Hackers Allegedly Selling Stolen VirusTotal API Keys on Dark Web
A dark web seller is reportedly offering a VirusTotal Enterprise API key for $350, sparking concerns about potential misuse of threat intelligence data.
A seller on the dark web has allegedly advertised a VirusTotal Enterprise API key for sale at $350, according to a post on Dark Web Informer dated October 7. The claim, however, remains unverified, with no concrete evidence presented to confirm the authenticity, legitimacy, or current operational status of the advertised key. The seller purportedly claims extremely high request limits, including 5,000 requests per day, 300,000 per hour, and one billion per month, though these figures are part of the advertisement and not confirmed capabilities.
These advertised limits warrant scrutiny, as a daily allowance of 5,000 requests could conflict with an hourly limit of 300,000 if both were intended to apply to the same usage. The advertisement does not clarify if these numbers refer to different services, separate quotas, or are simply inflated claims. VirusTotal's official documentation outlines API limits on a per-minute, daily, and monthly basis, and users can monitor their own allowances and consumption through their account's API key management page, underscoring the importance of account-level verification.
Furthermore, the platform distinguishes between public API access and its paid enterprise features. The public API has a significantly lower limit of 500 requests per day and four requests per minute. Premium allowances are tiered based on the licensed service level. Therefore, the mere inclusion of the term "Enterprise" in a sales post does not guarantee that the buyer would receive access to all, or even any, of the premium features.
An API key enables software to interact with VirusTotal programmatically, automating tasks that would otherwise require manual submission of files or queries through the website. Security teams commonly use this access to retrieve detailed file reports, investigate suspicious domains, and integrate threat intelligence into their automated security workflows. The ability to query VirusTotal at scale is a critical component of modern threat hunting and incident response.
Technically, VirusTotal API requests are authenticated using the x-apikey HTTP header. The platform explicitly warns users that their personal API key carries their account's privileges and must never be shared. If an unauthorized party gains possession of such a key, they could potentially make requests under the affected account, operating within its granted permissions and quota limits.
This situation represents a form of credential misuse rather than a direct breach of VirusTotal's systems. However, depending on the subscription level associated with the compromised key, such misuse could lead to the exposure of valuable licensed research capabilities or the depletion of request allowances needed by legitimate security analysts. The actual impact would depend on the specific access rights tied to the key and the endpoints targeted by the attacker.
Crucially, the current report does not identify the owner of the alleged compromised key, nor does it provide any details on how the seller might have obtained it, or offer evidence of a broader compromise affecting multiple users. Claims made in social media discussions about potential sources of the leak should be treated with extreme caution and not as established facts. A live demonstration of the key's functionality would prove current access but not necessarily lawful ownership or sustained availability.
Organizations that are concerned about the potential exposure of their API keys are advised to review their API usage logs for any unexplained or anomalous requests. Investigating such activity and promptly revoking any suspected compromised credentials are essential steps in mitigating the risks associated with stolen API keys. For now, this dark web listing remains an unverified allegation, not definitive proof of a confirmed VirusTotal breach or validated enterprise access.