Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms
Xigao Li
Network and Distributed System Security (NDSS) Symposium 2024 · Day 2 · Platform Security
Overview
In an era dominated by vast digital media platforms like YouTube, the sheer volume of user engagement creates fertile ground for cybercriminals. This talk, "Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms," presented by Xigao Li, sheds critical light on the escalating menace of comment scams. These sophisticated social engineering attacks leverage script-controlled accounts to post enticing or misleading comments and replies, aiming to lure unsuspecting users into direct contact for fraudulent purposes, ranging from fake prize giveaways to high-yield investment schemes. The ultimate objective is financial exploitation, often facilitated through cryptocurrency transactions.

Key moments
- 0:00 Introduction to comment scams and research motivation
- 2:00 Understanding comment scam operations and social engineering tactics
- 2:30 Scammer evasion techniques: VSS, split scripts, impersonation
- 4:00 Comprehensive three-part research methodology overview
- 4:40 IRB-approved user study and blockchain financial tracking
- 6:00 System design for dynamic comment data collection
Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms
Speakers: Xigao Li
Conference: NDSS Symposium
YouTube: (no public video)
Overview
In an era dominated by vast digital media platforms like YouTube, the sheer volume of user engagement creates fertile ground for cybercriminals. This talk, "Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms," presented by Xigao Li, sheds critical light on the escalating menace of comment scams. These sophisticated social engineering attacks leverage script-controlled accounts to post enticing or misleading comments and replies, aiming to lure unsuspecting users into direct contact for fraudulent purposes, ranging from fake prize giveaways to high-yield investment schemes. The ultimate objective is financial exploitation, often facilitated through cryptocurrency transactions.
Despite the widespread prevalence and significant financial impact of these scams, the research community has historically lacked a systematic, large-scale investigation into their intricate ecosystem. While individual instances have been highlighted by content creators and media outlets, a comprehensive understanding of the tactics, techniques, and payment channels employed by scammers remained elusive. This gap has hampered the development of effective countermeasures. This paper and presentation by Xigao Li address this critical void, offering the first systematic, large-scale study to characterize comment scams, revealing their underlying mechanisms, evasion strategies, and devastating financial consequences.
The research not only quantifies the scale of the problem but also meticulously details the methodologies scammers employ to bypass existing platform defenses. By combining large-scale data collection, multi-modal detection filters, and an IRB-approved user study involving direct interaction with scammers, the work provides unprecedented insights. It underscores the urgent need for more robust platform-level interventions and enhanced user education to combat this pervasive and financially damaging form of cybercrime.
Background
[▶ Watch: Introduction to comment scams and research motivation (0:00)]()
Comment scams on large media platforms, particularly YouTube, operate as a multi-stage social engineering attack designed to defraud users. The initial phase is characterized by script-controlled programs that generate comments or replies. These comments, often appearing innocuous or highly appealing, aim to persuade users to initiate contact with the scammer outside the platform, typically via text messages (WhatsApp) or other messaging applications (Telegram), under the guise of offering free prizes or lucrative investment opportunities.
Scammers employ a diverse array of social engineering tactics to maximize their reach and credibility. A common method involves impersonation, where attackers copy a popular channel owner's profile image and name to post comments advertising fake personal contact information. This tactic preys on users' trust in established content creators. Another prevalent strategy involves posing as regular users, recommending a "successful investment advisor" who promises unrealistic returns, thereby creating a false sense of peer validation. Scammers also fabricate entire conversations, splitting their scripts into multiple segments posted by different accounts to simulate organic, positive interactions around the scam.
To evade platform detection mechanisms, scammers utilize sophisticated obfuscation techniques. A primary method is the use of visually similar symbols (VSS). Instead of standard ASCII characters, scammers substitute Unicode symbols that appear virtually identical to the human eye (e.g., using a Latin letter small capital M (U+1D0D) instead of a Latin capital letter M (U+004D)). This allows them to bypass keyword-based filters while maintaining legibility for human victims. While platforms like YouTube have introduced features such as checkmarks for authenticated channels, many inexperienced users remain susceptible to these impersonation attempts.
