We were hit with a wave of spambot account creations and posts over the course of the last 4 to 5 days. It started around Thursday last week. I have deleted probably 100+ accounts since then. On a normal day to day basis I end up deleting 2 or 3 accounts and the associated posts along with them. However starting late week we were hammered by a wave of fake account creations.
I have since made changes to the registration process to make this more difficult for the spam bots. I have changed the Account Activation to "by admin" rather than by email. I have also changed the spambot countermeasures from using those easy to spoof images to a Q and A style check system.
We are also looking into other spambot solutions that might be rolled out depending on how well this change works.
Ideally, I would like to switch activation back to "by email" once we see if the Q and A check works. After a couple of days we should have some data on this.
edit: I have disabled the activation by admin and reverted back to user email about 1 week after implementing it and switch user registration to a set of challenge questions. This change has resulted in a 99% drop in spam (not scientific).