New Sectarian Bots Still Flooding Twitter with Anti-Shia Hate Speech

On June 22nd, after I completed this investigation on automated Twitter bots,  Twitter looked into it and banned multiple accounts after confirming bot-like activity. These apparently automated accounts were sending thousands of sectarian Tweets per day on the #Bahrain hashtag. However, I have been monitoring the hashtag regularly, and it has yet to show diminished activity. On 23rd June, 51% of the Tweets on the #Bahrain hashtag appeared to emanate from sectarian bot accounts. Indeed, it appears that the majority of the accounts I examined or reported have not been suspended, despite the investigations revealing behaviour that appeared to reflect high levels of automation. In fact, on 23rd June, more accounts were actually created, (scroll down for more information). At the moment, sectarian tweets still account for 50% of all tweets on the #Bahrain hashtag.

Summary of Tweets 26/06/2016

Before I discuss new bot accounts created since 22nd June,  I will examine the #Bahrain hashtag on 26th June. Once again, I searched the Twitter API for ‘#Bahrain’. It returned the following results (you can download data  here ((Look at the sheet titled ‘#Bahrain’).

Total number of Tweets extracted between 4.45.12 and 23.54.56 on 26th June 2016: 10923

Total number of Tweets suspected to be ‘fake’: 5456

Total number of suspected fake accounts: 1754

Percentage of Tweets on Bahrain hashtag suspected to be fake on 26th June 2016 = 50%

 

The Tweets

As usual, there were a cycle of a certain number of Tweets broadcast at regular intervals by accounts displaying the same qualities. In this examination of 5456 Tweets, only 12 unique, yet oft repeated Tweets came up, all of which contained derogatory and sectarian terms. Most contained the term Safavid, while some contained the term Majusi. The term Shia was repeatedly used, and in close proximity to sectarian terms or terms denoting violence, such as terrorist. The below table is a breakdown of the approximately 5456 fake tweets, all of which were not actual retweets, but copy and pasted tweets from individual accounts. (Number of Tweets is approximate in below )

اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/22eXRtES4G … #Bahrain #الفقيه #القائد Assaults by the deceased terrorist Nimr Al Nimr with the support and direction of the Safavid Persian Iranian regime #leader #faqih 88
الإرهابيين الصفويين https://t.co/2Lilk4cgVB … #آية_الله_قاسم #الشيخ_عيسي_قاسم #سحب_جنسية_عيسى_قاسم #البحرين #Bahrain #الفقيه #القائد Safavid Terrorists. #Ayatollah_Isa_Qasim #Shaykh_Isa_Qasim #Withdrawal_of_nationality_ofIsa_Qasim #Bahrain #Faqih #Leader 1511
الارهاب الصفوي المجوسي ضد بلاد الحرمين https://t.co/0Ene5wvu0W … #سحب_جنسية_عيسى_قاسم #البحرين #Bahrain #الفقيه #القائد #آية_الله_قاسم Safavid Majusi Terrorist against the country of the  Holy Mosques #Withdrawal_of_nationality_ofIsa_Qasim #Bahrain #Faqih #Leader #Bahrain #Isa_Qasim 39
الشيخ الشيعي السعودي البلادي يكشف حقيقة #ايران الصفوية ضد المملكة https://t.co/4bRTkx036U … #اسقاط_جنسيه_عيسي_قاسم #البحرين #Bahrain Saudi Shia Shaykh reveals truth about Safavid Iran against the Kingdom #Withdrawal_of_nationality_ofIsa_Qasim #Bahrain #Bahrain 891
الفرس والمجوس …حقد على العرب https://t.co/7l9MAOhJLE … #آية_الله_قاسم #الشيخ_عيسي_قاسم #سحب_جنسية_عيسى_قاسم #البحرين #Bahrain #الفقيه Persians and the Majus hate the Arabs #Ayatollah_Qasim #Shaykh_Isa_Qasim #Withdrawal_nationality_isa_qasim #Bahrain #Faqih 12
تقرير الاعلام الصفوي الكذب وتزييف الحقائق https://t.co/76axOKnfAq ’’’ #سحب_جنسية_عيسى_قاسم #البحرين #Bahrain #الفقيه #القائد #آية_الله_قاسم Media report of Safavid lies and distorted facts #Withdrawal_nationality_isa_qasim #Bahrain #Faqih #Leader #Ayatollah_Qasim 204
تواصل .. لقطات روحانية من الحرمين https://t.co/61UZpPNwxD … #البحرين #Bahrain #الفقيه #القائد #آية_الله_قاسم #الدراز #البحرين 470
تواصل.. إسقاط الجنسية البحرينية عن الشيعي الصفوي عيسي قاسم https://t.co/2sD5SOJRIf … #سحب_جنسية_عيسى_قاسم #البحرين #Bahrain #الفقيه #القائد Removal of Bahraini nationality from Shia Safavid Isa Qasim #withdrawal_of_nationality_of_Isa_Qasim #Bahrain #Faqih #Leader 481
داعش وإيران والخطاب الموحد https://t.co/emLlqMUO5f … #Bahrain #الفقيه #القائد #آية_الله_قاسم #الدراز #البحرين #اغلاق_جمعية_الوفاق Da’esh and Iran and their unified discourse #Faqih #Leader #Ayatollah_Qasim #Duraz #Bahrain #closing_of_AlWefaq 254
سوسن الشاعر:البحرين لا تعبأ بتهديدات قاسم سليمانى ولا غيره https://t.co/Jf6wGdNQH9 … #اسقاط_جنسيه_عيسي_قاسم #آية_الله_قاسم #البحرين #Bahrain Sowsan Sha’ir*: Bahrain will not listen to the threats of Qasim Suleimani**, or others like him.

