Skip to content
Security & Trust

x47.c botnet, advertised at $950, includes a mode that drains AI credits

Qrator describes a Windows botnet with an AI-account drain and a Grok-driven persistence module

K
Kannan SP
· 3 min read
Share on X LinkedIn
x47.c botnet, advertised at $950, includes a mode that drains AI credits
Key finding

Attack methods in the x47.c panel's DDoS tab: 18 (Source: Qrator, reported by SecurityWeek)

Qrator reports that a threat actor named WraithTools is selling access to x47.c, a Windows botnet. The seller advertises DDoS and credential theft, SOCKS5 proxies and an "AI API drain" method, as SecurityWeek reported. For organisations that pay for AI services, the drain mode is the notable part. It targets the AI account, not the website.

The drain mode targets the AI bill, not the web server

The botnet's control panel has a DDoS tab with 18 attack methods. HTTP, TCP and UDP floods are meant to exhaust resources and bandwidth. The AI drain mode is meant to consume a victim's paid AI credits. The operator supplies a model name and a valid API key for the targeted account on OpenAI, xAI or compatible chat APIs, and the requests consume credits or incur charges.

Qrator explains why this matters for monitoring: "Because those requests go straight to the provider, they do not need to pass through the victim's application. The website can remain reachable while the account behind its AI features runs out of credits." Website uptime checks would therefore not necessarily reflect this activity. Provider billing and usage records are where credit consumption would be visible.

18
Attack methods in the x47.c panel's DDoS tab
Source: Qrator, reported by SecurityWeek

AI also runs inside the botnet

x47.c includes an "AI stealth" module for persistence on infected hosts. It is advertised as using xAI Grok to choose from a predefined list of actions, including startup entries and scheduled tasks. Optional process hollowing and privilege escalation are also offered. The operator enables the calls by including an xAI key in the build.

Qrator says the status messages report startup changes, persistence repair and Windows Defender exclusions. They also show local fallback actions when a model call fails, so host maintenance can continue without a successful AI response. The model chooses from a predefined list, and maintenance continues when a model call fails.

Credential collection is part of the package

According to the report, x47.c can harvest passwords and cookies from browsers. It can also collect Discord tokens, wallet data and AI-site tokens. Traffic can be relayed through infected machines by a SOCKS5 module. The source does not say how operators obtain the API keys used in drain mode. It also does not cite victim counts. The findings describe what the seller advertises and what the panel shows.

$950
Advertised price of the full x47.c package, early August
Source: Qrator, reported by SecurityWeek
$200
Advertised price of the base package, early August
Source: Qrator, reported by SecurityWeek

What to ask your team

First, ask for an inventory of every AI provider account the organisation pays for, including accounts opened by individual teams, and who holds each API key. Second, ask whether spend caps and usage alerts are set on each account, and whether anyone reviews provider billing on a schedule separate from website uptime monitoring. Third, ask how quickly a key can be revoked and replaced, and whether that has been tested. Fourth, ask whether endpoint tooling would flag new startup entries, scheduled tasks and Windows Defender exclusions, which are the changes Qrator says the persistence module reports. Fifth, ask whether browser-stored passwords, cookies and AI-site tokens on employee machines are covered by the credential-theft response plan.

Share this insight