1. Executive Summary

The most dangerous influence operations are not the ones that shout the loudest — they are the ones you mistake for the crowd. — Ori Lehavi, Founder & CEO, Cyber Harpoon

The Bot Activity Detection System (BADS) is Cyber Harpoon's proprietary methodology for identifying, mapping, and attributing coordinated inauthentic behavior (CIB) across social media platforms and open-source digital environments. First developed in response to the surge in bot-driven market manipulation and political influence operations, BADS 2.0 represents a significant evolution: a multi-layer, cross-platform detection framework capable of distinguishing organic activity from manufactured consensus at scale.

BADS 2.0 operates across six primary data environments — Twitter/X, Reddit, YouTube, Telegram, the open web, and SEC regulatory filings — applying a layered signal analysis model that evaluates individual accounts, behavioral patterns, network topology, and cross-platform identity correlations. Findings are synthesized into a standardized threat scoring system that enables prioritized, actionable intelligence reporting.

Key capabilities include real-time detection of pump-and-dump promotion networks, identification of coordinated narrative campaigns, VIP/executive reputation threat assessment, and attribution of disinformation networks to suspected origin clusters. The methodology has been validated across financial, political, and corporate intelligence use cases.

This whitepaper presents the full BADS 2.0 framework, its technical methodology, signal taxonomy, scoring architecture, and representative case applications. It is intended for intelligence practitioners, corporate security teams, financial compliance officers, and researchers operating at the intersection of social media analysis and threat intelligence.

2. Introduction: The Coordinated Inauthentic Behavior Threat Landscape

2.1 The Scale of the Problem

Social media platforms collectively host over five billion users and generate hundreds of billions of interactions per day. Within this data environment, a growing proportion of activity is not what it appears to be. Coordinated inauthentic behavior — the use of fake, hijacked, or artificially amplified accounts to distort online discourse — has become a pervasive and increasingly sophisticated threat across financial markets, political systems, and corporate reputations.

The mechanics of modern CIB have evolved well beyond simple bot farms. Today's influence operations blend authentic-seeming synthetic accounts with real human participants, leverage algorithmic amplification dynamics, and deliberately suppress counter-narratives while flooding information ecosystems with targeted content. The result is artificial consensus: manufactured trends, inflated engagement, and false signals of public sentiment that can move markets, swing public opinion, and destroy individual reputations.

2.2 Why Existing Detection Approaches Fall Short

Most commercially available social listening and brand monitoring tools are designed to measure organic sentiment — not to detect its manipulation. Their keyword and volume-based architectures identify what is being said, but not whether the speakers are authentic. Platform-native enforcement mechanisms, while improving, operate reactively and at insufficient resolution for real-time intelligence operations.

Academic research on bot detection typically focuses on single-platform analysis and binary classification (bot vs. human). These approaches fail in operational contexts where:

  • Campaigns are multi-platform: Narratives are seeded on Telegram, amplified on Twitter/X, cited as "grassroots" on Reddit, and laundered through blog content indexed by search engines.
  • Automation is partial: Modern campaigns mix automated posting with human-operated accounts, defeating classifiers trained on fully automated behavior.
  • Attribution matters: Knowing that bots exist is insufficient. Intelligence consumers need to understand network structure, likely origin, and adversarial objectives.
  • Speed is critical: A pump-and-dump cycle may complete within 48–72 hours. Political narratives can go viral in hours. Detection tools that operate on weekly reporting cycles provide no operational value.

2.3 The BADS Response

Cyber Harpoon developed the Bot Activity Detection System to address these operational gaps. BADS 2.0 is not a platform monitoring tool — it is an intelligence methodology. It integrates automated data collection, behavioral analysis, network graph modeling, and cross-platform correlation into a structured, repeatable analytical framework that produces intelligence-grade findings.

BADS 2.0 is designed for the analyst who needs to answer operational questions: Is this stock promotion campaign organic or manufactured? Who is behind this coordinated attack on our executive? Is this political hashtag driven by real public sentiment or a bot amplification network?

3. The BADS 2.0 Framework

BADS 2.0 is built on two orthogonal analytical axes: detection layers (what level of abstraction is being analyzed) and signal categories (what kind of evidence is being weighed). Together, these produce a standardized Campaign Threat Score (CTS) that enables prioritized, comparable reporting across engagements.

