I don't think it likely hidden from you, more likely you didn't put the effort in, that's what the pattern looks like to outsiders reading your accounting of what happened here
we'd need to know more details to evaluate your botnet claims
we'd need to know more details to evaluate your botnet claims
what we would like to see is your settings and configuration, maybe the task(s) you gave them and any code/scripts around them, where did they run from (your laptop vs cloud vm)
why did they even have credentialed access to change credit cards? Sounds like you didn't do the basics for isolation
the agents go on side quests, all the time... super frustrating, but I suspect between that tendency and asking about a UI (image), you racked up a bill with legitimate requests
There is a reason some of us preach "stay in the loop" and I hope you now understand why we do