OpenAI API Exploited in Large-Scale Spam Campaign Targeting 80,000 Websites
  • 267 views
  • 2 min read

A sophisticated AI-powered spam campaign, dubbed "AkiraBot," has been discovered targeting over 400,000 websites, successfully spamming at least 80,000 of them since September 2024. This malicious framework leverages the OpenAI API to generate personalized spam content, effectively bypassing traditional spam filters and CAPTCHA protections. The campaign primarily targets small to medium-sized businesses (SMBs) using popular website builder platforms such as Shopify, GoDaddy, Wix, and Squarespace.

AkiraBot functions by analyzing a website's content to create customized promotional messages, primarily advertising dubious SEO services under the names "Akira" and "ServicewrapGO". This personalized approach makes the spam messages appear legitimate, significantly increasing their chances of reaching their intended targets. The bot leverages the GPT-4o-mini model through the OpenAI API, instructing it to act as a "helpful assistant that generates marketing messages" based on the website's content. Researchers at SentinelOne traced the tool's development back to September 2024, identifying various versions with code names like "Shopbot," "GoDaddy," and "Wixbot," indicating continuous improvements to its targeting capabilities. Initially focused on contact forms, newer versions also target live chat widgets, including those provided by services like Reamaze.

AkiraBot's effectiveness is further enhanced by its ability to evade CAPTCHA challenges. It employs various techniques, including mimicking real user browser behavior and utilizing external CAPTCHA-solving services like Capsolver, FastCaptcha, and NextCaptcha. The bot also uses multiple proxy hosts to avoid network detection. The operators of AkiraBot meticulously track their progress, logging successful and failed spam submissions. As of January 2025, the bot had successfully spammed 80,000 websites. Success metrics related to CAPTCHA bypass and proxy rotation are also collected and posted to a Telegram channel via API.

In response to the discovery of AkiraBot, OpenAI has disabled the API key and other associated assets used by the threat actors. However, the emergence of this AI-powered spam campaign highlights the growing challenges of defending websites against increasingly sophisticated attacks. AkiraBot represents a concerning evolution in spam technology, demonstrating how AI can be used to create personalized messages that bypass traditional spam filters. Its ability to evade CAPTCHA protections and use sophisticated network evasion techniques makes it particularly effective at targeting SMBs. Website owners should remain vigilant and implement robust security measures to protect against these increasingly sophisticated attacks.


Written By
Deepika possesses a knack for delivering insightful and engaging content. Her writing portfolio showcases a deep understanding of industry trends and a commitment to providing readers with valuable information. Deepika is adept at crafting articles, white papers, and blog posts that resonate with both technical and non-technical audiences, making her a valuable asset for any organization seeking clear and compelling technology communication.
Advertisement

Latest Post


## Elon Musk's Optimus Robot: A Revolutionary Technology Set to Reshape the Future of Humanity Elon Musk's Tesla has been developing a general-purpose humanoid robot named Optimus, also known as the Tesla Bot, which is poised to revolutionize variou...
  • 375 views
  • 3 min

The smartphone landscape is bracing for a monumental clash in 2026 with the anticipated arrival of the iPhone 18 series and the Samsung Galaxy S26. Both tech giants are expected to unleash a wave of innovation, setting the stage for fierce competitio...
  • 118 views
  • 3 min

Mozilla Firefox is set to redefine the browsing experience with its latest innovation: the "AI Window" feature. This optional, open-source tool integrates an AI assistant directly into the browser, offering users intelligent support while maintaining...
  • 197 views
  • 2 min

## BMW's Electric Revolution: Unveiling the First All-Electric M3, a New Era of Performance and Innovation BMW is poised to redefine its performance legacy with the introduction of its first-ever all-electric M3, expected to begin production in Marc...
  • 376 views
  • 2 min

Advertisement
About   •   Terms   •   Privacy
© 2025 TechScoop360