How fake signups drive AI fraud
A thriving gray market has emerged offering discounted access to AI models through fraudulent account registrations that exploit free trials and startup credits. Services like Poison Claude and Ecomagent offer 70-90% discounts by creating fake accounts on platforms such as AWS Bedrock and Google Cloud, then reselling access through custom API endpoints. The demand is driven by cost considerations, access restrictions in regions like China, and desire for anonymity. Fraudulent registration campaigns targeting AI video services show over 105,000 brute-force signup attempts using bots, VPNs, and disposable email domains. The operations leverage residential proxies to evade detection and accept cryptocurrency payments. These services operate through sophisticated AI gateways and are advertised on underground forums and messaging platforms, particularly in Chinese-language markets, representing a significant platform abuse challenge for AI service providers.
AI Analysis
Technical Summary
This campaign involves fraudulent registrations to exploit free trials and startup credits on AI service platforms, enabling discounted reselling of AI model access. Operators use automated bots, VPNs, disposable email domains, and residential proxies to create fake accounts on cloud platforms such as AWS Bedrock and Google Cloud. These accounts are then monetized by reselling access through custom API gateways, with discounts ranging from 70-90%. The campaign targets AI video services with over 105,000 brute-force signup attempts documented. Payment is accepted in cryptocurrency, and the services are promoted on underground forums and messaging platforms, particularly in Chinese-language markets. This activity constitutes a form of platform abuse rather than a software vulnerability and poses operational and financial risks to AI service providers.
Potential Impact
The fraudulent account creation and resale of AI service access lead to significant platform abuse, financial losses due to misuse of free trials and startup credits, and potential degradation of service quality for legitimate users. The use of bots and proxies complicates detection and mitigation efforts. The campaign also undermines trust in AI service platforms and may affect regional access policies due to abuse originating from specific countries.
Mitigation Recommendations
No official patch or fix applies as this is a platform abuse campaign rather than a software vulnerability. AI service providers should enhance fraud detection mechanisms, including monitoring for high volumes of signup attempts, use of disposable email domains, VPNs, and residential proxies. Implementing stricter identity verification and limiting the abuse of free trials and startup credits can reduce impact. Providers should also monitor underground forums and threat intelligence sources for emerging tactics and indicators such as the identified domains. Collaboration with payment processors to detect suspicious cryptocurrency transactions may help disrupt these operations.
Affected Countries
British Indian Ocean Territory, China, India, Indonesia, Lebanon, Thailand
Indicators of Compromise
- domain: poison-claude.bitsender.top
- domain: api.claudeopus.shop
- domain: ratixq.com
- domain: claudeopus.shop
How fake signups drive AI fraud
Description
A thriving gray market has emerged offering discounted access to AI models through fraudulent account registrations that exploit free trials and startup credits. Services like Poison Claude and Ecomagent offer 70-90% discounts by creating fake accounts on platforms such as AWS Bedrock and Google Cloud, then reselling access through custom API endpoints. The demand is driven by cost considerations, access restrictions in regions like China, and desire for anonymity. Fraudulent registration campaigns targeting AI video services show over 105,000 brute-force signup attempts using bots, VPNs, and disposable email domains. The operations leverage residential proxies to evade detection and accept cryptocurrency payments. These services operate through sophisticated AI gateways and are advertised on underground forums and messaging platforms, particularly in Chinese-language markets, representing a significant platform abuse challenge for AI service providers.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves fraudulent registrations to exploit free trials and startup credits on AI service platforms, enabling discounted reselling of AI model access. Operators use automated bots, VPNs, disposable email domains, and residential proxies to create fake accounts on cloud platforms such as AWS Bedrock and Google Cloud. These accounts are then monetized by reselling access through custom API gateways, with discounts ranging from 70-90%. The campaign targets AI video services with over 105,000 brute-force signup attempts documented. Payment is accepted in cryptocurrency, and the services are promoted on underground forums and messaging platforms, particularly in Chinese-language markets. This activity constitutes a form of platform abuse rather than a software vulnerability and poses operational and financial risks to AI service providers.
Potential Impact
The fraudulent account creation and resale of AI service access lead to significant platform abuse, financial losses due to misuse of free trials and startup credits, and potential degradation of service quality for legitimate users. The use of bots and proxies complicates detection and mitigation efforts. The campaign also undermines trust in AI service platforms and may affect regional access policies due to abuse originating from specific countries.
Defensive Guidance
No official patch or fix applies as this is a platform abuse campaign rather than a software vulnerability. AI service providers should enhance fraud detection mechanisms, including monitoring for high volumes of signup attempts, use of disposable email domains, VPNs, and residential proxies. Implementing stricter identity verification and limiting the abuse of free trials and startup credits can reduce impact. Providers should also monitor underground forums and threat intelligence sources for emerging tactics and indicators such as the identified domains. Collaboration with payment processors to detect suspicious cryptocurrency transactions may help disrupt these operations.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.okta.com/blog/threat-intelligence/free_tokens_for_sale"]
- Adversary
- null
- Pulse Id
- 6a7386e5ce9f6bd78c7da52b
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainpoison-claude.bitsender.top | — | |
domainapi.claudeopus.shop | — | |
domainratixq.com | — | |
domainclaudeopus.shop | — |
Threat ID: 6a744c2ebf8831d539758e96
Added to database: 08/06/2026, 08:56:14 UTC
Last enriched: 08/06/2026, 11:32:55 UTC
Last updated: 08/07/2026, 00:23:03 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.