A threat actor is selling access to a new Windows botnet that leans on an AI model to stay in place and to burn through victims’ paid AI budgets. Qrator Labs tracks the botnet as x47.c and attributes its sale to an operator going by WraithTools.
The package bundles distributed denial-of-service tools, credential theft, SOCKS5 proxies, and what the seller calls an AI API drain method. Early in August the base kit was priced at $200, with a DDoS add-on at $150 and the full set at $950. Buyers get a command-and-control panel covering bot management, fast-flux settings, stealer logs, and 18 attack modes.
Grok picks the script while the credits pay the bill
Among those modes is AI API draining, designed to consume a target’s prepaid model credits. The operator feeds the panel a model name and a valid key for an OpenAI, xAI, or compatible chat endpoint, then pushes requests straight to the provider. Because the traffic never touches the victim’s own infrastructure, ordinary network defenses have little to see.
x47.c also uses xAI’s Grok to choose between predefined actions, letting the malware vary its behaviour on an infected host without fresh instructions from the operator. For defenders the pattern matters more than the price list: AI spend is now an attack surface, and API keys deserve the same monitoring as any other credential.
