Hackers Sell an AI Token-Draining Service That Can Run Up Huge Bills for Victims

27.09.2026 4 minutes Author: Newsman

Researchers have discovered a new Windows botnet called x47.c, whose operators advertise an AI API drain feature designed to exhaust balances and credits on artificial intelligence services. Instead of simply overwhelming a website, attackers can send paid requests directly to an AI provider and force the victim to pay for a massive number of tokens.

The new tool was discovered by Qrator Labs. x47.c is being sold as a ready-made Windows botnet platform and, in addition to traditional DDoS capabilities, offers a dedicated attack mode targeting AI APIs. The seller openly advertises it as a way to “burn OpenAI, xAI, and compatible chat APIs with a heavy stream of completion requests,” putting pressure not only on bandwidth but also on token usage and costs.

To carry out the attack, the operator currently needs a valid API key for the account they want to drain. The botnet is then provided with the model name and begins sending requests directly to the AI service provider. In a Qrator Labs report, researchers explain:

“The operator provides this key and the model name. The bot then sends requests directly to the provider. If accepted, these paid requests consume credits or generate additional charges.”

This type of attack is known as denial-of-wallet. Unlike a traditional DDoS attack, the goal is not necessarily to make a website unavailable. The victim’s website or application may continue operating while its AI features gradually exhaust the available balance or generate additional costs. The scale of the potential losses depends on the initial balance, automatic top-up settings, and permitted spending limits.

The attacker is advertising a botnet.

Researchers spoke with the seller, who uses the alias WraithTools. According to him, the so-called “AI DDoS” can be used against projects built through vibe coding, content management systems, and AI assistants that rely on API keys to access models. The attacker also stated:

“You can sell this as a service for eliminating competition. There are plenty of Jarvis-style systems on social media right now.”

Because the requests are sent directly to the AI provider, this approach can also bypass traffic filtering that the service owner has placed in front of their website. The report does not clarify whether botnet operators can send requests through the victim’s own chatbots, although the seller claimed that such services usually have timers or blocking mechanisms.

The Botnet Is Sold as a Full Package for $950

The AI API drain feature is only one of x47.c’s capabilities. The base version of the platform sells for $200, while the DDoS module costs an additional $150. The full $950 package also includes credential theft, a SOCKS5 proxy, and AI-assisted persistence mechanisms.

In total, the seller claims support for 18 DDoS attack methods. These include HTTP floods, slow HTTP connections, TCP and UDP floods, TLS connection exhaustion, as well as various reflection and amplification techniques. The bots receive commands through a C2 server and can quickly switch to alternative domains and IP addresses if the main communication channel stops working. Researchers identified at least six domains and eight IP addresses used by the attackers’ infrastructure.

Botnet control panel.

At the same time, the x47.c build itself also uses AI APIs. To operate stealthily and maintain persistence on an infected system, the platform connects to xAI Grok, which assesses the state of the compromised computer and selects one of several predefined actions. To use this feature, the operator must add their own xAI API key when creating the build. Through the control panel, they can also download, update, and remove programs, including additional malware.

Separate modules allow attackers to generate additional revenue from infected computers. The malware can steal passwords and cookies from browsers, collect Discord tokens, while the SOCKS5 module turns compromised devices into proxies for routing third-party traffic. All of these functions are managed from a single desktop control panel.

How to Protect Against Such Attacks

Qrator Labs advises companies and developers that use AI APIs to limit potential financial losses at the account level. This primarily means setting strict spending limits and carefully controlling automatic balance top-ups so that a stolen or compromised key cannot be used to generate paid requests without restriction.

The emergence of x47.c shows that stolen API keys are becoming more than just a way for cybercriminals to use someone else’s AI models for free. They can now also be used as a tool for directly draining an account owner’s funds, while conventional website DDoS protection may offer little or no help in such a scenario.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.
↑