Threats · 2h ago

WraithTools Sells Botnet to Drain AI Credits

Qrator said on September 23 that the WraithTools seller is advertising x47.c, a Windows botnet with 18 attack methods and a dedicated "AI API drain" feature for OpenAI, xAI and compatible chat APIs. The same package also includes credential theft, SOCKS5 proxying, persistence and DDoS options.

The drain command takes a valid API key and sends repeated billable requests straight to the provider, so the victim’s website can stay up while the AI bill climbs. Because the requests bypass the app, web filtering does not stop the spending; Qrator also noted the seller’s pitch includes automatic top-ups to keep charges going after a balance runs out.

For teams that ship chatbots or other AI features behind paid keys, the exposure sits at the provider and the billing account, not just the web app. If an attacker gets a usable key, the service can be monetized against its owner without ever breaking the application itself.

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-26

Editions

Related stories