Once a user contacts the provided number or username, they enter the second, more direct phase of the scam. Here, the victim is defrauded through various means, most commonly fake investment schemes promising exorbitant returns or requests for "shipping fees" to deliver non-existent prizes.
This study builds upon prior research into social-bot activity and spam on YouTube, which primarily focused on self-promotion or malicious links. However, this work distinguishes itself by concentrating specifically on the social engineering aspects of comment scams, highlighting the direct engagement and manipulation of victims. Parallels can be drawn with technical support scams, which also utilize social engineering and phone numbers, but comment scams typically prefer text-based communication. This preference allows scammers to manage multiple victims simultaneously, significantly lowering their operational costs compared to voice-based interactions. Furthermore, comment scams are closely related to cryptocurrency scams, frequently preferring cryptocurrency payments due to the anonymity and irreversibility they offer. Unlike simple giveaway scams, comment scammers invest time in building confidence with victims before requesting funds, contributing to the longer lifespan and greater financial impact of their campaigns and infrastructure.
Key Findings
[▶ Watch: Scammer evasion techniques: VSS, split scripts, impersonation (2:30)]()
The systematic, large-scale investigation presented in this talk yielded several profound key findings that illuminate the scale, mechanics, and financial impact of comment scams:
- Pervasive Scale and Activity: Over a six-month period, the research identified 206,306 scam comments originating from 10,541 unique scammer accounts within a dataset of 8.8 million comments. On average, 1,140 new scam comments were posted daily, and approximately 58 new scammer accounts were created each day, demonstrating the high volume and continuous nature of these operations.
- Sophisticated Evasion Tactics: Scammers extensively employ various techniques to bypass detection. Visually Similar Symbols (VSS) were present in 81.89% of identified scam comments, while 80.94% included emojis. 45.56% of scammer accounts abused usernames for advertising, and 13.63% used profile images strikingly similar to channel owners, indicating targeted impersonation. Scripted conversations, identified by rapid-fire replies (mostly within 15 seconds), were also a common tactic.
- Targeting and Campaign Dynamics: While finance-related channels received the highest number of scam comments (148,070), popular channels across diverse categories like Cooking and News/Politics were also heavily targeted, indicating a broad and opportunistic targeting strategy. Large-scale campaigns were identified, with some involving over a hundred YouTube accounts promoting a single contact number or simultaneously targeting multiple channels.
- Ineffectiveness of Current Platform Defenses: Despite platforms' efforts, 59.87% of scam comments were deleted, mostly within one day. However, replies to regular users still resulted in permanent notifications, demonstrating a persistent impact even after deletion. Crucially, only 31.42% of scammer accounts were deactivated over the six-month study period, with some changing usernames up to 17 times, highlighting the successful evasion and longevity of scammer infrastructure.
- Direct Scammer Interaction Insights (IRB Study): An IRB-approved user study involving direct interaction with 50 scammers revealed that 76% conducted cryptocurrency investment scams, promising an average of 494.92% returns, while 22% ran fake prize scams (e.g., iPhones requiring shipping fees). Scammers were highly responsive (50% within one minute), polite and patient initially, but turned angry if payment was not received. They primarily operated between 2 PM and 3 AM Eastern Time.
- Preference for Cryptocurrency Payments: 76% of scammers preferred cryptocurrency payments, with digital payment platforms (PayPal, CashApp, Zelle) accounting for 22%. Investment websites provided by scammers were typically newly registered, used HTTPS, but crucially, each utilized a single cryptocurrency wallet address for all clients, a clear indicator of fraud. Blocklist coverage for these scam URLs was dismal, with only 1 out of 24 being flagged.
- Staggering Financial Impact: By tracking transactions on public blockchains (Bitcoin and Ethereum), the study accurately calculated that the 31 scammers from the user study alone had collectively stolen between $1.11M and $1.99M USD during the study period (67.64 BTC and 36.49 ETH). Over 1,901 Bitcoin and 85 Ethereum victim wallets were identified. While most victims paid under $5,000, some sent as much as $220,000, with average minimum investment deposits requested at $1,820 and shipping costs averaging $178.54.
