Apr 11, 2025
Cyware Daily Threat Intelligence, April 11, 2025
Bots don’t sleep and AkiraBot proves it. Since late 2024, this spam operation has flooded over 400,000 websites, zeroing in on small businesses using platforms like Shopify, Wix, and Squarespace. The messages push shady SEO services, powered by AI-generated content to dodge filters. With rotating domains, CAPTCHA bypass tools, and an expanding reach into live chats and comment sections, AkiraBot is becoming harder to pin down.
One bug, admin access - just like that. A critical flaw in the OttoKit WordPress plugin is being actively exploited, allowing attackers to create admin accounts and take over sites. Only some configurations are vulnerable, but where it hits, it hits hard.
When a checkout page starts asking for your card details twice, something’s wrong. A WordPress site was found hosting a fake credit card form. The malicious script captured payment info and funneled it to a freshly registered domain, designed to look harmless, but built to steal.