TBTrackerX: Fantastic Trigger Bots and Where to Find Malicious Campaigns on X

Mohammad Majid Akhtar

Network and Distributed System Security (NDSS) Symposium 2026 · Day 3 · Messaging Security

This research presents a systematic measurement and detection study of **trigger bots** on Twitter/X -- automated accounts that activate only when specific keywords appear in user posts or tweets. Unlike traditional social media bots that operate continuously, trigger bots lie dormant until triggered by keywords such as "MetaMask," "Robux," or other cryptocurrency and service-related terms, then flood the original post with deceptive replies designed to scam users.

AI review

A measurement study of keyword-triggered bots on Twitter/X that documents the phenomenon well but lacks technical depth. The honeypot methodology is straightforward, the detection boils down to XGBoost on 10 profile features, and the evasion analysis stays at the observation level without reverse engineering the actual bot infrastructure. The 38 BTC + 19 ETH theft figure comes from prior work, not this study.

Watch on YouTube