*Sowsan Sha’ir is a pro-status quo Bahriani Columnist

8
فيديو الإرهابيين الصفويين https://t.co/03CQrzHz5z … #آية_الله_قاسم #الشيخ_عيسي_قاسم #البحرين #Bahrain #الفقيه #القائد #آية_الله_قاسم #الدرا Video of Safavid terrorists #Ayatollah_Qasim #Shaykh_Isa_Qasim #Bahrain #Faqih #Leader #Ayatollah_Qasim #Dura  (<1511)
فيديو:الإرهاب الإيراني الصفوي بمكة المكرمة https://t.co/DdP1g3l9Lr … #آية_الله_قاسم #الشيخ_عيسي_قاسم #سحب_جنسية_عيسى_قاسم #البحرين #Bahrain Video: Irani Safavid Terrorists in Holy Mecca #Ayatollah_Qasim #Shaykh_Isa_Qasim #Withdrawal_nationality_Isa_Qasim 1413

Following this, I combined data from 22nd, 26th, and 27th June to get an estimate of how many unique bots there were. This would allow me to get a better sense of the number of bots out there. After I compiled all the suspicious accounts, I performed a remove duplication report in  Google Sheets, resulting in about 3108 active accounts (approx), all of which  fit the profile of sectarian bot accounts. (Feel free to peruse a list of the accounts here, I could find very few that had been suspended ((Look on the sheet titled ’22, 26,27 Aggregated’). While it is early days, this would suggest that different bots become active on different days, meaning daily API extractions only reveal a limited number of bots. It does not help establish how many bots might be out there, although it indicates that there are clearly a lot.

New Bots Since  June 22

What is especially interesting is that since Twitter suspended the accounts on 22nd June, new fake accounts have been created that follow much the same pattern. Either this a planned move, or a reaction to the suspension of accounts. At least 58 accounts were created on 23rd June. These accounts demonstrate many of the same qualities as their predecessors, although arguably they are more sophisticated in the sense that they have more information to appear more ‘credible’, such as a location and birthday (you can download the data here of all suspicious accounts monitored on 27th June). Yet there is little doubt they are bots or possibly people operating dozens of accounts. The following points highlight some of the patterns.

NewAccounts

  1. The accounts repeating the same Tweets were all created on the 23rd June.
  2. All Tweets were from TweetDeck
  3. All accounts had a similar number of tweets and followers (Usually about 300 Tweets; follower numbers in the fifties; and following numbers around 11-15)
  4. All accounts are tweeting the same, copy and pasted tweets, most of which were mentioned in the first table in this post.
  5. All accounts had the same input location and format, which was ‘Saudi +((city name)). See Table X for details at the bottom of this post It should be noted that this location information is input manually and so does not reflection the actual location of the account or the servers. It should also be added that previous accounts believed to be suspicious did not include this information. However, this reflects a progressive improvement over the course of three years in providing more information on the account. (As we saw before,  accounts created after 2015 began including biographical information).
  6. Because the new accounts were set up less than a  week ago, the Twitter archiver pulled the majority of the Tweets from the account, including the first one. This gives us a better sense of the origins of the accounts. Interestingly, all the new accounts from the 58 or so known new accounts exhibited the same pattern. Their very first Tweet contained an unusual idiom, saying, or phrase in Arabic. This idiomatic phrase was always launched from ‘Twitter Web Client’,  while the rest of the Tweets were launched from TweetDeck. I tested this on about 10 of the accounts registered on 23rd June. One of the examples was ‘البس يحب الخناقة’, the idiomatic translation of which I am told is (People love their oppressors lit: cats love their stranglers/cats love to fight). See below for some examplesaccount onesnippet 2snippet 3It is interesting to note that while the Archiver can only pull Tweets from the past week, if you manually go to some of the sectarian bot accounts created earlier in the year (2016), and scroll down to the beginning of their profile, you will sometimes see the same pattern of putting out a unique tweet (usually a proverb or saying), before the account begins its automated activity. Here is an example. This appears to be a relatively recent development.
    Tweet

