Cybersecurity researchers have uncovered an AI-powered platform called AkiraBot that systematically spams website chats, comment sections, and contact forms to promote questionable SEO services like Akira and ServicewrapGO.
According to SentinelOne researchers, AkiraBot has targeted more than 400,000 websites and successfully spammed at least 80,000 since September 2024. The Python-based framework leverages OpenAI’s large language models to generate customized messages tailored to each website’s purpose, helping it bypass traditional spam filters.
Initially launched as “Shopbot” targeting Shopify sites, the operation has expanded to websites built on GoDaddy, Wix, and Squarespace, as well as those using generic contact forms and Reamaze chat widgets.
## Sophisticated Evasion Techniques
What makes AkiraBot particularly effective is its ability to:
– Use the gpt-4o-mini model to create personalized spam content
– Circumvent CAPTCHA barriers (including hCAPTCHA, reCAPTCHA, and Cloudflare Turnstile)
– Mimic legitimate user traffic patterns
– Utilize SmartProxy services to mask traffic sources
– Track success metrics through detailed logging
The bot’s operators have created a user-friendly interface that allows them to select target websites and control concurrent operations.
In response to these findings, OpenAI has disabled the API key and associated assets used by the threat actors.
This development coincides with the emergence of another AI-powered cybercrime tool called Xanthorox AI, which offers malware development, vulnerability exploitation, and other hacking capabilities through voice-based interaction and multiple specialized models running on private servers.
