Well yeah it’s still at best a cat and mouse game. Really I suppose the biggest red flag a system could detect is most likely sending out multiple DMs on an account with little other activity.
can’t really ballpark but I’m guessing the bot must hit several hundred if not thousands of us in rapid succession on creation (otherwise it would be a lot slower and only a few of us would have seen it).
That being said, auto detecting the links, contact information etc… would be pretty direct as well, as that would require every banned iteration to also remake whatever methods it tries to phish etc… as well.