www.infosecurity-magazine.com 23 Sept 2026, 14:00 UTC

New Windows Botnet Targets Victims’ AI Credits in ‘Denial-of-Wallet’ Attacks

New Windows Botnet Targets Victims’ AI Credits in ‘Denial-of-Wallet’ Attacks
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

A previously undocumented Windows botnet called x47.c is being advertised with 18 attack methods, including a feature intended to exhaust victims’ paid AI credits. Qrator Research Labs reported on 23 September 2026 that the malware’s seller, WraithTools, promotes credential theft, SOCKS5 proxying and an AI-assisted persistence module.

The research was based on the seller’s advertisement, technical documentation, control-panel screenshots and follow-up messages; it does not establish that every advertised capability has been used in attacks.

The “AI API drain” command accepts a valid API key for OpenAI, xAI or a compatible chat API and sends repeated billable requests directly to the provider. Qrator described this as a denial-of-wallet attack: a victim’s website may remain operational while its underlying AI service consumes available credit. The seller reportedly marketed it against chatbots, AI-connected content management systems, trading bots and scanners, including for attacks on competitors.

Qrator said the cost depends on the account’s permitted overspend, and noted that anyone with a valid key could automate similar abuse. However, the documentation did not show that AI-site tokens stolen by the botnet are converted into API keys for this purpose.

Other advertised functions include HTTP, TCP and UDP floods, slow HTTP connections, TLS stress and reflection or amplification attacks, although Qrator found no test evidence supporting the claimed protection-bypass modes. The malware reportedly targets browser passwords, cookies and Discord tokens, while its “AI Stealth” feature uses Grok to select predefined persistence and concealment actions, including Windows Defender exclusions. An advertisement dated 3 August priced the botnet at $200–$950.

Qrator recommended revoking exposed AI keys, reviewing billing, setting spending limits and controlling automatic top-ups, alongside endpoint remediation and application- and network-layer DDoS protection.

View full article

Article by CyberSIXT