| Number of pages | 20 |
| Publication status | Submitted - 15 Aug 2025 |
| Event | Network and Distributed System Security - Wyndham San Diego Bayside, San Diego, United States Duration: 23 Feb 2026 → 27 Feb 2026 Conference number: 33 https://www.ndss-symposium.org/ndss2026/ |
Conference
| Conference | Network and Distributed System Security |
|---|---|
| Abbreviated title | NDSS |
| Country/Territory | United States |
| City | San Diego |
| Period | 23/02/26 → 27/02/26 |
| Internet address |
Fingerprint
Dive into the research topics of 'TBTrackerX: fantastic trigger bots and where to find malicious campaigns on X'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver