AkiraBot: OpenAI AI-Powered Spam Campaign Hits the Web

In one of the most dangerous AI-driven digital attacks, information security researchers have revealed a malicious program named "AkiraBot".

This program flooded thousands of websites with fake messages, aiming to deceive their owners into purchasing fake search engine optimization (SEO) services.

According to concurring reports from SentinelOne (an American cybersecurity company) and The Hacker News, AkiraBot's activity began in September 2024. It targeted over 420,000 websites, actually succeeding in flooding at least 80,000 of them with spam messages.

The vast majority of these websites belong to small and medium-sized businesses (SMBs) operating on platforms such as Shopify, Wix, Squarespace, and GoDaddy.

A SentinelOne report detailed how AkiraBot operates.

The report revealed that the program uses OpenAI's API. It also relies on the GPT-4o-mini model to generate custom messages automatically sent to comment sections, contact forms, and even live chats on the targeted sites.

The messages were tailored in style for different types of websites to evade traditional detection systems.

For example, a construction company's website would receive a different message than one sent to a beauty salon's site.

However, AkiraBot's capabilities weren't limited to content creation. It could also bypass protection systems like CAPTCHA, thanks to its use of intelligent proxy services that mask the browsing source and mimic real user behavior.

Targeted systems included hCAPTCHA, reCAPTCHA, and Cloudflare Turnstile, enabling the bot to execute the attack on a large scale without drawing attention.

Analysis of the code revealed the tool uses a general template paired with custom instructions, which is then fed into the AI model to generate realistic-looking marketing messages.

An internal graphical user interface (GUI) was also observed, allowing the attacker to select the number of target websites and customize message content for each case.

SentinelOne reported that AkiraBot logged all its attempts, both successful and failed, in a file named "submissions.csv". It also sent performance reports directly to a Telegram channel, indicating the meticulous organization behind the attack.

In response, OpenAI disabled the API key associated with AkiraBot and announced it is continuing to investigate the incident.

The company also stated it is working on enhancing its systems to detect this type of abuse.

SentinelOne praised the cooperation of OpenAI's security team and their efforts in countering these types of threats.

Notably, AkiraBot is unrelated to the notorious Akira ransomware group. These attacks also coincide with the emergence of advanced hacking tools like "Xanthorox AI," which is used for developing malware and exploiting security vulnerabilities.

Security experts believe this incident highlights the growing challenges AI tools pose to internet security. This is particularly true as attackers increasingly rely on sophisticated language models to bypass technical safeguards and employ deceptive tactics that are difficult to distinguish from human behavior.

وأوضح ŲŖŁ‚Ų±ŁŠŲ±Ā SentinelOne Ų·Ų±ŁŠŁ‚Ų© عمل AkiraBot.

وكؓف Ų§Ł„ŲŖŁ‚Ų±ŁŠŲ± أن البرنامج ŁŠŲ³ŲŖŲ®ŲÆŁ… ŁˆŲ§Ų¬Ł‡Ų© برمجة Ų§Ł„ŲŖŲ·ŲØŁŠŁ‚Ų§ŲŖ الخاصة ŲØŁ€ OpenAI. ŁƒŁ…Ų§ ŁŠŲ¹ŲŖŁ…ŲÆ على Ł†Ł…ŁˆŲ°Ų¬ GPT-4o-mini ل؄نؓاؔ رسائل Ł…Ų®ŲµŲµŲ© ŁŠŲŖŁ… ؄رسالها ŲŖŁ„Ł‚Ų§Ų¦ŁŠŁ‹Ų§ ؄لى أقسام Ų§Ł„ŲŖŲ¹Ł„ŁŠŁ‚Ų§ŲŖ ŁˆŁ†Ł…Ų§Ų°Ų¬ Ų§Ł„ŲŖŁˆŲ§ŲµŁ„ ŁˆŲ­ŲŖŁ‰ المحادثات Ų§Ł„Ų­ŁŠŲ© داخل Ų§Ł„Ł…ŁˆŲ§Ł‚Ų¹.

ŁˆŲŖŁ… ŲŖŲµŁ…ŁŠŁ… الرسائل ŲØŲ£Ų³Ł„ŁˆŲØ مختلف Ł„ŁƒŁ„ Ł†ŁˆŲ¹ من Ų§Ł„Ł…ŁˆŲ§Ł‚Ų¹ Ł„ŲŖŁŲ§ŲÆŁŠ أنظمة Ų§Ł„ŁƒŲ“Ł Ų§Ł„ŲŖŁ‚Ł„ŁŠŲÆŁŠŲ©.

على Ų³ŲØŁŠŁ„ Ų§Ł„Ł…Ų«Ų§Ł„ŲŒ ŁŠŲ­ŲµŁ„ Ł…ŁˆŁ‚Ų¹ ؓركة ؄نؓاؔات على رسالة تختلف عن ŲŖŁ„Łƒ المرسلة Ł„Ł…ŁˆŁ‚Ų¹ ŲµŲ§Ł„ŁˆŁ† ŲŖŲ¬Ł…ŁŠŁ„.