    You can also see on this account that the first Tweet occurred on Feb 19th, while the next one was 21 June

     

  7. Looking at the timeline of each individual account,  we see once again certain patterns of Tweeting. In the table below, or the two above, you can see that the accounts tweet approximately every four or 5 seconds in three tweet bursts, a pattern suggesting formulaic and repetitive behaviour. This pattern was apparent across all those new accounts created on 23rd June.
6/24/2016 9:15:46 @gasemsheblikhau جاسم شبلي داعش وإيران والخطاب الموحد https://t.co/7ibWPfkeEz … #Bahrain #الفقيه #القائد #آية_الله_قاسم #الدراز #البحرين #اغلاق_جمعية_الوفاق 746187535529836546 TweetDeck 12
6/24/2016 9:15:51 @gasemsheblikhau جاسم شبلي داعش وإيران والخطاب الموحد https://t.co/7ibWPfkeEz … #آية_الله_الشيخ_عيسى_قاسم #عيسى_قاسم #qatif #القطيف #ايران #حزب_الله #العراق 746187554421018624 TweetDeck 12
6/24/2016 9:15:55 @gasemsheblikhau جاسم شبلي داعش وإيران والخطاب الموحد https://t.co/7ibWPfkeEz … #اسقاط_جنسيه_عيسي_قاسم #الحشد_الشعبي 746187572095811584 TweetDeck 12
6/24/2016 9:39:33 @gasemsheblikhau جاسم شبلي تقرير الاعلام الصفوي الكذب وتزييف الحقائق https://t.co/9LSgLZZEjJ … #اسقاط_جنسيه_عيسي_قاسم #آية_الله_قاسم #الشيخ_عيسي_قاسم 746193522345152512 TweetDeck 12
6/24/2016 9:39:37 @gasemsheblikhau جاسم شبلي تقرير الاعلام الصفوي الكذب وتزييف الحقائق https://t.co/9LSgLZZEjJ … #سحب_جنسية_عيسى_قاسم #البحرين #Bahrain #الفقيه #القائد #آية_الله_قاسم 746193538975596545 TweetDeck 12
6/24/2016 9:39:42 @gasemsheblikhau جاسم شبلي تقرير الاعلام الصفوي الكذب وتزييف الحقائق https://t.co/9LSgLZZEjJ #الدراز #البحرين #اغلاق_جمعية_الوفاق #آية_الله_الشيخ_عيسى_قاسم #عيسى_قاسم 746193556637814789 TweetDeck 12
6/24/2016 10:02:45 @gasemsheblikhau جاسم شبلي تقرير الاعلام الصفوي الكذب وتزييف الحقائق https://t.co/9LSgLZZEjJ … #qatif #القطيف #ايران #حزب_الله #العراق #الحشد_الشعبي 746199359994265600 TweetDeck 12
6/24/2016 10:02:50 @gasemsheblikhau جاسم شبلي اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/aNxGT1ai9O … #اسقاط_جنسيه_عيسي_قاسم 746199378952478720 TweetDeck 12
6/24/2016 10:02:54 @gasemsheblikhau جاسم شبلي اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/aNxGT1ai9O … #ايران #حزب_الله #الحشد_الشعبي 746199396576985088 TweetDeck 12
6/24/2016 10:26:04 @gasemsheblikhau جاسم شبلي اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/aNxGT1ai9O … #qatif #القطيف #ايران #حزب_الله 746205227829723139 TweetDeck 12
6/24/2016 10:26:08 @gasemsheblikhau جاسم شبلي اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/aNxGT1ai9O #آية_الله_الشيخ_عيسى_قاسم #عيسى_قاسم 746205245437403136 TweetDeck 12
6/24/2016 10:26:13 @gasemsheblikhau جاسم شبلي اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/aNxGT1ai9O … #اغلاق_جمعية_الوفاق 746205263405821955 TweetDeck 12
6/24/2016 10:49:15 @gasemsheblikhau جاسم شبلي اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/aNxGT1ai9O … #آية_الله_قاسم #الدراز #البحرين 746211059346726913 TweetDeck 12
6/24/2016 10:49:19 @gasemsheblikhau جاسم شبلي اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/aNxGT1ai9O … #Bahrain #الفقيه #القائد 746211076857991168 TweetDeck 12
6/24/2016 10:49:23 @gasemsheblikhau جاسم شبلي اعتداءات الإرهابي الهالك نمر النمربدعم وتوجيه من النظام الصفوي الفارسي الإيراني https://t.co/aNxGT1ai9O … #سحب_جنسية_عيسى_قاسم #البحرين 746211094595674114 TweetDeck 12

