New Botnet Burns AI Credits, Steals Data
Key Takeaways The x47.c botnet, marketed by “WraithTools,” targets Windows systems. It offers 18 distinct attack methods, including data theft and denial-of-service capabilities. A novel...
Key Takeaways
- The x47.c botnet, marketed by “WraithTools,” targets Windows systems.
- It offers 18 distinct attack methods, including data theft and denial-of-service capabilities.
- A novel feature allows the botnet to exhaust victims’ paid AI service credits.
- Infection vectors for x47.c are currently unknown to researchers.
- The botnet can steal sensitive data like browser passwords, cookies, and Discord tokens.
Emergence of x47.c Botnet with AI Credit Depletion Capability
A new Windows-based botnet, dubbed x47.c, has been identified with a concerning array of functionalities, including the ability to exhaust a victim’s paid artificial intelligence (AI) service credits, steal sensitive data, and launch distributed denial-of-service (DDoS) attacks. This botnet is being actively marketed as a remote attack toolkit by its operator, known as “WraithTools.” While the advertised capabilities are extensive, security researchers emphasize that current observations are based on these advertised features rather than confirmed widespread infections or documented victim impact.
Table Of Content
The x47.c botnet grants its operators comprehensive control over compromised Windows machines. Its data exfiltration capabilities include harvesting browser passwords, cookies, and Discord tokens. The initial infection methods employed by x47.c to compromise these machines remain unconfirmed by researchers.
Qrator Labs analysts discovered this botnet during their routine threat intelligence activities. According to a Qrator Labs report, the seller “WraithTools” advertises a total of 18 attack vectors, notably featuring a method specifically designed to consume paid AI credits.
Botnet Pricing and Financial Risks
An advertisement dated August 3, 2026, outlines the pricing structure for the x47.c botnet, offering a base package for $200, a DDoS add-on for $150, and a comprehensive full package priced at $950. While researchers have not yet provided specific infection counts, measured attack capacity, or verified financial losses attributed to x47.c, the combination of data theft, service disruption, and the innovative billing abuse targeting AI accounts presents a significant and multi-faceted risk.
Advanced AI Credit Exhaustion Feature
The botnet’s distinctive AI credit draining functionality relies on a valid API key belonging to the target account. These API keys enable software to request services from AI providers without requiring direct user login. Once an operator supplies a model name, the compromised bots directly send requests to the AI provider, consuming the victim’s credits or generating charges. This documented mode supports OpenAI, xAI, and other compatible chat APIs. However, it cannot bill an account without the correct, operator-supplied API key associated with that account. Researchers refer to this as a “denial of wallet” risk: while the target website might remain operational, its AI-powered features could become unusable if the provider halts requests due to depleted balances or spending limits.
Potential targets for this type of attack include chatbots, content management systems, automated trading bots, and various scanning tools. Systems with automatic top-up features could see charges extend beyond their prepaid balances. Crucially, these AI credit depletion requests bypass the target website itself, meaning traditional traffic filtering on the website cannot mitigate this specific threat.
Although the botnet’s seller claims capabilities for stealing crypto wallets and AI-site tokens, the AI credit drain command still mandates an operator-provided account key. The current research does not demonstrate the bot’s automatic conversion of stolen AI-site tokens into functional provider keys for this attack mode. This distinction is vital; while incidents of AI token hijacking highlight the dangers of exposed keys, the mechanism by which x47.c acquires these keys for its AI credit draining feature is not yet fully understood.
The financial implications of compromised API keys are substantial. A separate incident involving a stolen Gemini API key resulted in over $82,000 in unauthorized transactions within just two days, underscoring the potential for significant financial damage, even if this specific case is not linked to x47.c.
Botnet Control, Data Theft, and Defensive Measures
Beyond AI credit depletion, the x47.c botnet’s command and control panel provides options for various denial-of-service attacks, including HTTP floods, slow connection attacks, TCP and UDP floods, TLS connection stress, and reflection attacks, all aimed at overwhelming network services. Each bot is designed to execute one attack at a time. Researchers have not found evidence or tests supporting the botnet’s advertised capabilities to bypass existing protection mechanisms.
The botnet’s infrastructure exhibits characteristics of fast flux, with bots remembering functional command servers and attempting alternatives if a connection fails. The control panel lists six domains and eight IP addresses, though their specific values were not disclosed in the report, suggesting a resilient command and control architecture.
An AI-powered stealth module within x47.c reportedly utilizes xAI Grok to analyze a compromised host and select predefined maintenance actions. Persistence is achieved through startup entries and scheduled tasks, with fallback mechanisms in place if the AI model call fails. It is important to note that the AI component assists in maintaining the botnet’s presence but does not select attack targets; this responsibility remains with the human operator. Additional modules facilitate the collection of browser data and transform infected machines into SOCKS5 traffic relays.
Operators can remotely review stolen data, manage proxy settings, and update the botnet software on compromised hosts. The SOCKS5 relay feature allows attackers to route their traffic through the victim’s network, effectively masking their true location. This means a single infection can pose a threat to both user accounts and network infrastructure.
What You Should Do
- Isolate Infected Systems: Immediately disconnect any compromised machines from your network to prevent further spread and data exfiltration.
- Remove Persistence Mechanisms: Identify and eliminate any startup entries, scheduled tasks, or other methods used by the botnet to maintain its presence on infected systems.
- Investigate Stolen Credentials: Conduct a thorough investigation into any stolen passwords, cookies, or tokens.
- Revoke Exposed Credentials: Promptly revoke all compromised credentials, including API keys, as theft cannot be undone by system cleanup.
- Monitor AI Usage and Bills: Regularly review AI service usage logs and compare them against billing statements for any anomalies.
- Rotate Compromised Keys: If AI API keys are suspected of compromise, rotate them immediately.
- Implement Spending Limits and Disable Auto Top-ups: Configure strict spending limits and disable automatic top-up features on AI accounts to mitigate potential financial abuse.
- Prepare for DDoS Attacks: Ensure your network and applications have robust DDoS protection measures in place to defend against potential floods.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.