A threat actor known as WraithTools is selling access to x47.c, a Windows botnet that uses AI-driven features for persistence, credential theft, DDoS attacks, and proxying. Qrator reports that the botnet also includes AI API draining against OpenAI, xAI, and compatible chat services, along with modules for fast-flux control, stealth, and rootkit-based cleanup of rival artifacts. #x47.c #WraithTools #Qrator #OpenAI #xAI #Grok
Keypoints
- x47.c is a new Windows botnet sold by the threat actor WraithTools.
- The botnet offers DDoS, credential theft, SOCKS5 proxying, and AI API drain capabilities.
- Its panel includes bot management, fast-flux settings, stealer logs, and attack options.
- An AI stealth module uses xAI Grok to help maintain persistence on infected hosts.
- x47.c can steal passwords, cookies, Discord tokens, wallet data, and AI-site tokens.
Read More: https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/