News Room
16
Share
Unit 42 Alerts on 'Wallet-Drainer' AI Attacks: Critical RAG Poisoning Exploits Found in Financial Sector
criticalAI Cyber Attacks

Unit 42 Alerts on 'Wallet-Drainer' AI Attacks: Critical RAG Poisoning Exploits Found in Financial Sector

Security researchers have detected a new wave of 'Denial-of-Wallet' (DoW) attacks leveraging Retrieval-Augmented Inference Cost Attacks (RA-ICA) and deepfake injection to deplete corporate API credits and bypass identity controls.

11 July 2026Last updated 20 August 20264 min readUnit 42
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
High Confidence
Source:
Unit 42
Read Time:
4 min

Executive Summary

On July 10, 2026, Unit 42 released a critical threat advisory regarding a sophisticated campaign targeting global financial institutions. The campaign involves the use of Retrieval-Augmented Inference Cost Attacks (RA-ICA), a novel method designed to cause financial exhaustion by forcing enterprise Large Language Models (LLMs) into infinite or hyper-redundant processing loops. Concurrently, the actors are utilizing high-fidelity deepfake video injection during mandatory verification calls to authorize high-value transactions. This dual-threat approach combines technical infrastructure sabotage with advanced social engineering, marking a significant escalation in AI-orchestrated cyber warfare.

Threat Analysis

The primary objective of this campaign, dubbed 'Project Chimera' by analysts, appears to be economic disruption and unauthorized capital extraction. Unlike traditional data exfiltration, the actors are exploiting the underlying architecture of Retrieval-Augmented Generation (RAG) systems. By poisoning public-facing document repositories with adversarial metadata—invisible to humans but prioritized by AI scrapers—attackers trigger 'Denial-of-Wallet' scenarios. In these cases, corporate AI instances consume their entire quarterly API token budget within hours, effectively shutting down automated customer service and risk assessment tools. Simultaneously, the group leverages these outages to force manual overrides, where they deploy real-time deepfake overlays to impersonate senior executives.

Technical Details

Technical analysis of the RA-ICA payload reveals a highly optimized set of 'token-sink' prompts embedded in PDF and XLSX metadata. These prompts utilize recursive logic gates that force the RAG system to retrieve and process the same data clusters repeatedly, increasing token consumption by up to 1,300% per query. For the social engineering component, the actors utilize a modified version of the 'BlackMamba' polymorphic loader to deliver a real-time deepfake injection tool. This tool hijacks virtual camera drivers (such as OBS Virtual Camera) to stream low-latency, AI-generated likenesses during Zoom and Microsoft Teams sessions. The deepfake models are trained on publicly available executive interviews, achieving a 98% similarity score and bypassing traditional liveness detection tests that rely on micro-expression analysis.

Attribution Assessment

Unit 42 attributes this activity with moderate confidence to a splinter cell of the 'Scattered Spider' syndicate, potentially operating in collaboration with a state-sponsored actor specializing in disruptive operations. The sophisticated nature of the RA-ICA prompts suggests a high degree of familiarity with enterprise AI middleware. Furthermore, the command-and-control (C2) infrastructure mirrors previous campaigns associated with Storm-0978, particularly the use of residential proxies to mask the origin of the adversarial RAG queries.

Implications

The emergence of RA-ICA represents a shift from data-focused attacks to infrastructure-cost attacks. For organizations heavily reliant on generative AI, the risk is no longer just a leak but total operational paralysis due to cost-induced service suspension. Moreover, the success of real-time deepfake injection indicates that current multi-factor authentication (MFA) and biometric standards are insufficient against machine-speed social engineering.

Recommendations

Encrygma recommends that organizations immediately implement 'Token Quotas' and hard caps on individual RAG queries. Development teams should integrate sanitization layers that strip metadata from all documents before they are ingested into vector databases. For executive communications, we advise implementing 'out-of-band' verification protocols, such as physical hardware tokens or secondary confirmation through encrypted mobile messaging, to mitigate the risk of deepfake impersonation during video conferences.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo