x47.c Botnet Targets Discord Tokens and Exploits AI APIs of OpenAI and Grok
What happened
A previously undocumented Windows botnet, x47.c, has been discovered offering 18 attack methods, including one designed to drain victims' paid AI credits. The botnet targets include credential theft and SOCKS5 proxying. The group utilizes an 'AI API drain' command that sends repeated billable requests to providers like OpenAI and xAI, which is seen as a form of denial of wallet (DoW) by security researchers.
Why it matters
The attack methods are pitched against various targets, including chatbots, AI-connected content management systems, and trading bots. Because the requests bypass the victim's application, the services can continue to operate while their paid AI balances are depleted. Anyone holding a valid API key could script the same attack.
Who's involved
Keep exploring
The entities involved
-
Discord
instant messaging and VoIP software
-
Grok
website
-
OpenAI
American artificial intelligence research organization
- Leaders call for international cooperation on AI risks, tech leaders call for oversight, and the CMA proposes stricter search engine choice requirements.
- Experts, including Dario Amodei at Cornell University, warned about the power and limits of AI, specifically citing risks of AI taking control of the internet.