Finding: one coordinated spam campaign, not a language problem
Most targets reuse short Han-script recruitment or payment lures, a Telegram mention, rotating digits, and a narrow set of display-name patterns. They arrive through many fresh accounts and repeat the same normalized templates across groups.
Entry-time metadata alone is not accurate enough for a blanket ban. The reliable design is a strict join gate for known fingerprints, followed by limited permissions until the first message is classified.