4. Detection Layers

BADS 2.0 applies analysis across four hierarchical detection layers, each building on the evidence established at the layer below it.

Layer 1

Account-Level Analysis

Individual account profiling. Each participating account is evaluated against a battery of authenticity signals — account age, follower/following velocity, profile completeness, historical posting volume, and cross-platform presence — to establish a baseline credibility score.

Layer 2

Behavioral Pattern Analysis

Temporal and content analysis. Detects posting velocity anomalies, temporal clustering across accounts, exact/near-exact content replication, off-hours activity inconsistent with stated geolocation, and coordinated narrative sequencing.

Layer 3

Network-Level Analysis

Maps the relational structure of the account ecosystem: amplification chains, cluster coefficients, hub identification, and temporal network evolution — did relationships predate the campaign, or emerge simultaneously with it?

Layer 4

Cross-Platform Correlation

Traces campaign activity across platforms to reconstruct the full operational picture. Username correlation, narrative fingerprinting, SEC filing correlation (for financial campaigns), and open-web indexing identify origin environments and attribution.

5. Signal Categories

BADS 2.0 evaluates signals across five weighted categories. Each contributes evidence to the overall campaign classification.

AAccount Authenticity Signals

Whether individual accounts appear to be genuine human-operated profiles. High-weight indicators: account age under 90 days at campaign onset, default/stock imagery, follower-to-following ratios below 0.1, zero or near-zero prior engagement outside the target topic, biography-vs-behavior inconsistencies.

BBehavioral Coordination Signals

Whether accounts are acting in coordination. High-weight indicators: posting within ±60-second windows across multiple accounts, identical/near-identical text with minor obfuscation, mass simultaneous follow events, coordinated engagement on specific content within tight temporal windows.

CContent Authenticity Signals

Whether content reflects genuine human perspective or manufactured messaging. High-weight indicators: identical narrative templates with variable insertion, rapid propagation of unverified claims without independent sourcing, artificially uniform sentiment, coordinated counter-narratives targeting critics.

DNetwork Structure Signals

Whether the network resembles organic community formation or centrally directed amplification. High-weight indicators: star-topology graphs, relationships formed within 24 hours of campaign start, exclusive mutual amplification clusters with minimal external connectivity, rapid dissolution after campaign end.

ECross-Platform Correlation Signals

The same campaign operating across environments. High-weight indicators: matching usernames/profile elements across platforms, Telegram narratives appearing 24–72 hours before mainstream platforms, coordinated SEC-filing/social-promotion timing, blog articles appearing shortly before social amplification begins.

6. The BADS Scoring System

BADS 2.0 produces a standardized Campaign Threat Score (CTS) for each analyzed environment, enabling prioritized reporting and trend tracking across engagements.

6.1 Scoring Architecture

The CTS is a composite 0–100 score built from weighted sub-scores across the five signal categories. Category weights are calibrated to context: financial market manipulation assessments apply higher weight to behavioral coordination signals; political influence assessments emphasize content and cross-platform signals; VIP reputation attacks weight account authenticity and network structure most heavily.

CTS RangeClassificationRecommended Response
0–19NegligibleOrganic activity within normal variance
20–39LowPossible low-level automation; monitor
40–59ModerateLikely coordinated activity; document and escalate
60–79HighConfirmed coordinated campaign; intelligence report
80–100CriticalSophisticated influence operation; immediate action

6.2 Sub-Score Components

Each of the five signal categories produces an independent sub-score (0–100), multiplied by its context-adjusted weight to produce the CTS. This architecture allows analysts to isolate which dimensions of a campaign are most prominent — a critical distinction between, for example, a low-sophistication spam network (high behavioral, low network) and a professional influence operation (moderate behavioral, high cross-platform).

7. Platform Coverage

BADS 2.0 is designed for multi-platform intelligence collection and analysis. The following platforms are supported in the current methodology:

Twitter / X

Primary amplification surface for most financial and political campaigns. BADS analyzes tweet content, account metadata, follower graphs, engagement patterns, and hashtag velocity. Twitter/X's high posting frequency and public engagement model make it the richest behavioral signal source in the methodology.