Ų±ŲŗŁ… Ų°Ł„ŁƒŲŒ لم تقتصر قدرات AkiraBot على ؄نؓاؔ Ł…Ų­ŲŖŁˆŁ‰ ŁŁ‚Ų·ŲŒ ŲØŁ„ ŲŖŁ…ŁƒŁ‘Ł† Ų£ŁŠŲ¶Ł‹Ų§ من تجاوز أنظمة Ų§Ł„Ų­Ł…Ų§ŁŠŲ© Ł…Ų«Ł„ CAPTCHA، بفضل اعتماده على Ų®ŲÆŁ…Ų§ŲŖ بروكسي ذكية تخفي Ł…ŲµŲÆŲ± التصفح وتحاكي Ų³Ł„ŁˆŁƒ المستخدم Ų§Ł„Ų­Ł‚ŁŠŁ‚ŁŠ.

ŁˆŲ“Ł…Ł„ŲŖ الأنظمة المستهدفة hCAPTCHA وreCAPTCHA وCloudflare Turnstile، الأمر Ų§Ł„Ų°ŁŠ Ł…ŁƒŁ‘Ł†Ł‡ من ŲŖŁ†ŁŁŠŲ° Ų§Ł„Ł‡Ų¬ŁˆŁ… على نطاق واسع ŲÆŁˆŁ† لفت الأنظار.

ŁˆŁ…Ł† خلال ŲŖŲ­Ł„ŁŠŁ„ Ų§Ł„ŁƒŁˆŲÆ Ų§Ł„ŲØŲ±Ł…Ų¬ŁŠŲŒ ŲŖŲØŁŠŁ† أن الأداة ŲŖŲ³ŲŖŲ®ŲÆŁ… قالبًا عامًا ŲŖŁŲ±ŁŁ‚ معه ŲŖŲ¹Ł„ŁŠŁ…Ų§ŲŖ Ł…Ų®ŲµŲµŲ©ŲŒ Ų«Ł… ŁŠŲŖŁ… ŲŖŲŗŲ°ŁŠŲŖŁ‡ Ł„Ł„Ł†Ł…ŁˆŲ°Ų¬ Ų§Ł„Ų°ŁƒŁŠ Ł„ŲŖŁˆŁ„ŁŠŲÆ رسائل ŲŖŲ³ŁˆŁŠŁ‚ŁŠŲ© تبدو ŁˆŲ§Ł‚Ų¹ŁŠŲ©.

ŁˆŁ‚ŲÆ ŲŖŁ… Ų£ŁŠŲ¶Ł‹Ų§ Ų±ŲµŲÆ ŁˆŲ§Ų¬Ł‡Ų© Ų±Ų³ŁˆŁ…ŁŠŲ© ŲÆŲ§Ų®Ł„ŁŠŲ© تتيح للمهاجم اختيار Ų¹ŲÆŲÆ Ų§Ł„Ł…ŁˆŲ§Ł‚Ų¹ المستهدفة وتخصيص Ł…Ų­ŲŖŁˆŁ‰ الرسائل Ų­Ų³ŲØ ŁƒŁ„ حالة.

وأفادت SentinelOne أن AkiraBot ŁƒŲ§Ł† ŁŠŲ³Ų¬Ł‘Ł„ Ų¬Ł…ŁŠŲ¹ Ł…Ų­Ų§ŁˆŁ„Ų§ŲŖŁ‡ŲŒ الناجحة ŁˆŲ§Ł„ŁŲ§Ų“Ł„Ų©ŲŒ في ملف باسم "submissions.csv"، Ł…Ų¹ Ų„Ų±Ų³Ų§Ł„ ŲŖŁ‚Ų§Ų±ŁŠŲ± الأداؔ Ł…ŲØŲ§Ų“Ų±Ų© ؄لى قناة Ų¹ŲØŲ± ŲŖŲ·ŲØŁŠŁ‚ ŲŖŁ„ŁŠŲŗŲ±Ų§Ł…ŲŒ في Ų„Ų“Ų§Ų±Ų© ؄لى مدى Ų§Ł„ŲŖŁ†ŲøŁŠŁ… Ų§Ł„ŲÆŁ‚ŁŠŁ‚ خلف Ų§Ł„Ł‡Ų¬ŁˆŁ….

في Ų§Ł„Ł…Ł‚Ų§ŲØŁ„ŲŒ قامت OpenAI ŲØŲŖŲ¹Ų·ŁŠŁ„ مفتاح Ų§Ł„ŁˆŲ§Ų¬Ł‡Ų© Ų§Ł„ŲØŲ±Ł…Ų¬ŁŠŲ© المرتبط ŲØŁ€ AkiraBot، ŁˆŲ£Ų¹Ł„Ł†ŲŖ أنها ŲŖŲŖŲ§ŲØŲ¹ Ų§Ł„ŲŖŲ­Ł‚ŁŠŁ‚ في الحادث.

