Skip to content
VECTOR WIREAI INTELLIGENCE
UTC

x47.c botnet drains AI API credits via stolen keys targeting xAI, OpenAI

A new Windows botnet called x47.c includes a dedicated mode to exhaust paid AI credits on xAI Grok and OpenAI using stolen API keys, sold as a turnkey…

A new Windows botnet called x47.c includes a dedicated attack mode designed to exhaust victims' paid AI credits on xAI Grok, OpenAI, and compatible chat APIs, according to research published by Qrator and reported by SecurityWeek1.

The botnet, sold by a threat actor operating under the handle WraithTools, bundles distributed denial-of-service capabilities, credential theft, SOCKS5 proxies, and what its operator calls an "AI API drain" method. In early August, WraithTools listed the base package at $200, a DDoS add-on at $150, and the full suite at $950.

How the AI drain works

The botnet's command-and-control panel exposes 18 attack methods, including HTTP floods, slow HTTP, TCP and UDP floods, TLS stressing, and reflection/amplification techniques. The AI drain mode stands apart: an operator supplies a model name and a valid API key for a targeted account on OpenAI, xAI Grok, or a compatible chat API, and the botnet fires requests directly at the provider to consume credits or rack up charges.

Because those requests route straight to the AI provider rather than through the victim's application, the victim's website can remain reachable while the account funding its AI features is silently emptied. The botnet also uses AI to maintain persistence on infected hosts.

A pattern of credential-driven AI abuse

The x47.c disclosure lands weeks after Anthropic forced logouts, pulled saved payment methods, and issued refunds to a subset of Claude users whose active sessions were hijacked by infostealer malware, which drained their usage credits[2]. That incident demonstrated that stolen session tokens alone can convert compromised endpoints into open billing channels on AI platforms.

The broader threat surface has drawn coordinated industry attention. On August 27, OpenAI, Anthropic, Microsoft, Amazon Web Services, Google, Advanced Micro Devices, and more than 100 other organizations signed an open letter warning that defenders have only months to prepare for AI-enabled cyberattacks[3]. OpenAI separately committed $1 billion in subsidized model access and technical support to extend its Daybreak cyber defense stack to critical-infrastructure defenders[1].

ANALYSIS The x47.c botnet operationalizes a risk that the Anthropic incident exposed on a per-user basis: once an attacker holds a valid API key or session token, draining an AI account requires no exploit against the platform itself. Packaging that capability inside a $950 turnkey botnet lowers the skill barrier and turns AI credit theft into a commodity service.