Reddit

Key secondary amplification surface, particularly for financial promotion campaigns (stock tickers, cryptocurrency) and political narrative seeding. BADS analyzes subreddit posting history, account karma patterns, comment velocity, and cross-subreddit posting behavior.

YouTube

Critical for video-based influence operations and long-form disinformation. BADS analyzes channel creation dates, subscriber growth patterns, comment section manipulation, and content correlation with social media campaigns.

Telegram

Frequently used as the origin/coordination layer for campaigns that subsequently amplify on public platforms. BADS monitors public channels and groups for early-stage narrative development, operational coordination signals, and account recruitment activity.

Open Web and Blog Networks

Press release farms, AI-generated blog networks, and astroturfed forum content frequently provide the "source material" cited by social media campaigns to lend legitimacy to manufactured narratives. BADS includes web indexing to identify and map these support structures.

SEC Filings and Financial Disclosures

For financial market applications, BADS cross-references social media promotion activity with SEC EDGAR filings — including Form 4 insider transactions, S-1 and registration statements, and paid promotion disclosures (required under Section 17(b) of the Securities Act). Divergence between disclosed compensation relationships and apparent organic social promotion is a primary indicator of securities fraud.

8. BADS in Action: Representative Case Studies

Case Study 1 · Financial Sector

Stock Promotion Bot Network

Background. A small-cap stock traded on OTC markets experienced a sudden 340% price increase over four trading days, accompanied by an explosion of social media activity promoting the company across Twitter/X and Reddit.

BADS Analysis. Layer 1 account analysis identified 847 accounts participating in the promotion campaign, of which 612 (72%) were created within 60 days of campaign onset. Layer 2 behavioral analysis revealed that 89 accounts posted identical promotional content within 3-minute windows on three separate occasions during the campaign. Layer 3 network analysis identified a hub-and-spoke amplification structure centered on four accounts with coordinated posting schedules.

Cross-platform analysis (Layer 4) identified matching usernames on a Telegram channel where the campaign had been coordinated 48 hours before Twitter/X deployment. SEC filing review identified two undisclosed promotional agreements that should have been disclosed under Section 17(b).

CTS: 87 · Critical

Outcome. Confirmed pump-and-dump promotion network. Report delivered to client with full account attribution, network map, and regulatory referral recommendation. The stock price returned to pre-campaign levels within 11 days. The SEC filing irregularities were flagged for regulatory review.

Case Study 2 · Political Influence

Coordinated Political Influence Campaign

Background. A local elected official engaged Cyber Harpoon after observing a sudden surge of hostile social media activity following a policy vote. The activity appeared disproportionate to the actual public response to the policy.

BADS Analysis. Twitter/X analysis identified 1,200+ accounts participating in the hostile campaign over a 72-hour window. Layer 1 analysis found 68% of accounts were under 6 months old. Layer 2 identified 14 distinct message templates being rotated across accounts, with minor variations consistent with automated obfuscation. Layer 3 identified three primary amplification clusters with minimal organic community overlap.

Cross-platform correlation traced the campaign origin to a Telegram channel with 2,300 members, where the messaging templates and target list had been distributed 18 hours prior to the Twitter/X deployment. Content fingerprinting identified the same narrative appearing in two blog posts published the previous week, establishing the layered support structure.

CTS: 74 · High

Outcome. Coordinated inauthentic campaign with political motivation. Network attribution provided to client with origin channel identification and engagement suppression recommendations.

Case Study 3 · Executive Protection

Targeted Reputation Attack Against a Corporate Executive

Background. A Fortune 500 Chief Financial Officer became the target of a sustained social media campaign alleging financial misconduct. The allegations were unsubstantiated but were gaining traction and beginning to appear in news searches.

BADS Analysis. Account-level analysis of the 340 accounts most actively propagating the allegations identified a bimodal distribution: 180 low-credibility accounts under 90 days old, and 160 older accounts with histories consistent with account takeover or rental. Layer 2 analysis confirmed posting coordination across both account cohorts.