ŁƒŁ…Ų§ أفادت أنها تعكف على تطوير أنظمتها لرصد هذا Ų§Ł„Ł†ŁˆŲ¹ من Ų§Ł„Ų§Ł†ŲŖŁ‡Ų§ŁƒŲ§ŲŖ.

وأؓادت SentinelOne ŲØŲŖŲ¹Ų§ŁˆŁ† ŁŲ±ŁŠŁ‚ الأمان في OpenAI ŁˆŲ¬Ł‡ŁˆŲÆŁ‡Ł… في Ų§Ł„ŲŖŲµŲÆŁŠ لهذا Ų§Ł„Ł†ŁˆŲ¹ من Ų§Ł„ŲŖŁ‡ŲÆŁŠŲÆŲ§ŲŖ.

ŁŠŁŲ“Ų§Ų± ؄لى أن AkiraBot لا يرتبط ŲØŁ…Ų¬Ł…ŁˆŲ¹Ų© "أكيرا" Ų§Ł„Ų“Ł‡ŁŠŲ±Ų© Ų§Ł„ŲŖŁŠ تنؓط في هجمات Ų§Ł„ŁŲÆŁŠŲ©. ŁƒŁ…Ų§ تتزامن هذه الهجمات Ł…Ų¹ ŲøŁ‡ŁˆŲ± أدوات قرصنة متقدمة Ł…Ų«Ł„ "Xanthorox AI"، ŁˆŲ§Ł„ŲŖŁŠ ŲŖŁŲ³ŲŖŲ®ŲÆŁ… في تطوير Ų§Ł„ŲØŲ±Ł…Ų¬ŁŠŲ§ŲŖ Ų§Ł„Ų®ŲØŁŠŲ«Ų© ŁˆŲ§Ų³ŲŖŲŗŁ„Ų§Ł„ الثغرات Ų§Ł„Ų£Ł…Ł†ŁŠŲ©.

من Ł†Ų§Ų­ŁŠŲ© Ų£Ų®Ų±Ł‰ŲŒ ŁŠŲ±Ł‰ Ų®ŲØŲ±Ų§Ų” Ų£Ł…Ł†ŁŠŁˆŁ† أن هذه الحادثة ŲŖŲØŲ±Ų² Ų§Ł„ŲŖŲ­ŲÆŁŠŲ§ŲŖ Ų§Ł„Ł…ŲŖŲ²Ų§ŁŠŲÆŲ© Ų§Ł„ŲŖŁŠ تفرضها أدوات Ų§Ł„Ų°ŁƒŲ§Ų” Ų§Ł„Ų§ŲµŲ·Ł†Ų§Ų¹ŁŠ على أمن Ų§Ł„Ų„Ł†ŲŖŲ±Ł†ŲŖŲŒ Ų®Ų§ŲµŲ©Ł‹ Ł…Ų¹ Ų§Ų¹ŲŖŁ…Ų§ŲÆ Ų§Ł„Ł…Ł‡Ų§Ų¬Ł…ŁŠŁ† على نماذج Ł„ŲŗŁˆŁŠŲ© Ł…ŲŖŲ·ŁˆŲ±Ų© Ł„ŲŖŲ¬Ų§ŁˆŲ² Ų§Ł„Ų­ŁˆŲ§Ų¬Ų² Ų§Ł„ŲŖŁ‚Ł†ŁŠŲ© ŁˆŲ§Ł„Ų®ŲÆŲ§Ų¹ ŲØŲ£Ų³Ų§Ł„ŁŠŲØ يصعب ŲŖŁ…ŁŠŁŠŲ²Ł‡Ų§ عن Ų§Ł„Ų³Ł„ŁˆŁƒ Ų§Ł„ŲØŲ“Ų±ŁŠ.

  • Related Posts

    OpenAI’s o3 and o4-mini show higher hallucination rates
    • April 19, 2025

    In a controversial move, internal tests conducted by OpenAI have revealed that the new AI models “o3” and “o4-mini”, specifically designed…

    Google Officially Launches Gemini 2.5 Flash Preview: Its First Hybrid Model with Controlled Thinking
    • April 18, 2025

    Google has officially launched the preview version of its Gemini 2.5 Flash model within the Gemini app and developer platforms such…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    OpenAI’s o3 and o4-mini show higher hallucination rates

    OpenAI’s o3 and o4-mini show higher hallucination rates

    Google Veo 2: AI Video Creation Now Supports Arabic

    Google Veo 2: AI Video Creation Now Supports Arabic

    Google Officially Launches Gemini 2.5 Flash Preview: Its First Hybrid Model with Controlled Thinking

    Google Officially Launches Gemini 2.5 Flash Preview: Its First Hybrid Model with Controlled Thinking

    Grok Evolves: xAI Adds Free Grok Studio and New Memory Feature

    Grok Evolves: xAI Adds Free Grok Studio and New Memory Feature