The Evolution of Facebook Spam: How Attackers Hired Kakaotalk to Bypass Defenses
Evolution of Spamming Attacks on Facebook
The paper investigates the "Evolution of Spamming Attacks on Facebook," specifically identifying a sophisticated localized campaign targeting Korean users. By developing a Python-based crawler and analyzer that processed 0.6 million comments, the authors demystify a new multi-phase tactic involving Facebook, the Kakaotalk messenger, and illicit web services.
TL;DR
Social media spam has evolved from simple URL-blasting to a sophisticated, three-stage pipeline. A study of 0.6 million Korean Facebook comments reveals that spammers are now using Kakaotalk as a middleman to hide malicious intent from Facebook's automated filters and are even using comment sections to recruit new attackers.
Context & Motivation
For years, academia and service providers like Facebook have been locked in an arms race with spammers. Historically, defenders focused on "Old School" patterns: attractive text paired with a direct link to a malicious site. However, as link-crawlers and keyword filters improved, spammers adapted.
The authors observed that in Korea, Facebook was becoming a "recruitment ground" rather than just an end-point for ads. The shift towards localization and platform-hopping has made these attacks harder to trace using traditional unified defense mechanisms.
Methodology: The Three-Phase Attack
The core of this research is the identification of the New Spamming Scheme, which breaks the connectivity between the initial exposure and the final malicious payload.
- Facebook Phase: Spammers flood popular posts with high-engagement comments. They mimic human conversation or quote popular stories to stay beneath the radar.
- Kakaotalk Phase: Instead of a URL, the comment provides a Kakaotalk ID. This ID acts as a "broker." Because Kakaotalk is a separate encrypted messenger, Facebook's security systems cannot see what happens once the user moves there.
- Web Phase: The "broker" on Kakaotalk then leads the victim to the final destination—usually illegal gambling (casinos), sports betting, or pornography.

Data-Driven Insights
The research team built a Python crawler via the Facebook Graph API, targeting 23 high-traffic pages over 20 days. They focused on specific Korean keywords that served as linguistic signals for illicit activity.
- The "Playground" Factor: Keywords like 놀이터 (Playground) and 충전 (Recharge) are local slang for online gambling.
- The Recruitment Loop: A surprising finding was the volume of 댓글 알바 (Comment Part-time Job) spams. These are not ads for products, but ads for hiring more spammers, turning victims into attackers to expand the reach of the campaign.
Figure: The correlation between specific keywords and the presence of Kakaotalk IDs, proving the platform-hopping strategy.
Critical Analysis & Takeaways
The brilliance—and danger—of this evolved attack lies in its obfuscation. By moving the "transaction" to a localized messenger like Kakaotalk, attackers exploit a blind spot in Facebook's security manifold.
Limitations: The study notes that since the Facebook API v2.0 update, researchers can only access public Page data, not private Profile data, meaning the actual volume of spam is likely much higher. Additionally, attackers are moving toward Image-based Spam (text inside pictures), which currently bypasses text-based analysis entirely.
The Future: To win this arms race, security systems must become as cross-platform as the attackers. Monitoring the transition points between social networks and third-party messengers is no longer optional; it is a necessity for localized digital safety.