Technical Deep Dive
[▶ Watch: Comprehensive three-part research methodology overview (4:00)]()
The research employed a robust, multi-faceted methodology to systematically characterize comment scams, primarily focusing on YouTube due to its dominant market share. This approach comprised three main components: longitudinal data collection, advanced scam detection filters, and an IRB-approved user study.
The foundation of the study was a meticulously designed and implemented modular system, depicted conceptually in Figure 2 of the paper. This system consists of three core modules:
- Crawl Module: Recognizing the dynamic nature of YouTube comments (creation, deletion, account status changes), a single data capture is insufficient. The Crawl Module addresses this by periodically collecting hourly snapshots of comments from various YouTube channels. It leverages the Google YouTube API to fetch comment text, associated profile images, and channel information. This continuous, snapshot-based collection is crucial for understanding the evolving tactics of scammers and the lifespan of their comments and accounts.
- Storage Module: All collected data, including comprehensive metadata such as comment creation time, user channel ID, and profile image, is stored in a structured database. This module segregates comments by channel, facilitating efficient processing and subsequent analysis. This rich dataset forms the backbone for identifying patterns indicative of scam activities.
- Analysis Module: This is where the core detection logic resides. It processes the stored comments to identify scam behavior using three distinct, iteratively refined filters:
- Text-based Filter: This filter targets textual characteristics indicative of scam activity. A primary focus is the detection of Visually Similar Symbols (VSS), a prevalent evasion technique where scammers substitute ASCII characters with Unicode equivalents (e.g.,
mwithᴍ). Through a snowball refining approach, the researchers identified over 40 different VSS alphabets used by scammers. The filter also looks for specific keywords commonly associated with scams (e.g., "investment," "prize," "WhatsApp," "Telegram") and explicit contact information like phone numbers or Telegram usernames. This filter proved to be the most effective overall, capturing 94.14% of identified scam comments. - Image-based Filter: Addressing the impersonation tactic, this filter focuses on graphical features. It utilizes perceptual hashing techniques (reference 27 in the paper) to generate unique hashes for both the comment author's profile image and the legitimate channel owner's profile image. A high similarity score between these hashes indicates an impersonation attempt. This filter was particularly effective in categories like Cooking and Gambling channels, capturing 13.63% of scam comments.
- Time-based Filter: This filter identifies scripted conversations, a tactic where scammers split their messages into multiple comments posted by different accounts to mimic natural, rapid-fire interactions. The researchers analyzed reply time intervals and defined a "session" as a group of comments with less than 15 seconds of inactivity between consecutive replies. This threshold was empirically chosen as most scam replies occur within this timeframe (as shown in Figure 8). These filtered conversations were then further refined using a keyword-based check to ensure they contained contact information. This filter captured 5.4% of scam comments, being more effective in Sports and News/Politics channels.
The filters were developed using a snowball refining approach, an iterative process of manually adjusting criteria to maximize scam comment identification while minimizing false positives. This ensured high accuracy, with only 2 (0.67%) false positives identified in a sample of 300 scam comments.
The system was deployed to monitor 20 YouTube channels (10 financial, 10 baseline from diverse categories) over a six-month period (October 1st, 2022, to March 31st, 2023). This comprehensive monitoring effort resulted in a massive dataset of 8.8 million individual comments, captured across 428,350 snapshots from 8,226 videos. The threat model specifically targeted automated scam comments aimed at luring users to unsolicited contact channels like WhatsApp or Telegram, with the ultimate goal of defrauding them through social engineering. The system was designed to counter scammers' constant adaptation to bypass YouTube's automated detection systems.
Finally, a crucial aspect of the methodology involved a quantitative analysis of stolen financial assets. By tracking transactions on publicly accessible blockchain networks (Bitcoin and Ethereum) using wallet addresses provided by scammers during the user study, the researchers could calculate the exact amount of funds stolen, moving beyond estimations and providing concrete evidence of financial harm.
