NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search Engines

Mingxuan Liu, Zhongguancun Laboratory; Yunyi Zhang, Tsinghua University and National University of Defense Technology; Lijie Wu, Tsinghua University; Baojun Liu, Tsinghua University and Zhongguancun Laboratory; Geng Hong, Fudan University; Yiming Zhang, Tsinghua University; Hui Jiang, Tsinghua University and Baidu Inc; Jia Zhang and Haixin Duan, Tsinghua University and Quancheng Laboratory; Min Zhang, National University of Defense Technology; Wei Guan, Baidu Inc; Fan Shi, National University of Defense Technology; Min Yang, Fudan University

NOKEScam (NOn-sense KEyword Spear scam) is an emerging fraud technique. NOKEScam uses uncommon and usually non-sense keywords (NSKeywords) as vectors to lure victims without complex Black Hat SEO techniques. The obscure NSKeywords ensure the top search results as only NOKEScam pages are exactly matched, misleading victims into trusting them. NOKEScam severely impacts victims and search engines, but its uniqueness has hindered prior research and efficient detection methods.

In this paper, we report on joint work with a leading Chinese search engine to combat NOKEScam. Based on an empirical study, we identified three key observations and developed a lightweight detection system. This system can process about 2 billion URLs within one hour. Over seven months, we identified 153,975 NSKeywords across 68,863 domains. Our measurement demonstrated that leveraging search engine trust endorsement, NOKEScam websites attract an average of over 30k page views daily, indicating significant fraudulent profit potential. Driven by this, attackers persist despite search engine crackdowns, employing evasion tactics like using more domain names. Despite these tactics, our detection system remains effective, significantly suppressing the impact of NOKEScam, with a 194-fold reduction in real-world user complaints. Our findings reveal emerging fraud activities and offer valuable governance lessons for the security community.

Category: 
Short Presentation

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {308130,
author = {Mingxuan Liu and Yunyi Zhang and Lijie Wu and Baojun Liu and Geng Hong and Yiming Zhang and Hui Jiang and Jia Zhang and Haixin Duan and Min Zhang and Wei Guan and Fan Shi and Min Yang},
title = {{NOKEScam}: Understanding and Rectifying {Non-Sense} Keywords Spear Scam in Search Engines},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
isbn = {978-1-939133-52-6},
address = {Seattle, WA},
pages = {4779--4798},
url = {https://www.usenix.org/conference/usenixsecurity25/presentation/liu-mingxuan},
publisher = {USENIX Association},
month = aug
}