This I think leads to a sort of toupee fallacy - where because you can spot the really bad examples you feel confident that you can identify the much better, more subtle examples. If an account which has only made 50 comments (all of which are very generic) makes 20 comments in a single month explicitly recommending ImageGeneratorDeluxeProMax then sure, you can guess they might not be legit. But if an account runs for a longer period of time and makes a lot more general organic contributions then if 1 in 500 of their comments are in favour of a particular product then it's harder to say.
I think ultimately account age is the only thing that will be difficult to replicate at scale. I know people buy older accounts but there is still a fundamental difficulty in obtaining them in sufficient numbers. And yes, obviously that will mean disregarding the many millions of legitimate accounts that are under (say) 2 or 3 years old. There is also no easy way of hiding accounts under a certain age when searching Reddit via Google.
By allowing uses to hide user profiles Reddit has also made detecting potentially bad actors that little bit more difficult. And from experience it feels like a large proportion of accounts now have hidden post histories. (It might also be the default for new accounts, I'm not sure).