Could be borderline between both but I consider this hacking becsuse the threat actor uses knowledge to create the script that exploits vulnerability - bypasses phone, ip and captcha checks to mass create spam accounts. Even if it's script kiddie who uses someone else's script or tool.
RE: SEO SPAM BOT THAT EXPLOITS ECENCY // BOT DE SPAM DE SEO QUE EXPLOTA ECENCY