New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits
Qrator uncovered the x47.c Windows botnet, sold by WraithTools, combining DDoS, credential theft, SOCKS5 proxying, and AI API credit-draining attacks.
Qrator Research Labs identified the previously undocumented Windows botnet x47.c, sold by an operator using the name WraithTools at $200 base, $150 for a DDoS add-on, and $950 for a full package. The botnet combines 18 DDoS methods, credential theft, SOCKS5 proxying, and fast-flux C2 with an 'AI API drain' that exhausts victims' paid AI credits, a Denial of Wallet attack requiring a valid API key for services like OpenAI or xAI. Its 'AI Stealth' module reportedly uses an embedded xAI Grok API key to select persistence actions, including Windows Defender exclusions, scheduled tasks, process hollowing, and privilege escalation. Qrator found no evidence the malware automatically converts stolen browser tokens into API keys.
- AI API drain exhausts victims' paid AI credits using valid API keys, a Denial of Wallet attack.
- Packages priced $200 base, $150 DDoS add-on, $950 full with credential theft and SOCKS5.
- Botnet offers 18 DDoS methods plus fast-flux C2 designed to resist takedowns.
- AI Stealth module uses embedded Grok API key for persistence, Defender exclusions, and process hollowing.
Full article777 words · extracted from gbhackers.com · click to collapse
A newly identified Windows botnet dubbed x47.c is marketing a blend of conventional DDoS tooling, credential theft, SOCKS5 proxying, fast-flux command-and-control infrastructure, and an “AI API drain” capability designed to exhaust victims’ paid artificial-intelligence service credits.
Qrator Research Labs identified the previously undocumented malware platform during threat hunting. They traced its sale to an operator using the name WraithTools.
The offering is notable not because automated API abuse is new, but because the seller has packaged AI-credit exhaustion as a dedicated botnet attack method alongside network- and application-layer flooding features.
WraithTools advertised a $200 base package, a $150 DDoS add-on, and a $950 full package incorporating credential theft, SOCKS5 proxy functions, and AI-assisted persistence.
The botnet’s “AI API drain” function requires an attacker to possess a valid API key tied to the targeted account.
Operators provide the credential and a model name for services such as OpenAI, xAI, or compatible chat-completion platforms.
x47.c then repeatedly sends billable requests directly to the AI provider, consuming prepaid balances or creating usage-based charges.
This is a form of Denial of Wallet (DoW), a risk OWASP categorizes under unbounded consumption.
Rather than immediately knocking a public-facing service offline, the attack targets the financial and quota layer behind an AI-enabled application.
The web application may remain available while its AI chatbot, content-processing workflow, scanner, or trading feature becomes unavailable once spending limits or account balances are exhausted.
The direct-to-provider design also limits the usefulness of traditional web filtering. Requests do not need to traverse the victim’s website or application infrastructure, meaning a web application firewall may not observe the malicious traffic.
WraithTools allegedly promoted the capability against AI-enabled chatbots, content management systems, scanners, and trading bots, including as a means of disrupting competitors.
The campaign still depends on key compromise. Qrator’s analysis found no indication that x47.c automatically converts stolen browser tokens into provider API keys; the AI-drain command requires the operator to supply a valid credential.
However, the platform’s credential-stealing component creates an obvious opportunity to harvest sensitive session data, browser passwords, cookies, Discord tokens, wallets, and potentially AI-related access material from compromised hosts.
AI-Powered Botnet x47.c
x47.c advertises 18 attack methods, including HTTP floods, slow HTTP attacks, TCP and UDP flooding, TLS connection stress, and reflection or amplification techniques.
Qrator Research Labs identified, x47.c operator panel, branded “x47 Fast Flux C2GUI v4.1,” reportedly provides dedicated sections for bot administration, stealth operations, credential-stealer logs, proxy management, DDoS campaigns.
The malware documentation claims each bot can execute one method at a time, with raw-socket SYN capability falling back to TCP connection attempts where privileges or platform support are insufficient.
The botnet also uses a fast-flux-style C2 design intended to preserve operator access. Infected systems retain the last working destination and attempt alternate domains or IP addresses after connection failures.
This can complicate takedowns and blocking efforts, although multiple listed domains may still resolve to the same underlying virtual private server.
For persistence, x47.c’s “AI Stealth” module reportedly uses an xAI Grok API key embedded during bot creation to assess host conditions and select predefined maintenance actions.
Advertised functions include startup persistence, scheduled tasks, persistence repair, Windows Defender exclusions, optional process hollowing, and privilege-elevation attempts.
Local fallback behavior reportedly enables the malware to continue host-maintenance activity even when its AI call fails.
Its SOCKS5 module further monetizes compromised endpoints by establishing reverse proxy connections through C2 infrastructure, allowing traffic to exit through a victim’s network even when the device sits behind NAT.
Organizations using paid AI APIs should treat key exposure as both a data-security and financial-risk event.
Immediate defensive actions include revoking exposed keys, disabling or tightly governing automatic top-ups, applying strict per-key spending ceilings, and monitoring billing telemetry for abrupt request or token-consumption spikes.
OWASP recommends enforcing resource limits because uncontrolled inference can result in service degradation, financial loss, and denial of service.
Security teams should also isolate AI credentials from browser-accessible environments, use separate keys per workload, limit permissions and model access, enforce rate and token limits, and configure automated circuit breakers that stop anomalous consumption before it becomes an invoice.
Endpoint remediation, credential resets, and layered DDoS protections remain essential where x47.c infection is suspected.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.