New Windows Botnet Drains AI Credits While Stealing Data

Researchers have uncovered a Windows-based botnet dubbed x47.c that goes beyond data theft: it mines paid AI credits, hijacks browser data, and launches service-disrupting attacks. While its full reach and impact remain unclear—no confirmed infectee list or exact losses have been published—the botnet is already being advertised as a versatile toolkit for cybercrime.

What x47.c Can Do

The malware offers operators control over compromised Windows machines, giving access to browser passwords, cookies, and Discord session tokens. It also includes an attack mode designed to spend victims’ paid AI credits by misusing valid API keys tied to those accounts. Although it supports OpenAI, xAI and other chat API-compatible services, the drain feature requires a legitimate user’s API key to function.

Beyond the AI-credit drain, the botnet equips attackers to flood sites using HTTP, TCP, UDP, TLS-based attacks, slow connection stress, and reflection tactics. It can also run SOCKS5 proxies through infected devices, collect sensitive data, and deploy persistent stealth modules that leverage an AI-assisted model to assess and maintain control even when certain defenses are in place.

Advertisement, Pricing & Risk

The threat was first flagged by threat hunters at Qrator Labs, who noticed an ad from a seller known as WraithTools. The seller listed three tiers: a base package for $200, a DDoS add-on at $150, and a comprehensive “full” package priced at $950. These packages reportedly unlock features like AI credit-draining and web service disruption. Despite these claims, there are no verified statistics on how many machines have been compromised, how much damage has been done, or how extensively the tools are being used in the wild.

Experts warn that even without visible outages or performance hits to websites, financial damage can still pile up stealthily—through unauthorized usage of AI services, automatic top-ups, or inflated API requests. Among several concerns is what’s meant by a “denial of wallet” scenario, in which a service may remain operational while its AI tools are shut down once a billing threshold is reached.

Defense & Indicators

Key signs of infection include software payloads named “x47_bot.exe” or “x47_bot.dll”, a control panel directory listed as “x47.c_FF_v4.1”, and seller names like “WraithTools”. The tool also uses a server script called “server_master.js” and a reverse-proxy handshake label “REVERSE_PROXY|”. The backend infrastructure follows a fast-flux style of rotating domains and IPs, making it harder to block permanently.

To mitigate threats, defenders are urged to isolate infected hosts, strip out persistence mechanisms like scheduled tasks and startup entries, and revoke compromised credentials immediately. Keeping API usage strictly monitored, disabling auto-renewals or top-ups, and rotating keys can reduce risk. For organizations running public-facing services, preparing for floods—both at network and application layers—is essential.

This botnet does not yet appear to have been confirmed in widespread deployment. The advertised capabilities could represent potential, not proven, attack scale. That said, it highlights a growing threat: attackers aren’t just going for data any more—they’re siphoning off billing power and AI resources too.

What this means: x47.c marks a troubling evolution in cybercrime. Attackers are increasingly targeting cloud- and AI-based economic models, turning legitimate API keys into financial liabilities for users and service providers alike. The real danger is less about system crashes, and more about invisible bleeding of budget and trust. Organizations should closely audit API key use, enforce strict credential hygiene, and adapt defenses to this new threat vector if they hope to stay ahead.