Back Infosecurity-Magazine Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
A previously undocumented Windows botnet dubbed x47.c has been found offering 18 attack methods, including one designed to drain victims' paid AI credits.
According to research published by Qrator Research Labs on September 23, the seller, WraithTools, also offers credential theft, SOCKS5 proxying and an AI module meant to keep the malware on infected machines.
Draining AI Accounts at the Provider
The "AI API drain" command takes a valid API key for OpenAI, xAI or a compatible chat API and sends repeated billable requests straight to the provider. OWASP calls this type of attack denial of wallet (DoW).
Because the requests never pass through the victim's application, its website can stay up while the AI features behind it run out of credit. Filtering traffic at the website will not stop them, Qrator said.
The seller pitched the method against chatbots, AI-connected content management systems, trading bots and scanners, including as a service to use against competitors. He also pointed to automatic top-ups as a way to keep charges accruing once a balance runs out.
The resulting cost depends on how much extra spending the account allows, Qrator said.
Anyone holding a valid key could script the same attack, Qrator noted. The botnet's stealer lists AI-site tokens among its targets, but the documentation does not show them being turned into API keys for the drain command.
DDoS, Proxies and AI-Assisted Persistence
The remaining methods include HTTP floods, slow HTTP connections, TCP and UDP floods, TLS connection stress and reflection and amplification techniques. Qrator found no test results supporting the advertised protection-bypass modes.
An "AI Stealth" module uses xAI's Grok to assess the infected host and choose from predefined persistence and concealment actions. Seller-provided status messages describe persistence repair and Windows Defender exclusions, with local fallbacks when model calls fail.
The stealer targets browser passwords, cookies and Discord tokens, and a SOCKS5 module turns infected machines into relays for traffic leaving through the victim's network. What the seller calls fast flux gives bots alternative domains and IP addresses, though several of those domains can point to a single server.
Qrator advised revoking exposed AI keys, checking billing against legitimate usage and setting spending limits and controls on automatic top-ups. It also recommended endpoint cleanup and DDoS protection at both the application and network layers.
Global SystemBC Botnet Found Active Across 10,000 Infected Systems News 4 February 2026
Global SystemBC Botnet Found Active Across 10,000 Infected Systems
Curl Releases Fixes For High-Severity Vulnerability News 11 October 2023
Curl Releases Fixes For High-Severity Vulnerability
UK Government Cybersecurity Advisory Board Applications Now Open News 25 May 2022
UK Government Cybersecurity Advisory Board Applications Now Open
Indirect Prompt Injection in Web Content Targets AI Agents News 6 July 2026
Indirect Prompt Injection in Web Content Targets AI Agents
Ransomware Groups Fragment Amid Rising Cybercrime Threats News 22 July 2024
Ransomware Groups Fragment Amid Rising Cybercrime Threats
What’s Hot on Infosecurity Magazine?
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Revolut Customers Targeted with New Wave of Phishing Attacks
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
AI Agent Carries Out Multi-Stage Data Theft Attack
Most Firms Unable to Recover Quickly from Ransomware
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
AI-Driven Cloud Threats and Defenses: Securing AI-Powered Environments
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
From APIs to Agents: How to Secure AI at Enterprise Scale
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
