Safety & Security

Apate's 350,000 AI bots are wasting scammers' time

Apate runs roughly 350,000 AI bots that pick up scam calls and absorb phishing texts, while ETH Zurich says LLM-powered honeypots trap AI attackers for significantly longer.

AI Is Getting Really Good at Messing With Cybercriminals
AI Is Getting Really Good at Messing With CybercriminalsAI-generated
By Rebecca Stone5 min read

Updated

Why it matters

  • Apate operates approximately 350,000 AI bots that intercept scam calls and phishing texts, per CEO Dali Kaafar
  • The platform has collected more than 250,000 pieces of fraud intelligence in real time, including URLs and mule accounts
  • Apate scam calls regularly extend past two hours, according to founder Dali Kaafar
  • ETH Zurich researcher Mark Vero says LLM-powered honeypots keep agentic AI attackers engaged 'significantly longer'
  • Apate's bot network is used by banks and supported by telecom carriers in production

A Sydney-based anti-scam firm operates a fleet of roughly 350,000 AI bots that pick up phone fraud calls and absorb phishing texts, the company's founder said this week.

Apate — named after the Greek goddess of deception — has spent two years training conversational systems designed to intercept scam calls, infiltrate fraud chat groups online and reply to fraudulent messages. The aim is straightforward: keep criminals engaged long enough that they cannot reach real victims at scale.

"What we really like to think is that we're building the perfect victims for scammers," founder and CEO Dali Kaafar told Kernel Panic, the privacy and security newsletter published by Wired journalists Lily Hay Newman and Matt Burgess.

Kaafar framed each minute of scammer time on a bot as stolen capacity. "A minute that a scammer is talking to a bot or an agent is a minute where you're probably saving hundreds, if not thousands of possible people being reached out to by that exact same scammer," he said.

He cited automated dialing tools as the multiplier that turns one engaged scammer into a mass-production operation.

How Apate's bot network actually operates

Apate's bots answer inbound calls, populate scam chat rooms online and respond to fraudulent text messages. Each persona carries a distinct personality, language set and digital profile.

The platform is in production use at banks and runs with the support of telecom carriers, Kaafar said. The system fields around 350,000 bots. Those bots have collectively collected more than 250,000 pieces of fraud intelligence in real time, he added, ranging from scam URLs to money mule accounts and bank routing details.

That intelligence feeds back to financial institutions, where it supports account freezes, takedown requests and cross-bank blacklist maintenance.

The bots mirror real people with deliberate friction. Some maintain WhatsApp accounts; some don't. "Sometimes they pick up the phone, sometimes they just actually hang up on the scammer saying, 'I'll come back to you later,'" Kaafar said.

The pacing matters. A bot that responds too eagerly tips off the scammer. A persona that engages believably — skeptical but not dismissive — extends the contact window.

Can the bots really hold a two-hour conversation?

Calls routinely run past two hours, Kaafar told Kernel Panic. The newsletter tested a public demo of the system, with two writers working in tandem against one bot, "Lucy," alongside a "financial adviser" persona called "Mickey."

After six minutes of pitching an obviously bogus crypto opportunity, neither tester landed the AI as a victim. The publication described the reply timing as natural, even with two humans coordinating against one persona.

The test was anecdotal. It captured the design objective: a victim that resists the scam, just not instantly.

Why banks and telecoms are paying for it

Banks fund Apate's deployment because fraud losses translate directly into chargebacks and write-offs. Telecoms support the system because fraudulent calls erode consumer trust and raise regulatory exposure.

Apate packages its intelligence as a paid feed for institutional customers. The bot network is effectively an early-warning sensor array, with each conversation a datapoint.

The model resembles spam-the-spammers experiments that predate generative AI. Researchers and hobbyists previously ran automation to drown scammers in pointless exchanges. Apate has converted that idea into sustained, bank-grade infrastructure.

Where AI fits in cybersecurity's broader arsenal

Apate is one of several active attempts to weaponize generative AI for defensive use. Honeypots — decoy systems designed to lure attackers, study their methods and burn their time — have been running in security research for decades.

Open-source providers have started integrating large language models into those honeypots, according to Mark Vero, a doctoral researcher at ETH Zurich's computer science department.

LLM-driven honeypots keep AI attackers engaged "significantly longer" than predictable ones, Vero told Kernel Panic. "The agentic attackers are much more convinced by the LLM simulated honeypots and they also mark them as actual honeypots at a much lower rate," he said.

Vero said the implications reach commercial defense. "If these systems are built well enough, then I think it's quite advantageous for defenders," he said.

Honeypots target the pre-attack phase, before a real user or system is engaged. Apate's bots operate downstream, after the scammer has already picked up the phone. Together, the two approaches cover opposite ends of the kill chain.

What limits the trick

Even with 350,000 bots in circulation, Apate cannot cover global call volume. Cybercriminals launch billions of scam messages a year, with the most organized operations running physical, industrial-scale calling sites.

Professional scambaiters have publicly trolled scammers for years, often filming their work. Law enforcement has infiltrated scam networks, seized infrastructure and arrested ringleaders. None of those efforts have reversed the expansion of online fraud, the newsletter noted.

Generative AI is widening the gap on both sides. Cheap language models now draft multilingual phishing lures; voice synthesis replicates a target's relative in real time. Apate-style defenders and ETH-style honeypots try to neutralize that advantage.

The arms race is detectable in shared code. Open-source honeypot providers increasingly incorporate LLMs into their systems to make them appear more realistic, Vero said. Defenders and attackers both contribute patches to shared toolkits. Capability upgrades cut both ways.

Kernel Panic's own finding captures the gap: even with Apate's massive swarm of bots on the case, "it's only a matter of time before you get your next scam call or text."

The defender case so far

The strongest empirical signal defenders can point to is data volume. Apate's 250,000 pieces of fraud intelligence give banks something consumer fraud reports never delivered: contemporaneous, structured evidence of active operations.

Vero's group published its honeypot findings openly and intends the work to be reproduced. Open-source defenders can fold the same techniques into their own tooling at marginal cost.

For now, the defensive case is straightforward: keep one scammer on the phone for two hours, capture signals on a few hundred operations, and another batch of victims is delayed by minutes that compound across the swarm.

The economics tilt toward whichever side is willing to spend compute without supervision. Generative AI made the supply of that compute elastic on both ends, and defenders are now spending their share in the same currency the attackers use.

Original: news.virginmediao2.co.uk

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

239 articles

Related articles

  1. OpenAI Disrupts Cambodia-Based Scam Network That Used ChatGPT
  2. Microsoft Disrupts EvilTokens, AI Chatbot Platform Behind 12,000 Account Hacks
  3. INTERPOL: AI Supercharges Existing Cybercrime, Not a New Threat
  4. OpenAI Bans Cambodia-Based Accounts Running AI Dating Scams
  5. OpenAI Maps the Anatomy of AI-Enabled Romance Scams

« Previous articleNext article »