A sophisticated Windows botnet has emerged on the dark web, offering a range of malicious services to threat actors. Dubbed x47.c, this botnet utilizes artificial intelligence (AI) to maintain persistence on infected hosts and provides its operators with a suite of tools for distributed denial-of-service (DDoS) attacks, credential theft, and other nefarious activities.
According to Qrator, the company that discovered the botnet, x47.c is being sold by a threat actor known as WraithTools. For a mere $200, users can gain access to the botnet’s base package, which includes tools for managing infected machines, configuring fast-flux networks, and collecting information from victims’ browsers. The DDoS add-on costs an additional $150, while the full x47.c package, complete with all capabilities, is available for a whopping $950.
One of the most concerning aspects of x47.c is its use of AI to drain victim accounts on platforms like OpenAI and xAI. By providing operators with model names and valid API keys, the botnet can consume victims’ paid credits or incur charges without ever passing through the victim’s application. This means that even if a website remains reachable, the underlying account behind its AI features can still be drained of funds.
The botnet’s administrator has implemented various measures to maintain control over infected machines, including fast-flux configurations with six domains and eight IP addresses. The x47.c also boasts an “AI stealth” module, which uses xAI Grok to choose from a predefined list of actions for maintaining persistence on infected systems. This can include modifying startup entries and scheduled tasks, as well as applying privilege escalation techniques.
In addition to its AI-powered features, the botnet offers operators a range of tools for collecting credentials, relaying traffic, and even removing rival artifacts from infected systems. The x47.c also includes a rootkit module for evading detection by anti-virus software and other security measures.
The emergence of x47.c highlights the growing trend of AI-powered threats in the cybersecurity landscape. As more organizations adopt AI technologies, they are inadvertently creating new attack surfaces that can be exploited by malicious actors. It’s essential for users to remain vigilant and take proactive steps to protect themselves against such threats.
To stay safe, we recommend that Windows users exercise caution when interacting with online services that utilize AI. Always verify the authenticity of any API keys or model names provided by a service, and be wary of unusual activity on your account or system. Additionally, ensure that you have robust security measures in place to detect and respond to potential threats. By staying informed and taking proactive steps, we can all do our part in mitigating the impact of AI-powered threats like x47.c.
Source: SecurityWeek — 2026-09-26