Windows Botnet x47.c Exploits AI Credits, Steals Data, and Launches DDoS Attacks
Researchers at Qrator Labs have uncovered x47.c, a Windows-based botnet marketed as a remote attack toolkit with capabilities to drain paid AI credits, steal sensitive data, and disrupt online services. The botnet, advertised by a seller known as WraithTools, is offered in tiered packages ranging from a $200 base version to a $950 full package with an optional $150 DDoS add-on, as listed in an August 3, 2026 advertisement.
Capabilities and Threat Vectors
Once installed on a victim’s machine, x47.c provides operators with control over compromised systems, enabling:
- Data Theft: Harvests browser passwords, cookies, and Discord tokens.
- AI Credit Exploitation: Uses stolen or operator-supplied API keys to consume paid AI credits from providers like OpenAI and xAI, bypassing direct website traffic filters. This creates a "denial of wallet" risk, where AI services may fail due to exhausted balances or spending limits.
- DDoS Attacks: Includes HTTP floods, TCP/UDP floods, TLS stress tests, and reflection attacks, with each bot executing one attack at a time.
- Traffic Relaying: Converts infected machines into SOCKS5 proxies, obscuring the operator’s origin.
- Persistence Mechanisms: Uses startup entries, scheduled tasks, and an AI-assisted stealth module (leveraging xAI Grok) to evade detection.
Key Limitations and Unknowns
- No Confirmed Infections or Victims: Researchers have not documented widespread infections or verified financial losses tied to x47.c.
- API Key Dependency: The AI credit-draining feature requires a valid API key either stolen or provided by the operator limiting its effectiveness without prior credential compromise.
- Unproven Bypass Claims: Advertised protection bypasses lack supporting evidence.
- Fast Flux Infrastructure: The botnet uses six domains and eight IP addresses (not publicly disclosed) to sustain malicious connections, though some may resolve to the same server.
Defensive Considerations
While the report does not confirm active campaigns, it highlights risks to AI-powered services, trading bots, and content management systems, where unauthorized API usage could lead to significant financial losses. A separate incident involving a stolen Gemini API key resulted in $82,000 in charges over two days, underscoring the potential impact of such attacks.
Indicators of compromise (IoCs) include the WraithTools seller alias, the x47.c product name, and filenames like x47_bot.exe and server_master.js. Security teams are advised to monitor for these artifacts in controlled threat intelligence platforms.
Source: https://cybersecuritynews.com/hackers-built-a-botnet/
Gemini AI cybersecurity rating report: https://www.rankiteo.com/company/geminiai
OpenAI cybersecurity rating report: https://www.rankiteo.com/company/openai
"id": "GEMOPE1790699080",
"linkid": "geminiai, openai",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['Technology',
'Finance',
'Content Management'],
'type': ['AI Service Providers',
'Trading Bots',
'Content Management Systems']}],
'attack_vector': ['Malware Installation',
'Stolen API Keys',
'SOCKS5 Proxy',
'Persistence Mechanisms'],
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': ['High'],
'type_of_data_compromised': ['Browser passwords',
'Cookies',
'Discord tokens',
'API keys']},
'date_detected': '2026-08-03',
'date_publicly_disclosed': '2026-08-03',
'description': 'Researchers at Qrator Labs uncovered x47.c, a Windows-based '
'botnet marketed as a remote attack toolkit with capabilities '
'to drain paid AI credits, steal sensitive data, and disrupt '
'online services. The botnet is advertised by a seller known '
'as WraithTools and is offered in tiered packages. Once '
'installed, it enables data theft, AI credit exploitation, '
'DDoS attacks, traffic relaying, and persistence mechanisms to '
'evade detection.',
'impact': {'data_compromised': ['Browser passwords',
'Cookies',
'Discord tokens',
'API keys'],
'identity_theft_risk': ['Personally Identifiable Information '
'(PII)'],
'operational_impact': ['Unauthorized AI credit consumption',
'DDoS attacks on online services'],
'systems_affected': ['Windows machines']},
'investigation_status': 'Ongoing',
'lessons_learned': 'The incident highlights risks to AI-powered services, '
'trading bots, and content management systems where '
'unauthorized API usage could lead to significant '
'financial losses. Security teams should monitor for IoCs '
'and implement controls to prevent API key misuse.',
'motivation': ['Financial Gain',
'Disruption of Services',
'Data Exfiltration'],
'post_incident_analysis': {'corrective_actions': ['Monitor for IoCs',
'Implement API key usage '
'controls',
'Enhance detection for '
'persistence mechanisms'],
'root_causes': ['Malware installation on victim '
'machines',
'Stolen or operator-supplied API '
'keys']},
'recommendations': ['Monitor for IoCs (e.g., WraithTools, x47.c, x47_bot.exe, '
'server_master.js).',
'Implement controls to prevent unauthorized API key '
'usage.',
'Enhance detection mechanisms for persistence techniques '
'(e.g., startup entries, scheduled tasks).',
'Educate users on the risks of malware installation and '
'credential theft.'],
'references': [{'date_accessed': '2026-08-03', 'source': 'Qrator Labs'}],
'response': {'enhanced_monitoring': ['Monitoring for IoCs (e.g., WraithTools, '
'x47.c, x47_bot.exe, server_master.js)'],
'third_party_assistance': 'Qrator Labs'},
'threat_actor': 'WraithTools',
'title': 'Windows Botnet x47.c Exploits AI Credits, Steals Data, and Launches '
'DDoS Attacks',
'type': ['Botnet', 'Data Theft', 'DDoS', 'AI Credit Exploitation']}