Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
New Windows botnet 'x47.c' offers 18 attacks, including a novel method to drain victims' paid AI API credits.
Qrator Research Labs has documented a new Windows botnet called x47.c, sold by threat actor WraithTools. The botnet's most notable feature is an 'AI API drain' command that can exhaust a victim's paid AI service credits (e.g., OpenAI, xAI) by sending repeated billable requests directly to the provider. The malware also offers DDoS, credential theft, SOCKS5 proxying, and an 'AI Stealth' module that uses the Grok model to automate persistence and evasion on infected hosts.
65