x47.c Windows botnet (Qrator / WraithTools): AI API drain + Grok-driven “AI Stealth” persistence
Qrator Research Labs (23 September 2026; SecurityWeek amplify 26 Sep; Infosecurity Magazine 23 Sep) documents a previously unreported Windows botnet sold by WraithTools as x47.c. Seller ads (early August package ~$200 base / $150 DDoS add-on / ~$950 full) and panel screenshots advertise DDoS, credential theft, SOCKS5 proxies, fast-flux style C2 domain/IP pools, and an “AI API drain” mode: operator supplies a model name plus a valid OpenAI, xAI, or compatible chat API key so bots send billable requests straight to the provider (OWASP denial-of-wallet) — victim web apps can stay up while AI credits/auto-top-ups are exhausted. DDoS tab claims 18 methods (HTTP/slow-HTTP, TCP/UDP floods, TLS stresser, reflection/amplification; Qrator found no evidence for advertised protection-bypass modes). “AI Stealth” persistence module is advertised as using xAI Grok (operator-supplied xAI key in the build) to choose predefined actions (startup entries, scheduled tasks, Defender exclusions, optional process hollowing / privilege escalation) with local fallbacks when model calls fail. Stealer targets browser passwords/cookies, Discord tokens, wallet data, and AI-site tokens. Qrator’s analysis is from seller materials rather than confirmed in-the-wild campaigns. Advice: revoke exposed AI API keys, billing anomaly checks, spending limits / disable auto top-ups, endpoint cleanup, app+network DDoS controls. Primary wire: SecurityWeek / Infosecurity citing Qrator (qrator.net blog returned 401 to desk fetch).
- Product
- Windows endpoints (x47.c botnet / WraithTools malware panel)
- Versions
- n/a (crimeware for sale; not a product CVE)
- Exploited in Australia?
- unknown
- Patch to
- Revoke and rotate exposed OpenAI/xAI/compatible API keys; set hard spending caps and disable auto top-ups; hunt unexpected AI billing; EDR cleanup of x47.c-class bots; SOCKS5/fast-flux C2 monitoring; DDoS protections at app and network layers
Primary: SecurityWeek — x47.c Windows botnet weaponizes xAI Grok / AI API draining (26 Sep 2026) · Vendor: Qrator Research Labs — x47.c botnet (23 Sep 2026; primary research; fetch may require browser) · Infosecurity Magazine — x47.c AI API draining / 18 attack methods (23 Sep 2026)