The new accounts are, as mentioned, using lots of sectarian terminology. In what is becoming a tradition, I have included a word cloud below of all the tweets used by one of the new accounts. As you can see (or not, depending on if you read Arabic), the dominant

wordcloud (1)

words include ‘Safavid’, ‘Shia’, ‘Iran/Irani’, ‘Faqih’, ‘Hezbollah’, ‘Al-Majusi’, ‘Terrorist’. As mentioned before, many of these words are derogatory terms used to refer to Shia. Terms such as Faqih too are often used, playing on Arab fears that the Shia in the Gulf are attempting to set up an Iranian-style theocracy based on Vilayat e-faqih (guardianship of the jurist).

Some Remarks

To sum up; half of the tweets on the Bahrain hashtag appear to be hate speech generated by sectarian bots. Despite reporting this to Twitter and Twitter taking action the figure has not changed. Despite Twitter’s suspension of accounts, new ones are still being created, raising question of how difficult it is to tackle them.

Clearly the problem of sectarian bots has not gone away, and will not go away anytime soon. I do not know what information Twitter have on their side to be able to determine unusual activity coming from specific email domains, or servers located in specific places for example. Unfortunately for Twitter, tales of thousands of bot accounts spewing hatred across the internet does not fit into their brand as a progressive, democracy-encouraging social media platform.

Needless to say, while the tweets examined do suggest that whoever is behind the accounts are technically anti-Islamic State, the anti-Shia discourse used indicates substantial overlap with the rhetoric of groups like Islamic State. Indeed it resembles some sort of Wahabi orthodoxy evident in places like Saudi Arabia. I certainly would suggest that these bots be taken more seriously in the fight against hate speech. Given the scale, it is very hard to imagine that this is the work of a small group of individuals. Instead it implies a large-scale operation undertaken with assistance of technical specialists, and possibly reputation management/PR companies.

 

Table X

حتات سدير – السعودية
الصفانية – السعودية
Saudi Arabia
النويعمة – السعودية
أرجح – السعودية
الفايضة – السعودية
مكة – السعودية
العوامية – السعودية
الجوف – السعودية
القيسومة – السعودية
غرّان – السعودية
أبقيق – السعودية
العديلية – السعودية
الصحف – السعودية
الصالحية – السعودية
الخفجة – السعودية
الطائف – السعودية
مليجة – السعودية
جيزان – السعودية
جرّارة – السعودية
الأفلاج – السعودية
الدلم – السعودية
البجادية – السعودية
حائل – السعودية
المزاحمية – السعودية
عثيثية – السعودية
القنفذة – السعودية
عفيف – السعودية
الزبية – السعودية
الظهران – السعودية
الدمّام – السعودية
السعودية
الرياض – السعودية
ينبع – السعودية
أحد رفيدة – السعودية
الرفيع – السعودية
بالأسمر – السعودية
العيون – السعودية
البدع الشمالي – السعودية
الخصرة – السعودية
القصيم – السعودية
السيح الشمالي – السعودية
الشوارى – السعودية
القصب – السعودية
مدينة الجبيل الصناعية – السعود
مسدح – السعودية
الدغيمي – السعودية
الزيقين – السعودية
بيشة – السعودية
الأرتوية – السعودية
حفر البطين – السعودية
جدة – السعودية
خليص – السعودية
الخوار – السعودية
السلمية – السعودية
العيينة – السعودية
Datu Saudi
القويز – السعودية
Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s