www.securityweek.com 26 Sept 2026, 12:00 UTC

New x47.c Windows Botnet Drains AI Credits and Steals Credentials

New x47.c Windows Botnet Drains AI Credits and Steals Credentials
CyberSIXT Evidence Panel
Threat Actor

A threat actor is selling access to a new Windows botnet called x47.c, according to research from Qrator. The malware is advertised under the name WraithTools with distributed denial-of-service (DDoS), credential theft and SOCKS5 proxy capabilities, as well as a feature designed to drain victims’ paid artificial intelligence credits. In early August, the base package was offered for $200, the DDoS add-on for $150 and the complete package for $950.

The botnet’s command-and-control panel supports 18 attack methods, including HTTP, TCP and UDP floods, TLS stress attacks, reflection and amplification techniques, and AI API draining. For the latter, an operator supplies a model name and valid API key for OpenAI, xAI or compatible services, sending requests directly to the provider to consume credits or generate charges while the victim’s application may remain accessible. Qrator says x47.c also uses fast-flux configurations to maintain control, with six domains and eight IP addresses listed in one management panel.

An “AI stealth” module is advertised as using xAI’s Grok to select persistence actions such as startup entries and scheduled tasks. Optional process hollowing and privilege escalation are also available. Qrator reports that status messages indicate persistence repairs and Windows Defender exclusions, with local fallback actions if an AI call fails.

Operators can additionally download or remove software, collect browser passwords and cookies, Discord tokens, wallet data and AI-service tokens, relay traffic through SOCKS5 proxies, and use a rootkit module to remove rival malware.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline