Back to Newsroom
Threat Intel

New Botnet Drains Victims' Paid AI Credits, Not Just Data

A Windows-based botnet advertised on criminal forums for up to $950 doesn't just exfiltrate data — it can spend a victim's paid AI API credits until the account runs dry, alongside DDoS floods and proxy abuse.

New Botnet Drains Victims' Paid AI Credits, Not Just Data

A newly documented Windows botnet, sold under the name x47.c "Fast Flux Edition," adds an unusual capability to the usual malware playbook: instead of only stealing data or flooding a target with traffic, it can spend the victim's own paid AI API credits until the balance — or the wallet — is empty.

What happened

The botnet was advertised on underground forums starting in early August 2026, with pricing tiers reported at roughly $200 for a base package, $150 for an optional DDoS module, and $950 for the full bundle. Security researchers who reviewed the listing and an associated command-and-control panel found no evidence of how many machines are infected, how much attack capacity the operators actually control, or any confirmed financial losses tied to the tool. What is documented is the design: a modular Windows implant built to combine theft, service disruption, and — the new piece — billing abuse against AI provider accounts.

The AI-drain feature requires a valid API key tied to the account that will be charged. Once the operator supplies a key and picks a target model, infected machines send requests directly to the AI provider — bypassing the victim's own website or application entirely. The documented mode targets OpenAI, xAI, and compatible chat APIs.

Why it matters

Every accepted request against a paid AI account consumes credits or generates a charge. Researchers describe this as a denial-of-wallet risk, distinct from a denial-of-service: a targeted site or app can stay online and reachable while its AI-powered features — chatbots, automated triage, trading logic, content pipelines — stop working the moment the account hits its balance or spending cap. Because the requests go straight to the AI provider, they never touch the target's own infrastructure, so traffic filtering or a web application firewall offers no protection. Automatic top-up settings, meant to keep a service running, could instead let the drain continue and rack up a larger bill before anyone notices.

The seller's listing also advertises theft of wallets and AI-service tokens, but there is no evidence in this reporting that stolen tokens are automatically converted into usable API credentials for the drain feature — the gap between "advertised" and "demonstrated" is worth keeping in mind. Separately, a documented case involving a stolen Gemini API key showed unauthorized use running up more than $82,000 in charges in two days; that incident is unrelated to x47.c and doesn't establish what this botnet has actually cost anyone, but it illustrates how expensive an exposed AI key can get.

Beyond the AI-drain angle, the panel offers a familiar toolkit: HTTP floods, slow-connection attacks, TCP/UDP floods, TLS connection stress, and reflection-based methods, with each bot running one attack at a time and falling back to alternate command servers if its primary one goes down. The panel reportedly manages six domains and eight IP addresses without exposing their values — a fast-flux-style setup meant to keep command infrastructure resilient, though several hostnames may ultimately resolve to a single server.

A stealth module reportedly uses xAI's Grok to assess an infected host and choose from a preset list of maintenance actions — for example, which persistence method (startup entries, scheduled tasks) to use as a fallback if another fails. Target selection stays with the human operator; the AI component only helps the malware behave more reliably on the machines it already controls. Other modules harvest browser data and turn compromised systems into SOCKS5 proxies, letting operators route traffic through victim networks and manage stolen material remotely.

What to do

  • Treat any AI API key as a sensitive credential: store it like a password, scope it to the minimum required, and rotate it on any suspicion of exposure.
  • Set hard spending limits on AI provider accounts and think carefully before enabling automatic top-ups, which can turn a drain attempt into a larger bill instead of a service outage.
  • Monitor AI API usage for sudden volume or cost spikes from unfamiliar IP ranges or at unusual hours.
  • If a host shows signs of compromise, isolate it, remove persistence mechanisms, and assume any stored credentials, cookies, and tokens on that machine are burned — revoke and reissue them rather than relying on cleanup alone.
  • Prepare for combined scenarios: a single compromised environment can face credential theft, network floods, and AI billing abuse at the same time.

This report documents an available attack toolkit, not a confirmed wave of successful campaigns. The underlying warning still holds: a paid AI account is now another resource attackers can exhaust, even when the website or service in front of it stays up.

SHARE