Network analysis revealed that the campaign's most amplified content originated from three accounts with high follower counts and engagement histories consistent with legitimate users — indicating account compromise or paid amplification. Cross-platform analysis identified identical allegations appearing on Reddit, on two anonymous blog platforms, and in a Telegram channel associated with a known reputation-for-hire operation.

CTS: 69 · High

Outcome. Coordinated reputation attack with indicators of professional execution. Intelligence report delivered with network map, suspected origin attribution, and platform reporting recommendations to suppress inauthentic amplification.

9. Technical Methodology

9.1 Account Age and History Analysis

Account age relative to campaign onset is one of the strongest single predictors of inauthenticity in coordinated campaigns. BADS applies a sliding-scale weighting model: accounts created within 30 days of campaign onset receive maximum inauthenticity weight; accounts created between 30–90 days receive elevated weight; accounts older than 90 days are evaluated on behavioral signals.

History depth analysis examines the pre-campaign posting record of each account. Authentic accounts accumulate organic posting histories across varied topics over time; inauthentic accounts frequently show sparse or topically narrow pre-campaign histories, or histories consistent with dormancy-and-reactivation patterns associated with account farming.

9.2 Posting Velocity and Pattern Detection

Human beings have cognitive and physical limits on posting rate. BADS applies empirically derived velocity thresholds — based on documented human posting capacity research — to identify accounts posting at rates inconsistent with human operation. Sustained rates above 50 posts per hour, or activity during physiologically improbable hours relative to stated geolocation, are flagged as high-weight automation signals.

Temporal clustering analysis goes beyond per-account velocity to examine inter-account timing. When multiple accounts post identical or substantially similar content within 60-second windows, the probability of organic coincidence approaches zero at scale. BADS calculates temporal clustering coefficients across the account network and applies statistical significance thresholds to distinguish coordination from coincidence.

9.3 Engagement Authenticity Scoring

Engagement metrics — likes, shares, comments, upvotes — are increasingly subject to manipulation. BADS evaluates engagement authenticity by examining the ratio of engagement to reach (inflated engagement with limited organic reach is a strong manipulation indicator), the account-level authenticity scores of engaging accounts (engagement from bot-flagged accounts is discounted), and engagement velocity (organic engagement follows a predictable decay curve; coordinated engagement produces anomalous spikes).

Sentiment analysis is applied to comment and reply content to detect coordinated sentiment manipulation — cases where the emotional tone of responses is artificially uniform or where negative sentiment is being artificially amplified or suppressed.

9.4 Network Graph Correlation

BADS generates directed network graphs of all identified accounts, with edges representing amplification relationships (retweets, shares, crosspost attributions) and weighted by temporal proximity and content similarity. Graph topology analysis identifies structural signatures associated with coordinated operations:

  • Star topology. Central hub accounts amplified by spokes with no inter-spoke connections — indicates centrally directed distribution.
  • Clique topology. Dense clusters of accounts exclusively amplifying each other — indicates isolated coordinated networks.
  • Layered topology. Distinct hub accounts that relay content from low-credibility accounts to high-credibility amplifiers — indicates laundering operations.

Network evolution timeline analysis examines when account relationships formed relative to the campaign. Organic communities build relationships over time; coordinated networks form relationships in tight temporal clusters coinciding with campaign launch.

9.5 Cross-Platform Identity Correlation

BADS applies a multi-signal identity correlation methodology to link accounts across platforms. Correlation signals include: exact or variant username matching, profile image similarity (using perceptual hash comparison), biographical text similarity, posting timestamp correlation (accounts that post to multiple platforms in close temporal sequence), and narrative fingerprinting (tracking the same talking points, grammatical patterns, or content structures across platforms).

Cross-platform correlation is particularly valuable for identifying campaign origin environments. Campaigns typically originate in closed or semi-closed coordination environments (Telegram channels, private Discord servers) before deploying to public amplification surfaces. BADS traces this flow to identify both the coordination infrastructure and, in some cases, the operational actors behind it.

10. Applications and Use Cases

Financial Market Integrity

BADS 2.0 is directly applicable to securities market surveillance. Pump-and-dump schemes involving penny stocks, small-cap equities, and cryptocurrency assets routinely use coordinated social media promotion to artificially inflate prices. BADS provides the evidential framework to identify these campaigns, attribute them to specific account networks, and correlate them with SEC filing records for regulatory referral.