Demo / Proof of Concept
[▶ Watch: IRB-approved user study and blockchain financial tracking (4:40)]()
While the talk did not feature a live software demonstration in the traditional sense, a significant and ethically approved "proof of concept" was conducted through an IRB-approved user study. This experiment involved direct interaction with 50 scammers, where researchers posed as unsuspecting victims through messaging applications like WhatsApp and Telegram. This unique approach allowed for invaluable, firsthand insights into the scammers' operational methodologies, social engineering tactics, and preferred payment channels that could not be gleaned from passive observation alone.
The user study yielded critical data points:
- Scam Schemes: Out of 50 completed conversations where scammers responded and requested payment, 76% (38) involved cryptocurrency investment scams, promising often unrealistic and exorbitant returns (averaging 494.92%, with some pledges up to 1300%). The remaining 22% (11) were fake prize scams, where victims were asked to pay "shipping fees" for valuable items like iPhones. One outlier scammer attempted to sell programming courses.
- Scammer Identities and Responsiveness: In fake prize scams, scammers invariably impersonated the channel owner. For crypto investment scams, they typically presented themselves as "investment advisors" or "brokers," often using generic trading images. Scammers were highly active, with 50% responding within one minute of initial contact, indicating constant monitoring of their communication channels. The median conversation length was 22 messages, with crypto scams tending to be slightly less verbose (median 19 messages) than fake prize scams (median 27 messages). Scammers were most active between 2 PM and 3 AM Eastern Time, suggesting operations from different time zones.
- Payment Channels and Fraudulent Infrastructure: A strong preference for cryptocurrency payments was observed, with 76% of scammers requesting funds via Bitcoin or Ethereum. The remaining 22% preferred digital payment platforms like PayPal, CashApp, or Zelle, and only one requested gift cards. Scammers consistently demanded screenshot verification of payments. The study investigated 24 URLs provided by scammers for their "investment platforms." Most were newly registered in 2022 (83.33%) and remained active for a median of 186.5 days. All used HTTPS, but only 20.83% implemented email verification. A crucial finding was that each website used a single cryptocurrency wallet address for all clients, a definitive sign of fraudulent activity. Furthermore, analysis with VirusTotal showed that only 1 out of 24 scam URLs was flagged as suspicious, underscoring the severe limitations of existing online blocklists.
- Financial Impact Quantification: By leveraging publicly accessible blockchain networks, the researchers tracked transactions to 47 cryptocurrency wallet addresses from 31 scammers identified in the user study. These scammers collectively received 67.64 BTC and 36.49 ETH, amounting to an estimated $1.11M to $1.99M USD during the study period. A staggering 93.5% of BTC wallets and 68.8% of ETH wallets had at least one incoming transaction, with average wallet ages of 227 days for BTC and 319 days for ETH, indicating established operations. The study identified 1,901 Bitcoin and 85 Ethereum wallet addresses belonging to victims. While most individual payments were under $5,000, some victims sent as much as $220,000.
- Scammer Demeanor: Scammers maintained a polite and patient demeanor initially, providing detailed investment plans and confidently addressing safety concerns, frequently requesting screenshots to guide victims. However, this shifted dramatically to anger or blame if payment was not received, with some even initiating phone or video calls to pressure victims. They also employed new accounts to re-engage with victims, demonstrating persistence.
This IRB-approved user study provided an unparalleled look into the "human" element of these automated scams, revealing the psychological tactics, financial mechanisms, and sheer scale of losses inflicted on victims, thereby serving as a compelling proof of concept for the scam's execution and impact.
Defensive Implications
[▶ Watch: System design for dynamic comment data collection (6:00)]()
The findings of this comprehensive study carry significant implications for defenders across multiple fronts, highlighting the urgent need for enhanced security measures on media platforms and improved user awareness. Current scam-detection mechanisms are demonstrably insufficient, necessitating a paradigm shift in approach.
