Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

Funksec Ransomware Decryptor was published for free after the group was dormant

Skechers make kids shoes with hidden air tag compartments

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Akirabot bypasses Captcha protection and targets 420,000 sites with Openai-generated spam
Identity

Akirabot bypasses Captcha protection and targets 420,000 sites with Openai-generated spam

userBy userApril 10, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 10, 2025Ravi LakshmananWebsite Security/Cybercrime

Openai-generated spam

Cybersecurity researchers have revealed details about an AI-powered platform called Akirabot, used in Akirabot, comments sections and contact forms, facilitating suspicious search engine optimization (SEO) services such as Akira and ServiceWrapgo.

“Akirabot has targeted more than 400,000 websites since September 2024 and has successfully spamed at least 80,000 websites,” Sentinelone researchers Alex Delamotte and Jim Walter said in a report shared with Hacker News. “Bots use OpenAI to generate custom outreach messages based on the purpose of the website.”

Cybersecurity

The targets for the activity include contact forms and chat widgets that exist on small to medium business websites, and the framework shares spam content generated using Openai’s leading language model (LLMS). What sets the “sparse” Python-based tool stand apart is the ability to create content so that spam filters can be bypassed.

Bulk messaging tools are believed to be in use since at least September 2024, starting with the name “Shopbot”, which appears to be a reference to a website using Shopify.

Over time, Akirabot has expanded its targeting footprint to include sites developed using GoDaddy, Wix, Squarespace, and sites with general contact forms and live chat widgets built using Reamaze.

The core of the operation, which is generating spam content, is facilitated by leveraging the OpenAI API. The tool also provides a graphical user interface (GUI) to select a list of targeted websites and customize the number that can be targeted at the same time.

“Akirabot creates custom spam messages for the target website by processing templates that contain a general outline of the types of messages the bot should send,” the researchers said. “The template is processed by a prompt sent to the Openai chat API and generates customized outreach messages based on the content of the website.”

Openai-generated spam

Source code analysis revealed that Openai clients use the GPT-4O-MINI model and are assigned the role of “helper assistants to generate marketing messages.”

Another notable aspect of this service is that it can avoid Captcha Barriers on spam websites of scale and avoid network-based detection by relying on proxy services typically provided to advertisers. The targeted Captcha service consists of Hcaptcha, Recaptcha and CloudFlare Turnstile.

To achieve this, BOT’s web traffic is designed to mimic legitimate end users, using various proxy hosts in SmartProxy to obscure the source of traffic.

Akirabot is configured to log activity in a file named “submissions.csv” which records both successful and unsuccessful spam attempts. Examining these files revealed that over 420,000 unique domains have been targeted so far. Additionally, success metrics related to Captcha bypass and proxy rotation are collected and posted to the telegram channel via the API.

In response to the findings, Openai invalidated the API keys and other related assets used by threat actors.

Cybersecurity

“The author or author has invested a great deal of effort in the bot’s ability to bypass commonly used Captcha technology, demonstrating that operators are motivated to violate service provider protection,” the researcher said. “Akirabot’s use of LLM-generated spam message content exemplifies the new challenges AI poses to protecting websites against spam attacks.”

This development coincides with the emergence of a cybercrime tool called Xanthorox AI, sold as an all-in-one chatbot that handles code generation, malware development, vulnerability exploitation, and data analysis. The platform also supports real-time voice calls and voice-based interactions via asynchronous voice messaging.

“The Xanthorox AI comes in five different models, each optimized for different operational tasks,” Slashnext said. “These models run entirely on local servers controlled by sellers rather than deployed through public cloud infrastructure or exposed APIs. This local-first approach significantly reduces the likelihood of detection, shutdown, or traceability.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDeaths hit 184 after nightclub roof collapse in the Dominican Republic | News
Next Article Our Academic on Thailand’s bail before trial via royal insults | Political News
user
  • Website

Related Posts

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

July 30, 2025

Funksec Ransomware Decryptor was published for free after the group was dormant

July 30, 2025

Enabling remote hijacking via critical duffer camera defect ONVIF and file upload exploit

July 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

Funksec Ransomware Decryptor was published for free after the group was dormant

Skechers make kids shoes with hidden air tag compartments

2 How Uc Berkeley Dropout raised $28 million for AI Marketing Automation Startup

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

New Internet Era: Berners-Lee Sets the Pace as Zuckerberg Pursues Metaverse

TwinH Transforms Belgian Student Life: Hendrik’s Journey to Secure Digital Identity

Tim Berners-Lee Unveils the “Missing Link”: How the Web’s Architect Is Building AI’s Trusted Future

Dispatch from London Tech Week: Keir Starmer, The Digital Twin Boom, and FySelf’s Game-Changing TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.