第一财经

Stock recommendations hidden in "delivery codes" and poetic acronyms: The financial underworld is starting to outwit platform algorithms

原文:荐股藏进“取件码”和藏头诗,金融黑灰产开始和平台算法斗智

Hello everyone, I'm your financial observer. Today, we're not going to talk about some boring regulatory documents, but about a "spy thriller" that's taking place right on our mobile phone screens.

The news reports that REDnote has recently made public some cases of financial scams and gray markets (groups that engage in illegal stock recommendations and fraud) trying to outsmart the platform's review systems. This reveals a harsh reality: The people trying to trick you out of your money online are becoming more and more skilled in technology, more understanding of human behavior, and even better at circumventing machine detection.

To make this easier to understand, I've broken down the news into five key points, and we'll discuss the behind-the-scenes tactics in plain language.

1. Masquerading Stock Recommendations as Delivery Codes: The Evolution of Scammers' Tactics

In the past, scammers would be very straightforward, shouting things like, "Buy this stock; it will hit the daily limit up tomorrow!" in their friend circles or groups. Such blatant tactics made it easy for the platforms to catch them.

But now, they've become more subtle and hidden. There's a particularly illustrative example in the news: a string of numbers that looks like a delivery code, like "8392-105," actually contains a stock code; or they might post a poem, and the first letter of each line, when put together, reveals the actual stock they want to recommend.

Why do they do this?

Platform review systems initially relied on "keywords" to identify scams. Words like "stock recommendation," "add WeChat," or "sure profit" would trigger alarms. To evade these systems, scammers have started to "encrypt" their messages. They turn contact information into random codes, hide recommendations in images or comment sections, or spread them across multiple accounts.

It's like a thief who used to break into houses with a crowbar; now they use fingerprints to unlock them. If you only focus on the crowbar, you won't catch the thief using fingerprints.

2. From Deleting Posts and Blocking Accounts to AI-Powered Pattern Recognition: Platforms' Technical Countermeasures

Facing these encrypted methods, platforms haven't been idle. In the past, reviewers would simply check a single post; if no prohibited words were found, it was approved.

Now, platforms use large-scale AI models to analyze the situation more comprehensively.

How does AI do this?

AI doesn't just look at the content of a post; it also considers:

  • The main text for any anomalies,
  • The comment section for hidden contact information,
  • The account's past behavior,
  • And the account's interactions with other accounts.

For example, a post might seem normal on its own, but if AI notices that the account uses coded language to direct users to add a WeChat account in the comments, or if it frequently interacts with 50 other accounts, it can piece together the clues and identify a scamming group.

However, AI isn't omnipotent.

The news also mentions that platforms still use manual reviews because some scammers are very clever, and human experience and intuition are needed to detect subtle hints. Machines might mistake normal conversations for legitimate ones, but experienced reviewers can spot the signs of deception.

3. Shifting Risks from the Main Text to the Comment Section

Data doesn't lie. The news shows that in the past six months, REDnote deleted 1.01 million posts but 4.77 million comments.

The number of comments deleted is more than four times that of posts, indicating that the risk is shifting.

Scammers used to dare to promote their activities directly in the main text, but now they avoid it because the main text is more exposed and easier to detect. They write clean, seemingly innocent posts about daily life and hide their tricks in the comments.

For instance, if the main text asks, "How's the stock market doing?" and someone in the comments asks, "How can I contact you?" a scammer might respond with a seemingly harmless emoji or number. This pattern makes it much harder to regulate, as you have to monitor not only the speakers but also the listeners and the channels of communication.

4. Industrialization of Scams and AI-Driven Identity Theft

This is perhaps the most alarming aspect of the news: Financial scams have formed a complete industrial chain and are using high-tech methods to operate.

First, the fabrication of credentials. In the past, opening a financial account required corporate verification. Now, scammers specialize in obtaining "legitimate company" credentials, which they then forge and sell to those who want to make illegal stock recommendations, with prices ranging from a few hundred to several thousand yuan. This means that the "official financial institution" accounts you see could actually be operated by fraudsters.

Second, AI-driven identity theft bypasses biometric detection. Platforms used to require a legal representative to perform certain actions for verification. Scammers have found a way around this with AI face-swapping technology. The news describes a scenario where a system asked a female representative to perform actions, but a man actually operated the system, using technology to make the female on the screen perform the required actions, thus deceiving the system.

This shows that scammers' technical skills have caught up with or even surpassed some platforms' defenses. They are no longer individual actors; they are organized, technologically advanced, and part of a well-structured criminal network.

5. The Dilemma of Regulation: Separating Education from Fraud

This is the ultimate challenge for all platforms: Where is the line between legitimate information and fraud?

Financial content is particularly sensitive, as it directly affects users' finances.

  • A comment like "I'm optimistic about this stock" could be a genuine opinion or a trick to lure investments.
  • An insurance tutorial could be a helpful sharing or a tactic to sell insurance.

If the rules are too loose, scammers will slip in and users will lose their money. If the rules are too strict, legitimate financial education and communication will be suppressed, and people will be afraid to speak out.

The news mentions that in April this year, eight departments issued the "Financial Product Online Marketing Management Measures," which came into effect on September 30th. The main idea is that only financial institutions and their authorized platforms are allowed to sell financial products online.

REDnote has also released the "Community Financial Ecology Convention" to clarify the rules. Nevertheless, regulation remains a cat-and-mouse game. Scammers will study the rules, platforms will upgrade their technologies, and scammers will adapt their methods...

In summary:

This news tells us that the "gray market" in online finance is undergoing a technological upgrade and industrialization. Scammers are no longer relying on simple tactics; they use disguise, technical countermeasures, and coordinated efforts to carry out their scams.

For the average person, this means:

1. Be wary of perfect strangers offering stock recommendations and asking to add you on WeChat; it's likely a trick.

2. Don't trust codes, poems, or casual conversations that seem to offer investment advice; be cautious if they involve financial advice.

3. Compliance is essential: genuine financial knowledge sharing won't encourage private transactions or promise guaranteed profits.

Platforms and regulators are working hard, but as users, our own vigilance is the best defense. Scammers' methods may change, but our human tendency to seek quick gains remains a constant threat.