The previously undocumented x47.c Windows botnet is being marketed by WraithTools with 18 attack capabilities, including credential theft, SOCKS5 proxying, fast-flux infrastructure, DDoS attacks, and AI-assisted persistence and host concealment. Its persistence module reportedly uses xAI's Grok to select from predefined persistence and evasion actions on compromised hosts.
x47.c's "AI API drain" capability uses valid stolen or exposed API keys to send repeated billable requests directly to OpenAI, xAI, and compatible AI providers, exhausting a victim's credits while potentially leaving the victim-facing application functional. The activity represents a denial-of-wallet attack; organizations should revoke exposed AI keys, investigate anomalous usage and billing, enforce spending caps and limits on automatic top-ups, remediate infected endpoints, and maintain layered application- and network-level DDoS protections.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
WraithTools marketed the previously undocumented Windows botnet x47.c as providing 18 attack methods, including an AI API-drain feature that uses valid API keys to make billable requests to OpenAI, xAI, or compatible providers and exhaust victims' credits. The botnet was also advertised with DDoS, credential-stealing, SOCKS5 relay, fast-flux, and AI-assisted persistence and concealment functions.
An August 3 advertisement offered x47.c packages priced from $200 to $950. The highest-priced package included credential theft, SOCKS5 proxying, and AI-assisted persistence capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.