Cybernews New x47.c Botnet Targets AI Services with API Draining Attacks
Article Content
- •x47.c botnet offers 18 attack methods, including AI credit draining.
- •Attackers can exploit valid API keys to execute denial-of-wallet attacks.
- •Qrator Labs recommends revoking exposed keys and monitoring billing.
A new Windows botnet, x47.c, has been discovered offering 18 attack methods, including a feature to drain AI credits from victims' accounts. This botnet, sold by a seller known as WraithTools, allows attackers to exploit valid API keys for services like OpenAI and xAI, executing a denial-of-wallet (DoW) attack. The botnet's capabilities include credential theft, SOCKS5 proxying, and various DDoS techniques. The AI API drain method sends repeated billable requests directly to the provider, bypassing the victim's application and keeping their website operational while exhausting AI credits. The total cost incurred by victims depends on their initial balance and any automatic top-up settings. Qrator Research Labs advises affected users to revoke exposed API keys, monitor their billing, and implement spending limits. The botnet is currently active and poses a significant threat to organizations using AI services.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track SystemBC and Qrator Research Labs in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Veradigm Data Breach Exposes Patient Information via Vendor Compromise Veradigm, a healthcare technology company, reported a data breach involving a third-party vendor's systems, where hackers accessed personal data, including Social Security numbers, of some patients. The breach was disclosed in an 8-K filing with the SEC on September 8, 2026. The unauthorized party obtained credentials…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…