Compliance teams, hedge funds, and financial regulators can use BADS to screen equities showing abnormal social media activity, evaluate whether trending financial discussions reflect genuine retail investor sentiment, monitor competitor stocks for artificial promotion activity, and support regulatory investigations with structured social media intelligence.

Corporate Security and Brand Protection

Reputation attacks against corporations and their executives represent a growing category of competitive and adversarial threat. BADS provides the analytical capability to distinguish organic negative sentiment (a legitimate PR problem) from manufactured attack campaigns (a security problem). This distinction is operationally critical — the appropriate response to each is entirely different.

Political and Election Integrity

Influence operations targeting elections, referenda, and policy debates rely on manufactured consensus to move genuine public opinion. BADS provides the detection framework to identify these operations, enabling political campaigns, government agencies, and civil society organizations to respond with accurate counter-narrative rather than amplified disinformation.

Intelligence and National Security Applications

At the nation-state level, coordinated inauthentic behavior has been used to destabilize democratic institutions, amplify social divisions, and suppress protest movements. BADS provides a rigorous, repeatable methodology for detecting, attributing, and documenting these operations in forms suitable for intelligence reporting and policy response.

VIP and Executive Protection

Public-facing executives, celebrities, athletes, and political figures face increasing risk from coordinated social media attacks. BADS continuously monitors the information environment around protected persons, providing early warning of coordinated attack campaigns and enabling proactive response before artificial amplification reaches organic audiences.

11. Conclusion

The manipulation of digital information environments has become one of the defining operational challenges of the current decade. Bot networks, coordinated inauthentic behavior, and influence operations are no longer edge cases — they are routine tools of competitive, political, and adversarial actors across industries and geographies.

Effective response requires more than awareness. It requires a rigorous, repeatable methodology for detection, attribution, and prioritization — one that operates at the speed of the threat rather than days or weeks behind it. BADS 2.0 was developed to meet that requirement.

By layering account-level authenticity analysis, behavioral pattern detection, network topology modeling, and cross-platform correlation, BADS 2.0 provides intelligence practitioners with the analytical framework to move from raw social media data to actionable threat intelligence. The methodology's platform breadth — spanning Twitter/X, Reddit, YouTube, Telegram, the open web, and regulatory filings — ensures that campaigns cannot evade detection by operating across multiple environments.

As influence operations continue to grow in sophistication, BADS will continue to evolve. Cyber Harpoon is actively developing BADS 3.0 enhancements in the areas of AI-generated content detection, adversarial account aging (professional-grade long-term sleeper accounts), and real-time streaming detection for time-critical financial and political applications.

Closing Thesis

The information environment is contested. Maintaining its integrity requires purpose-built intelligence capabilities. BADS 2.0 is Cyber Harpoon's contribution to that effort.

12. About Cyber Harpoon

Cyber Harpoon is a boutique intelligence and digital threat analysis firm headquartered in Los Angeles, California. The company specializes in social media intelligence, coordinated inauthentic behavior detection, executive protection analytics, and open-source intelligence (OSINT) operations for corporate, financial, and government clients.

Cyber Harpoon's proprietary BADS (Bot Activity Detection System) methodology provides clients with the analytical capability to distinguish genuine online sentiment from manufactured influence operations — enabling accurate threat assessment, proactive response, and regulatory-grade evidence documentation.

Ori Lehavi is the Founder and CEO of Cyber Harpoon. He brings expertise in digital threat intelligence, social media analytics, and influence operation attribution to clients across the financial services, corporate security, and government sectors.

© 2026 Cyber Harpoon. All rights reserved. This document may be cited and reproduced with attribution. For licensing inquiries, contact Cyber Harpoon at cyberharpoon.com. BADS and Bot Activity Detection System are proprietary methodologies of Cyber Harpoon. Version 2.0.

Engage Cyber Harpoon

Have a suspected campaign to investigate?

Whether it's a coordinated attack on an executive, an unusual price move driven by social media, or a political narrative that doesn't add up — Cyber Harpoon delivers intelligence you can act on.