Well-Mannered Bots Deceive More: Surfshark Study Reveals New Social Threats

The most effective bots in social engineering are those with polite and positive manners, not aggressive accounts. This is what emerges from a Surfshark study that analyzed the ability of 1,722 global users to distinguish human comments from AI-generated ones in social media contexts. The overall detection rate stood at a concerning 40%.

Quick Answer

The most difficult bots to identify are the positive and reasonable ones, with only a 38% detection rate. Aggressive bots are recognized in 50.2% of cases. Users over 50 have the lowest detection ability, with higher error rates in reporting human accounts as bots.

Positive Bots: 80% Evasion

Luís Costa, Research and Insights Lead at Surfshark, explains that in the tests, participants identified only 38% of the bots with a positive tone, compared to 50.2% of the aggressive ones. This 12% difference suggests that users have more difficulty recognizing accounts that adopt friendly and logical behavior.

Sophisticated Manipulation: When Bots Go Unnoticed

Costa highlights a concerning phenomenon: the most dangerous bots are those that seem to support real opinions, artificially amplifying consensus on certain positions. These "invisible" accounts are rarely reported, allowing more effective manipulation campaigns compared to aggressive accounts that are more easily identified.

The Distorting Effect on Serious Topics

The study found that users identify more bots in light discussions (such as the one about pineapple pizza) compared to serious topics like women's rights. In the latter cases, not only are fewer bots detected, but more false positives also occur, reporting human accounts as bots. The exception is represented by the topic of immigration, where positive bots are the most difficult to identify.

Emoji: The Revealing Signal

A relevant technical detail emerges from the use of emoji: bots that overuse them are detected in 60% of cases, while those with plain language only in 35%. This suggests that a simple change in a bot's behavior - such as reducing the use of emoji - can halve the chances of being identified.

Security Risks: When Bots Seem Human

The researchers warn that friendly and logical bots pose a greater threat than aggressive ones. These accounts do not raise suspicions and can induce users to share personal information, click on suspicious links, or accept arguments without adequately evaluating the source. This phenomenon is particularly concerning in contexts of political or social manipulation.

Key Factors: Platform, Age, and Habits

The detection ability varies significantly based on the platform used. Threads users (text-based) showed the highest detection rates, closely followed by X users. TikTok and Facebook, however, show lower performance. Age is another determining factor: detection ability peaks among the youngest, progressively decreasing until the over 50s, who also show the highest error rates.

The Impact of Usage Habits

The study reveals that the most active social media users (those who use them "almost always") identify about half of the bots they are exposed to. In contrast, those who do not use social media at all only detect a third of the bots. This suggests that greater exposure could develop a certain sensitivity, even if not sufficient to effectively counter the threat.

Implications for Cyber Insurance

These results have important implications for the cyber insurance sector. Cyber risk policies may need to include specific coverage for attacks based on friendly bots, which represent a growing threat for companies that use social media for marketing or customer service. The incident response will need to evolve to address this type of sophisticated threat.

The Role of Managed SOC

For organizations, protection against these bots requires a proactive approach. A Managed Security Operations Center (Managed SOC) could implement advanced Managed Detection and Response (MDR) and Identity Access Management (IAM) solutions to identify and mitigate these threats. The NIS2 compliance and the DORA regulation may require additional measures to counter these attacks.

Future Perspectives

The Surfshark study underscores the urgency of developing new detection technologies and user education methods. Social platforms will need to implement more sophisticated algorithms to identify these bots, while users will need to be trained to recognize revealing signals. Ransomware protection and other cybersecurity measures will need to adapt to this new threat.

See Also

To learn more about incident response strategies and Managed Security Operations Center solutions, consult our specialized guides.

The Technical Vulnerabilities Behind "Invisible" Bots

The problem is not only behavioral but also technical. Many of these "invisible" bots exploit vulnerabilities in the authentication systems of major social platforms. For example, some third-party APIs used for integrating advanced features contain flaws that allow bots to bypass standard controls. The CVE-2023-41963, recently discovered in a popular authentication framework, demonstrates how these systems can be manipulated to make bots appear as legitimate users.

