Skip to main content
Emerging ThreatsMalware & Ransomware

Windows Botnet x47.c Exploits AI Credits with 18 Attack Methods

Rows of servers and networking equipment in a data center with a laptop in the foreground.

“The 'AI API drain' command takes a valid API key for OpenAI, xAI or a compatible chat API and sends repeated billable requests straight to the provider.” That single line, lifted from Qrator Research Labs’ September 23 report, describes a capability baked into a newly observed Windows botnet called x47.c that directly targets paid AI service accounts.

x47.c and the WraithTools marketplace offering

Qrator Research Labs analyzed seller materials — an advertisement, technical documentation, panel screenshots and follow-up messages — and concluded the botnet is being sold by a vendor calling itself WraithTools. An August 3 advertisement listed packages priced from $200 to $950; the top package, according to Qrator, added credential theft, proxying and AI-assisted persistence. The analysis is drawn entirely from the seller-provided material Qrator reviewed.

AI API drain: denial of wallet against OpenAI, xAI and compatible APIs

The botnet includes an "AI API drain" command that accepts a valid API key for OpenAI, xAI or a compatible chat API and automates repeated, billable calls directly to the AI provider. Qrator notes that because those calls do not pass through the victim’s application, a target website can remain reachable while its paid AI features run out of credit. The technique maps to what OWASP calls "denial of wallet" (DoW). The seller explicitly pitched the method against chatbots, AI-linked content management systems, trading bots and scanners, and even as a service to use against competitors. The seller also highlighted automatic top-ups as a mechanism to let charges continue accruing once a balance is exhausted.

Eighteen attack methods: DDoS, proxies and credential theft

Beyond the AI-drain capability, x47.c advertises 18 attack methods. Those include HTTP floods, slow HTTP connections, TCP and UDP floods, TLS connection stress, and reflection and amplification techniques. The malware's stealer module targets browser passwords, cookies and Discord tokens, and a SOCKS5 component can turn infected machines into relays for outbound traffic. What the seller calls "fast flux" gives bots alternative domains and IP addresses, though Qrator noted several of those domains can still point to a single server. Qrator also reported it found no published test results supporting the seller’s claimed protection-bypass modes.

AI Stealth module: Grok-assisted persistence and concealment

Seller documentation describes an "AI Stealth" module that uses xAI’s Grok model to assess the infected host and select from predefined persistence and concealment actions. Qrator captured seller-provided status messages that describe persistence repair and the creation of Windows Defender exclusions; the materials also describe local fallback behavior if model calls fail. While the stealer lists "AI-site tokens" among its targets, Qrator said the documentation does not demonstrate converting those tokens into API keys for use with the drain command.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: Qrator’s findings point to immediate technical actions — revoke exposed AI keys, check billing against legitimate usage, and set spending limits and controls on automatic top-ups. The lab also recommends endpoint cleanup to remove stealer and persistence artifacts and layered DDoS protection at both the application and network layers.
  • Affected enterprises and procurement leaders: The seller’s pitch that the drain can be used against competitors and that automatic top-ups can sustain charges suggests procurement and risk teams should review vendor API key practices, subscriptions with auto-refill features, and the exposure risk of site-connected AI credentials.
  • End users and administrators: Because the drain traffic can bypass the victim application, visible site functionality may not reveal billing abuse. Administrators should monitor account billing closely for anomalous billable AI calls and treat browser-stored credentials and Discord tokens as potential vectors for credential theft.

The x47.c offering packages a broad toolkit — DDoS methods, credential theft, proxying and an AI-assisted persistence feature — and adds a distinct commercial angle by advertising an AI-targeting "denial of wallet" capability. Qrator’s straightforward mitigation recommendations — revoke keys, audit billing, limit automatic top-ups, clean endpoints and deploy DDoS protections at multiple layers — are practical steps that map directly to the seller’s advertised features. Whether providers, customers and defenders act on those steps will determine how quickly this particular capability moves from seller marketing into widespread abuse.

Original reporting: https://www.infosecurity-magazine.com/news/x47c-botnet-ai-api-draining-18/