Firstly, platform-level moderation tools must evolve beyond basic keyword matching and simple image comparisons. The research clearly demonstrates that scammers effectively evade these rudimentary defenses through techniques like Visually Similar Symbols (VSS), sophisticated impersonation, and splitting scripts into multiple comments. Future moderation systems should incorporate advanced textual analysis capable of detecting VSS and other obfuscation methods, leveraging the extensive VSS alphabets identified in this study. Furthermore, perceptual hashing for image analysis should be integrated more deeply to identify impersonation attempts, not just for channel owners but also for common scammer profiles. Temporal analysis, as demonstrated by the time-based filter, is crucial for flagging rapid-fire, scripted conversations that mimic organic interactions. These multi-modal detection capabilities, combining textual, graphical, and temporal features, are essential for identifying and flagging suspicious comments for human review or automated takedown.
Secondly, fundamental platform changes are required to disrupt the scammer infrastructure at its root. The observed longevity of scammer accounts (only 31.42% deactivated over six months) and the ability to acquire and maintain thousands of script-controlled accounts point to weaknesses in account creation and bot detection. Platforms should implement stricter account creation policies, potentially incorporating multi-factor authentication or more rigorous identity verification for new accounts, especially those exhibiting bot-like behavior. Enhanced bot detection algorithms that go beyond simple rate limiting, perhaps using behavioral analytics and network-level indicators, are vital. More aggressive and proactive account deactivation policies for suspicious activity, such as rapid comment posting, VSS usage, or repeated contact information dissemination, are also necessary to reduce the lifespan of scammer accounts.
Thirdly, client-side protections and robust user education are paramount. While platform-side improvements are critical, users remain the ultimate target. Educational campaigns should explicitly detail common scam tactics, including the use of VSS, impersonation, fake investment promises, and requests for shipping fees. Users need clear guidance on how to identify and report suspicious comments, emphasizing that legitimate offers rarely require contacting third-party numbers or paying upfront fees for "prizes." The development of browser extensions or integrated platform features that can flag suspicious comments in real-time could provide an additional layer of defense for users. These tools could leverage the detection logic developed in this research to highlight potentially fraudulent comments before users engage with them.
Finally, the study underscores the need for fast takedown mechanisms for identified scam campaigns. Even when scam comments are deleted, the persistent notifications to users highlight the lasting impact. Platforms need to streamline the process for users and researchers to report scams, ensuring that identified fraudulent content and accounts are swiftly removed to minimize exposure and potential harm. The dismal blocklist coverage of scam investment URLs (only 1 out of 24 flagged) also points to a broader industry need for better threat intelligence sharing and proactive blacklisting of known scam infrastructure.
Key Takeaways
- Comment Scams are a Pervasive and Financially Devastating Threat: The study identified over 200,000 scam comments from 10,000+ unique accounts in six months, demonstrating a massive, ongoing operation. A small sample of 31 scammers alone stole over $1.1 million USD, highlighting the significant financial impact on victims.
- Scammers Employ Sophisticated Evasion Tactics: Attackers extensively use techniques like Visually Similar Symbols (VSS) (81.89% of scam comments), targeted impersonation (13.63%), and scripted, rapid-fire conversations to bypass existing keyword-based and simple image-matching detection systems.
- Current Platform Defenses are Insufficient: Despite platform efforts, scammer accounts exhibit high longevity (only 31.42% deactivated), and deleted scam comments still leave persistent notifications, indicating that current moderation tools are failing to curb abuse effectively.
- Cryptocurrency is the Preferred Payment Channel: The majority of scammers (76%) prefer cryptocurrency payments due to their anonymity, making financial tracking challenging but not impossible. Fraudulent investment websites consistently use single wallet addresses for all "clients," a clear red flag.
- Multi-Modal Detection is Essential: Effective scam detection requires a combination of textual (VSS, keywords), graphical (perceptual hashing for impersonation), and temporal (rapid-fire replies for scripted conversations) analysis, as demonstrated by the study's highly accurate filters.
- Urgent Need for Platform and User-Side Interventions: Platforms must implement more sophisticated moderation tools, stricter account creation policies, and aggressive bot detection. Concurrently, comprehensive user education and client-side protections are crucial to empower individuals to identify and avoid these increasingly prevalent scams.
About the Speaker(s)
The talk "Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms" was presented by Xigao Li. Based on the provided metadata and transcript, specific details regarding Xigao Li's title or company affiliation were not included.
All talks from Network and Distributed System Security (NDSS) Symposium 2024