AkiraBot Reportedly Used OpenAI to Spam Website Chats and Contact Forms at Scale
SentinelLabs reported that unknown operators used AkiraBot, a Python framework, plus OpenAI's chat API to generate customized SEO spam and bypass CAPTCHAs, posting via SMB websites' contact forms and Reamaze-style chat widgets. Researchers assessed >400k domains were targeted and ≥80k successfully spammed since 09/01/2024. OpenAI said the API key was disabled after disclosure.
- Date it happened
- 2024-09-01
- Organisation involved
- Malicious actors, Unknown AkiraBot operators
- Product, system or model
- Telegram, SmartProxy, Selenium WebDriver, reCAPTCHA, OpenAI Chat Completions API, NextCaptcha, headless Chrome, hCAPTCHA, FastCaptcha, CAPTCHA, Capsolver, BeautifulSoup, AkiraBot
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.