The Role of NIS2 Compliance in Managing Bots

The NIS2 directive imposes new obligations for digital operational resilience for digital platforms. Companies managing social media will need to implement technical and organizational measures to prevent the use of bots for social manipulation. This includes the obligation to conduct periodic security audits and adopt Security Information and Event Management (SIEM) solutions to monitor suspicious activities. Non-compliance could result in significant sanctions, up to 2% of global turnover.

Impact on the Institutional Crypto Custody Sector

The phenomenon of friendly bots also has implications for the institutional crypto custody sector. Exchanges and wallet providers must be aware that bots can be used to manipulate markets or obtain sensitive information from users. Crypto AML compliance requires the implementation of advanced KYC exchange systems and transaction monitoring to prevent the use of bots for illicit activities.

Breach Remediation Strategies for Companies

For organizations affected by bot-based attacks, breach remediation requires a structured approach. In addition to removing compromised accounts, it is essential to conduct a forensic analysis to identify the exploited vulnerabilities. Enterprise Data Loss Prevention (DLP) solutions can help prevent the loss of sensitive data caused by interactions with malicious bots. Furthermore, training employees on social engineering techniques is crucial to reducing the risk of internal attacks.

The Evolution of the Cyber Insurance Market

The cyber insurance sector is undergoing a significant change in risk assessment. Cyber risk policies may include specific clauses to cover damages caused by friendly bots, directly impacting the cyber insurance cost. Companies with advanced security measures, such as the implementation of a Managed Security Operations Center, may benefit from lower premiums due to a more favorable risk assessment.

The Importance of ISO 27001 Certification

The ISO 27001 certification is becoming a fundamental requirement for companies operating in sectors at high risk of cyber attacks. This international standard provides a comprehensive framework for information security management, including protection against malicious bots. A security audit conducted by a certified body can help organizations identify and correct vulnerabilities before they are exploited.

The Future of Ransomware Protection

The threat of friendly bots requires an evolution of ransomware protection strategies. Traditional ransomware recovery solutions must be integrated with advanced threat detection technologies. Using machine learning to analyze user communication patterns can help identify suspicious activities and prevent attacks before they cause significant damage.

Impact on Cloud Security Posture Strategies

Companies using cloud services for user data management must adopt advanced cloud security posture measures. CSPM (Cloud Security Posture Management) solutions can help monitor and protect cloud infrastructures from bot-based attacks. Implementing a zero trust architecture is essential to ensure that only legitimate users can access sensitive resources.

The Role of Disaster Recovery as a Service

In case of a successful attack, organizations must be ready to quickly implement disaster recovery as a service (DRaaS) solutions. These services can help restore normal operations in a short time, minimizing the impact of bot-based attacks. The integration of enterprise backup and business continuity strategies is fundamental to ensuring operational resilience.

Frequently Asked Questions

What is the economic impact of bot-based attacks?

Bot-based attacks can cause significant losses, both direct and indirect. Companies may suffer reputational damage, loss of customers, and legal costs. Additionally, cyber risk policies may not cover all damages, further increasing costs.

How can companies protect themselves from friendly bots?

Companies can adopt technical measures such as implementing MDR and SIEM solutions, as well as organizational strategies like employee training and adopting standards such as ISO 27001. A Managed Security Operations Center can provide specialized support.

Which platforms are most at risk?

Platforms with a high level of social interaction, such as Facebook and TikTok, are particularly vulnerable. However, even newer platforms like Threads can be targeted for attacks, especially if they are text-based and have a high level of engagement.

How does the age of users affect the ability to detect bots?

Younger users tend to be more skilled at recognizing bots, while those over 50 show higher error rates. This suggests that education and experience with social media play a crucial role in the ability to identify digital threats.

What are the legal implications for social platforms?

Social platforms may face sanctions for non-compliance with the NIS2 directive. Additionally, they may be legally pursued for damages caused by malicious bots, especially if they do not adopt adequate measures to prevent the improper use of their platforms.

Future Perspectives and Forecasts

The future of the fight against friendly bots depends on technological and regulatory evolution. Social platforms will need to invest in advanced detection and prevention algorithms, while companies will need to adopt proactive measures to protect their data and users. Compliance with the NIS2 directive and the DORA regulation will be crucial to ensuring digital operational resilience. As the sophistication of bots increases, collaboration between the public and private sectors will be essential to develop effective solutions and prevent significant damage.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.