Hackers Built a Botnet That Doesn’t Just Steal Data, It Burns AI Credits
Qrator Labs uncovered x47.c, a Windows botnet sold by WraithTools that steals credentials, launches DDoS floods, and drains victims' paid AI API credits.
Qrator Labs found seller WraithTools advertising the x47.c botnet with 18 attack methods, priced at $200 base, $150 DDoS add-on, and $950 full package. The toolkit steals browser passwords, cookies, and Discord tokens, runs SOCKS5 relays through victims, and includes an AI-drain mode that spends OpenAI, xAI, and compatible chat API credits using valid keys. Persistence uses startup entries and scheduled tasks, and an AI-assisted stealth module uses xAI Grok for host assessment. Researchers documented no confirmed infections, attack capacity, or verified losses; a separate stolen Gemini API key case caused over $82,000 in charges in two days.