x47.c botnet uses xAI Grok to drain AI service credits

The x47.c Windows botnet, sold by WraithTools, uses xAI Grok for persistence and an “AI drain” DDoS mode that consumes victims’ paid AI service credits.

A Windows botnet called x47.c is being offered for sale by an actor identifying as WraithTools. The package, first advertised in early August, includes a web-based command-and-control panel, credential theft, SOCKS5 proxy services and a DDoS toolkit with an “AI drain” mode that targets paid AI accounts.

The seller offered a base build for about $200, a DDoS add-on for roughly $150 and a full-featured package for about $950. Buyers receive a control panel that provides bot management, fast-flux configuration, information-stealer logs, proxy controls, concealment tools and multiple DDoS options.

The botnet’s AI drain mode lets an operator supply a model name and a valid API key for targeted accounts on providers such as OpenAI and xAI or any compatible chat API, then issue requests that consume credits or incur charges to the targeted account. Researchers noted: “Because those requests go straight to the provider, they do not need to pass through the victim’s application. The website can remain reachable while the account behind its AI features runs out of credits.”

The DDoS toolkit lists 18 attack methods, including HTTP floods, AI API draining, slow HTTP attacks, TCP and UDP floods, a TLS stresser and several reflection and amplification techniques. Traditional flood methods are aimed at exhausting bandwidth and server resources; the AI drain option is designed to deplete paid usage allowances tied to an organisation’s AI features.

For command resilience, the kit supports a fast-flux setup that rotates domains and IP addresses. The control panel exposes six domains and eight IP addresses in its management view and lets operators assign preferred hostnames and IPs for individual compromised machines. An “AI stealth” persistence module is advertised to use xAI Grok to select maintenance actions such as creating startup entries and scheduled tasks. Optional techniques in the build include process hollowing and privilege escalation to hide or elevate the malware’s presence.

The builder can be configured with an xAI key so the bot contacts the model for status updates and actions. Status messages include startup changes, persistence repairs and Windows Defender exclusions, and the code contains fallback local actions so maintenance continues if a model call fails.

Operators can select DDoS targets from the panel and remotely download, update or remove software on infected systems. Modules harvest credentials and tokens from browsers and apps, including passwords, cookies, Discord tokens, cryptocurrency wallet data and AI-site tokens. A SOCKS5 proxy component relays traffic through compromised hosts and the control panel reports proxy health and timeouts. The seller also offers an optional rootkit module intended to remove competing malware artifacts from infected machines.

The offering is sold as modular access-as-a-service, allowing buyers to select specific features and add-ons at the time of purchase.

Articles by this author