New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits
Qrator uncovered the x47.c Windows botnet, sold by WraithTools, combining DDoS, credential theft, SOCKS5 proxying, and AI API credit-draining attacks.
Qrator Research Labs identified the previously undocumented Windows botnet x47.c, sold by an operator using the name WraithTools at $200 base, $150 for a DDoS add-on, and $950 for a full package. The botnet combines 18 DDoS methods, credential theft, SOCKS5 proxying, and fast-flux C2 with an 'AI API drain' that exhausts victims' paid AI credits, a Denial of Wallet attack requiring a valid API key for services like OpenAI or xAI. Its 'AI Stealth' module reportedly uses an embedded xAI Grok API key to select persistence actions, including Windows Defender exclusions, scheduled tasks, process hollowing, and privilege escalation. Qrator found no evidence the malware automatically converts stolen browser tokens into API keys.