Skip to content
Rush Commerce
AI & Automation4 min read

x47.c botnet drains your AI API credits with stolen keys

A $200 Windows botnet ships an AI API drain module that burns your OpenAI credits with your own key. Your site stays up while the bill lands.

Your AI API key is now a product category on the crimeware market. Qrator Research Labs published an analysis of a previously undocumented Windows botnet called x47.c, sold by a threat actor going by WraithTools. Buried in an otherwise ordinary DDoS panel is a feature that should change how you store credentials: an AI API drain command that takes a stolen key and spends your money with it until the account is empty.

What actually happened

Qrator's researchers documented the botnet's command-and-control panel in detail. The DDoS tab offers 18 attack methods — HTTP floods, slow HTTP, TCP and UDP floods, a TLS stresser, the usual reflection and amplification set — and sitting in that same list is "AI API drain."

The mechanics are blunt. The operator supplies a valid API key for OpenAI, xAI, or any compatible chat API, and the botnet sends repeated billable requests straight to the provider. Those requests never touch your application. As Qrator puts it, the site can stay perfectly reachable while the account behind its AI features runs out of credits. Your WAF sees nothing. Your rate limiter sees nothing. Your first signal is a spend alert, or a support ticket saying the chat widget stopped answering.

Qrator classifies this as a denial-of-wallet (DoW) attack and maps it to OWASP's LLM10:2025, unbounded consumption. It is not a new idea. It is newly productized.

The rest of the kit explains where the keys come from. The stealer module pulls browser passwords, cookies, Discord tokens, and — relevant here — tokens for AI sites. A SOCKS5 module turns infected machines into relays. And an "AI Stealth" module calls xAI's Grok to look at the infected host and pick from a set of predefined persistence and concealment actions: startup entries, scheduled tasks, Windows Defender exclusions, with local fallbacks when the model call fails.

Pricing, per Qrator: $200 for the base package, $150 for the DDoS add-on, $950 for the lot.

Why AI API key hygiene is now a cost control, not just a security control

A leaked key used to mean data risk. Now it means a bill. That changes who needs to care. Data exposure is a security conversation; a five-figure overnight charge on a card is a finance conversation, and it happens faster than your quarterly access review.

Your provider's spend controls are the actual mitigation. Not your firewall. OpenAI, Anthropic and the rest all support per-key budget caps and usage alerts. Set a hard monthly limit on every key, one key per service, and alert on daily spend — not monthly. A drain attack that hits a $200 ceiling is an incident. One that hits an uncapped org account is a crisis.

Keys on developer laptops are the exposure. The stealer targets browsers and local credential stores. If a production key lives in someone's .env, their shell history, or a browser-saved dashboard session, a commodity infostealer gets it for $200. Server-side secret managers with short-lived tokens are the fix, and they are not exotic anymore.

Rotate on a schedule you actually keep. Most teams we audit have keys older than the employees who created them. If you cannot list every live key and what it is for in under five minutes, you cannot respond to this attack — you can only pay for it.

Watch token spend like you watch uptime. Most small teams have a Slack alert for a downed server and nothing for a 40× jump in token consumption. The second one costs more and is quieter.

Key takeaways

  • Qrator Labs documented x47.c, a Windows botnet sold by WraithTools with 18 DDoS methods including an "AI API drain"
  • The drain module sends billable requests with a stolen API key directly to the provider, bypassing your app entirely
  • Your site stays up while the AI-backed features silently run out of credits — a denial-of-wallet attack, OWASP LLM10:2025
  • The bundled stealer harvests browser passwords, cookies, Discord tokens and AI-site tokens, which is where the keys come from
  • An "AI Stealth" module calls xAI's Grok to choose persistence actions: startup entries, scheduled tasks, Defender exclusions
  • Priced at $200 base, $150 for the DDoS add-on, $950 for the full package
  • Defense is provider-side: hard per-key budget caps, one key per service, daily spend alerts, and no production keys on laptops

Do you know how many live AI API keys your business has right now? We build AI systems with per-key budget caps, server-side secret handling, and spend alerting wired in from day one — so a stolen key costs you a rotation, not a quarter. See how we build it, or have us audit what you already run.

Sources: Qrator Research Labs, SecurityWeek, Infosecurity Magazine.

  • #api-keys
  • #denial-of-wallet
  • #botnet
  • #security
  • #ai-costs
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.