Skip to content
New x47.c Botnet Targets AI Services with API Draining Attacks

New x47.c Botnet Targets AI Services with API Draining Attacks

First seen 24 Sep 2026, 14:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 14:28 UTC
  • •x47.c botnet offers 18 attack methods, including AI credit draining.
  • •Attackers can exploit valid API keys to execute denial-of-wallet attacks.
  • •Qrator Labs recommends revoking exposed keys and monitoring billing.

A new Windows botnet, x47.c, has been discovered offering 18 attack methods, including a feature to drain AI credits from victims' accounts. This botnet, sold by a seller known as WraithTools, allows attackers to exploit valid API keys for services like OpenAI and xAI, executing a denial-of-wallet (DoW) attack. The botnet's capabilities include credential theft, SOCKS5 proxying, and various DDoS techniques. The AI API drain method sends repeated billable requests directly to the provider, bypassing the victim's application and keeping their website operational while exhausting AI credits. The total cost incurred by victims depends on their initial balance and any automatic top-up settings. Qrator Research Labs advises affected users to revoke exposed API keys, monitor their billing, and implement spending limits. The botnet is currently active and poses a significant threat to organizations using AI services.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-23
x47.c botnet discovered
Qrator Research Labs published findings on the x47.c botnet, detailing its capabilities and attack methods.
Infosecurity-Magazine
2026-09-24
Cybernews reports on x47.c
Cybernews highlighted the botnet's AI API drain feature and its implications for businesses using AI services.
Cybernews
2026-09-24
Scworld provides brief on x47.c
Scworld published a brief summarizing the attack methods offered by the x47.c botnet and its potential impact.
Scworld

More articles in this cluster (4)

Following this threat?

Track SystemBC and Qrator Research Labs in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed