x47.c Botnet Burns Victims’ AI Credits: Denial-of-Wallet Goes Commodity
A Windows botnet sold by an actor calling itself WraithTools has productised an attack the AI-security community has warned about for two years: denial-of-wallet against paid AI APIs. According to analysis by Qrator Research Labs (covered from 23 September 2026), the x47.c botnet ships an “AI API drain” mode that fires billable requests directly at OpenAI, xAI, and compatible chat APIs using the victim’s own key — so the website stays reachable while the account behind its AI features runs dry. Base package: $200. DDoS add-on: $150. The full kit: $950.
This matters beyond the usual botnet noise for two reasons. First, the drain bypasses the defences most teams actually bought: requests go straight to the provider, never traversing the victim’s app or WAF. Second, the same botnet uses a frontier model — xAI’s Grok — to maintain its own persistence, while bundling a stealer that harvests exactly the material (browser credentials, AI-site tokens) that feeds the drain. Offence and defence are now bidding on the same API credits.
How the AI drain works — and its hard requirement
The operator’s panel (branded “x47 Fast Flux C2GUI v4.1”) offers 18 attack methods: HTTP floods, slow HTTP, TCP and UDP floods, a TLS stresser, reflection/amplification techniques — and AI API draining. For the drain, the operator supplies a model name plus a valid API key for the targeted account; bots then hammer the provider directly, consuming prepaid balances or running up usage-based charges. Seller documentation reportedly markets it against AI chatbots, content-management systems, scanners, and trading bots — including as a way to disrupt competitors.
The crucial corrective, straight from Qrator’s analysis: there is no indication x47.c automatically converts stolen browser tokens into provider API keys. The drain only works with an operator-supplied credential. That bounds the hype — but it also names the defence precisely. The campaign still depends on key compromise, and the botnet’s stealer (passwords, cookies, Discord tokens, wallet data, AI-site tokens) exists to make that compromise happen. Every leaked key is now both a confidentiality incident and an open line of credit to whoever holds it. The same lesson runs through the MCP OAuth account-takeover class: AI credentials change hands silently, and the blast radius is measured in someone else’s spend.
Grok handles persistence; fast-flux handles survival
x47.c’s “AI Stealth” module reportedly embeds an xAI key at build time and asks Grok to choose from a predefined list of host-maintenance actions: startup entries, scheduled tasks, persistence repair, Windows Defender exclusions — with optional process hollowing and privilege escalation. Status messages report what changed, and local fallback actions keep maintenance going when the model call fails. Note the design discipline worth stealing: the AI proposes, the menu constrains, and failure degrades to a safe default. Most enterprise agent deployments would benefit from exactly that shape.
Command-and-control uses fast-flux (six domains and eight IPs in the management tab, per the seller), with bots retaining the last working destination and trying alternates after failures — which complicates takedowns even though multiple domains may resolve to one VPS. A rootkit module removes rival malware from infected hosts, and a SOCKS5 module monetises endpoints as reverse proxies that work from behind NAT, with health monitoring per connection.
What to do today
- Cap spend per key, and alert on velocity. Separate keys per workload, strict per-key spending ceilings, automatic top-ups disabled or tightly governed, and billing-telemetry alerts on abrupt request or token-consumption spikes. OWASP’s unbounded-consumption guidance exists for this exact invoice.
- Treat exposed AI keys as financial-breach events. Revoke, rotate, and review charges — not just the code that leaked them. Add circuit breakers that halt anomalous consumption before it becomes an invoice.
- Keep AI credentials out of browser-accessible environments. x47.c harvests exactly where developers paste keys. Scope keys to least privilege, restrict model access, and never let a frontend or shared workstation hold a key with top-up authority.
- Monitor the persistence primitives, not just the malware name. New startup entries, scheduled tasks, and Defender-exclusion changes are the observable half of “AI Stealth” — alert on them regardless of which family creates them.
- Assume competitor-grade targeting. The seller explicitly markets disruption of rivals’ AI features. If your product is an AI chatbot or agent, denial-of-wallet belongs in your threat model next to DDoS, with runbooks that cover a drained account, not just a downed server.
Sources:
- SecurityWeek — “New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining” (26 September 2026; Qrator findings, pricing, 18 methods, Grok persistence, fast-flux, stealer)
- GBHackers — “New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits” (29 September 2026; operator-supplied-key requirement, direct-to-provider design, defensive controls)
- Infosecurity Magazine — “Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods” (23 September 2026)
- Cybernews — “AI API drain botnet can run up huge bills for victims” (25 September 2026)
- Cybersecurity News — “Hackers Built a Botnet That Doesn’t Just Steal Data, It Burns AI Credits” (29 September 2026)