A sophisticated Windows botnet, dubbed x47.c, has been discovered on the market, leveraging AI to maintain persistence on infected hosts and drain victims’ paid AI credits. The botnet, advertised by a threat actor named WraithTools, offers a range of malicious capabilities, including DDoS attacks, credential theft, and SOCKS5 proxies.
The x47.c botnet’s command-and-control (C&C) panel provides access to a plethora of features, including bot management, fast-flux configuration options, information stealer logs, proxies, concealment capabilities, and DDoS attack options. The panel’s DDoS tab boasts 18 different attack methods, including HTTP floods, AI API draining, slow HTTP, TCP and UDP floods, TLS stresser, and various reflection and amplification techniques.
The most striking aspect of x47.c is its ability to drain victims’ paid AI credits through an “AI drain mode.” This feature exploits the victim’s existing relationship with AI service providers such as OpenAI or xAI, where a threat actor supplies a model name and API key for the targeted account. As a result, requests are made directly to the provider, bypassing the victim’s application and depleting their AI credits without their knowledge.
The botnet also features an “AI stealth” module that utilizes xAI Grok to maintain persistence on infected systems. This module allows the operator to select from a list of predefined actions, including startup entries and scheduled tasks, with optional process hollowing and privilege escalation capabilities available.
The impact of this botnet is significant, as it not only provides DDoS capabilities but also enables operators to collect credentials from infected machines or relay traffic through them. The x47.c botnet can harvest passwords, cookies, Discord tokens, wallet data, and AI-site tokens, making it a formidable tool for cybercriminals.
The fact that this botnet is being sold on the market raises concerns about the ease with which threat actors can acquire sophisticated tools to carry out attacks. It also highlights the growing trend of using AI-powered malware to evade detection and stay one step ahead of security measures.
For users, this news serves as a stark reminder to be vigilant about their online activities and to take steps to protect themselves from these types of threats. It is essential to ensure that AI services are used responsibly and that users are aware of the potential risks associated with them. By staying informed and taking proactive measures, individuals can reduce their exposure to these types of attacks.
In light of this discovery, it’s crucial for organizations and individuals alike to review their security posture and take necessary precautions to protect against x47.c-style botnets. This includes implementing robust cybersecurity measures, such as using reputable AI services, monitoring account activity, and staying up-to-date with the latest threat intelligence. By doing so, we can mitigate the impact of these types of attacks and ensure a safer online environment for everyone.
Source: SecurityWeek — 2026-09-26