OTP Bot
An OTP bot is an automated calling or texting service criminals use to trick victims into revealing one-time passcodes, defeating SMS and app-based MFA at scale.
An OTP bot is an automated service — typically rented through Telegram channels on a subscription basis — that places scripted phone calls or sends texts designed to trick victims into revealing their one-time passwords. OTP bots industrialize what used to require a skilled social engineer: defeating code-based multi-factor authentication, one convincing robocall at a time.
How it works
The attacker starts with credentials already in hand, usually from a breach dump or an infostealer log. When they attempt to log in to the victim's bank, email, or crypto exchange, the real service sends the victim a legitimate verification code. At that exact moment, the bot calls the victim, impersonating the service's fraud department with professional voice prompts: "We've detected a suspicious login. To block it, please enter the code we just sent you." The victim, seeing a genuine code arrive from the genuine sender, types or speaks it into the call — and the bot relays it to the attacker, who completes the login before the code expires. Better kits let the operator configure the impersonated brand, caller ID, language, and script, and report captured codes back in real time.
The same mechanics work against app-generated codes, since the bot does not care where the code came from — only that the victim reads it out. What OTP bots cannot capture is a credential that never produces a human-readable code at all.
How to defend
For individuals, one rule defeats every OTP bot: a real bank or IT department will never call and ask for a verification code — codes are for you to type into a site you navigated to, never to share with a caller. Organizationally, treat OTP bots as part of the broader MFA bypass landscape: move high-value roles to phishing-resistant MFA, which generates nothing a victim can be talked into revealing, and include voice-channel scenarios in awareness training and simulations — the same conditioning that blunts vishing generally, covered in depth in our vishing and smishing defense guide.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo