Evolution of OTP Bots
For years, multi-factor authentication (MFA) has been widely used as a trusted method for securing online accounts. By requiring a second form of verification, such as a code sent to a mobile phone, MFA adds an extra layer of protection against unauthorized access. However, as cybercriminal tactics evolve, even these security measures can be circumvented.
One such threat comes in the form of OTP Bot. These are automated programs designed to intercept sensitive information including one-time passwords. Cybercriminals use these bots as part of social engineering attacks, specifically calling victims to trick them into sharing their OTPs (and other sensitive information). This enables attackers to bypass MFA and gain unauthorized access to accounts.
OTP bots are programmed to dial a victim’s phone number, utilizing convincing voice and pre-recorded messages to manipulate them into disclosing sensitive information to the attacker (e.g., payment card details).
Traditionally, OTP bot tools came with predefined social engineering scripts tailored for different targets, such as banks, e-commerce merchants, government entities and other institutions. The common limitation along these bots was their reliance on pre-recorded and unmodifiable scripts.
Overtime, OTP bots have evolved. A notable example “Astaroth”1, an OTP bot service that introduced a key feature allowing users to upload their own audio files. The advancement enables attackers to craft custom social engineering scripts in any language or dialect, making their tactics more convincing.
In addition, Telegram has been a primary platform for the operation and distribution of OTP bots. These malicious tools were traditionally offered as standalone services within the messaging app’s ecosystem, making them easily accessible to cybercriminals.
However, unlike other OTP Bots, Astaroth is being distributed as a web-based application. This shift from Telegram to a web-based platform may attract a broader user base. Some cybercriminals consider Telegram less secure, particularly in light of recent events, including the arrest of Telegram founder Pavel Durov. As a result, Astaroth could appeal to more sophisticated fraudsters who prioritize anonymity and operational security, further escalating the threat of account takeovers.
While Astaroth allows for customized audio, its core social engineering script remains pre-determined. This means attackers still need to anticipate various scenarios and create scripts for each. What if, instead, the bot could adapt on the fly, crafting personalized scripts based on the victim’s responses and the information available about them? This level of dynamic manipulation is now becoming possible with AI-powered script generation services.
Recently we profiled a service called “Valley AI” that uses artificial intelligence to perform calls to victims. Valley AI has a number of advanced features; for example, it is able to use a natural-sounding voice with ambient background sounds to resemble an actual employee at a call center. Not only can it impersonate but also adapt dynamically to a conversation to extract information from its victims, thus making it very hard to identify such call as being conducted by a bot and not a real human.
The evolution of OTP bots, from simple pre-recorded scripts to AI-powered dynamic manipulation, presents a serious and escalating threat to online security. Astaroth’s custom audio feature and web-based distribution represent significant advancements for cybercriminals, lowering the barrier to entry andincreasing the potential reach of these attacks. However, the emergence of AI-driven services like “Valley AI,” capable of real-time script generation and personalized manipulation, marks a paradigm shift. These sophisticated bots can adapt to individual conversations, making them incredibly persuasive and difficult to detect. The ability to impersonate human voices, incorporate ambient sounds, and dynamically adjust tactics makes these attacks far more potent than their predecessors. This rapid evolution underscores the urgent need for individuals and organizations to adopt stronger security measures and remain vigilant against these increasingly sophisticated threats. The game has changed, and our defenses must evolve with it.