Brind.

x47.c Botnet Targets Discord Tokens and Exploits AI APIs of OpenAI and Grok

1 report, 1 independent Updated Sep 23
AI-generated briefing. Brind wrote this from the reports listed below. It can be wrong. Each section says how much you can rely on it, and the sources are linked so you can check.

What happened

Some supportReported by 1 outlet

A previously undocumented Windows botnet, x47.c, has been discovered offering 18 attack methods, including one designed to drain victims' paid AI credits. The botnet targets include credential theft and SOCKS5 proxying. The group utilizes an 'AI API drain' command that sends repeated billable requests to providers like OpenAI and xAI, which is seen as a form of denial of wallet (DoW) by security researchers.

From infosecurity-magazine.com

Why it matters

Some supportBrind's analysis of the reports

The attack methods are pitched against various targets, including chatbots, AI-connected content management systems, and trading bots. Because the requests bypass the victim's application, the services can continue to operate while their paid AI balances are depleted. Anyone holding a valid API key could script the same attack.

From infosecurity-magazine.com

Who's involved

  • DiscordInstant messaging and VoIP software targeted by the botnet.
  • OpenAIAmerican artificial intelligence research organization targeted for financial drain.
  • GrokWebsite whose AI services are targeted by the botnet.

Keep exploring

The entities involved

Coverage

Newest first; wire copies grouped