New Windows Botnet 'x47.c' Can Drain Company AI Credits and Steal Passwords
Security researchers at Qrator Research Labs have documented a previously unknown Windows botnet called x47.c, being sold by a seller known as WraithTools. Alongside 18 attack methods such as HTTP floods, TCP/UDP floods and TLS stress attacks, the malware offers credential theft, SOCKS5 proxying, and a standout feature: an 'AI API drain' function that exploits stolen or valid API keys for services like OpenAI or xAI.
This drain attack works by sending repeated billable requests directly to the AI provider using a valid API key, a technique known as denial of wallet. Because these requests bypass the victim's own website or application entirely, the site can remain online while the AI-powered features behind it exhaust their credit balance. Filtering website traffic will not stop this type of attack, and the seller has even suggested using automatic top-up settings to keep charges accumulating.
The malware also includes a stealer component targeting browser passwords, cookies and Discord tokens, plus an 'AI Stealth' module that uses AI to help the malware persist and evade detection on infected machines, including disabling Windows Defender protections. Qrator noted it found no evidence supporting some of the seller's advertised protection-bypass claims.