Hackers Built a Botnet That Doesn’t Just Steal Data, It Burns AI Credits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A Windows botnet called x47.c can spend victims’ paid AI credits, steal data, and flood websites. Its operator markets it as an attack toolkit for remote use, but the evidence describes advertised capabilities, not confirmed widespread infections or documented victims.

The botnet gives operators control of infected Windows machines and can collect browser passwords, cookies, and Discord tokens. Researchers have not established how it first infects those machines.

Its advertised attacks threaten online services and paid AI accounts. Analysts at Qrator Labs identified the offering during routine threat hunting.

Qrator Labs said in a report shared with Cyber Security News (CSN) that seller WraithTools advertised 18 attack methods, including one meant to consume paid AI credits.

An August 3, 2026 advertisement lists a $200 base package, a $150 DDoS add-on, and a $950 full package. Researchers reported no infection count, measured attack capacity, or verified losses. The risk is the combination of theft, service disruption, and billing abuse.

Hackers Built a Botnet

The AI drain feature requires a valid API key for the account being charged. This key lets software request services without a person signing in. The operator provides a model name, then bots send requests directly to an AI provider.

The documented mode supports OpenAI, xAI, and compatible chat APIs, but it cannot bill an account without a valid key belonging to that account.

x47.c platform overview and included components (Source - Qrator Labs)
x47.c platform overview and included components (Source – Qrator Labs)

Accepted requests consume credits or generate charges. Researchers call this a denial of wallet risk: the website may stay online while its AI features fail if the provider stops requests at a balance or spending limit.

Possible targets include chatbots, content management systems, trading bots, and scanners. Automatic top-ups could extend charges beyond a prepaid balance. Unlike website floods, these requests bypass the target website, so filtering its traffic cannot stop them.

Although the seller advertises theft of wallets and AI-site tokens, the drain command still requires an operator-supplied account key.

The report does not show the bot automatically converting stolen AI-site tokens into usable provider keys for this attack mode. That distinction matters: AI token jacking cases illustrate the danger of exposed keys, but do not establish how this botnet gets them.

The wider financial risk is real. In a stolen Gemini API key case, unauthorized use generated more than $82,000 in two days. That separate incident does not establish losses from x47.c.

Control, theft and defenses

The panel also offers HTTP floods, slow connections, TCP and UDP floods, and other service disruption methods. The documented methods include TLS connection stress and reflection attacks that aim to overload network services.

Each bot reportedly runs one attack at a time. Researchers found no tests supporting advertised protection bypasses. Bots remember a working command server and try alternatives if it fails.

The panel shows six domains and eight IP addresses without publishing their values. This resembles fast flux infrastructure used to sustain malicious connections, although several names may point to one server.

Attack methods (Source - Qrator Labs)
Attack methods (Source – Qrator Labs)

An AI-assisted stealth module reportedly uses xAI Grok to assess a host and select preset maintenance actions. Startup entries and scheduled tasks support persistence; fallback actions work if the model call fails.

AI does not choose attack targets; the operator remains responsible for selecting them. Other modules collect browser data and turn infected machines into SOCKS5 traffic relays.

Operators can review stolen material, manage proxies, and update software on a compromised host. The relay sends traffic out through the victim’s network, potentially hiding where the operator actually sits. One infection therefore threatens both accounts and networks.

Defenders should isolate infected systems, remove persistence, and investigate stolen passwords, cookies, and tokens. Revoke exposed credentials because cleanup cannot undo theft. Compare AI usage against bills, rotate compromised keys, and limit spending and automatic top-ups.

Finally, prepare for application and network floods. The report documents attack options, not successful campaigns or proven performance. Its warning is that access to a paid AI account can become another resource attackers exhaust, even when a website remains available.

Indicators of compromise (IoCs):-

Type Indicator Description
Seller username WraithTools Name used to advertise the botnet.
Advertised product x47.c, Fast Flux Edition v4.1 Product identifier in the source material.
Panel title x47 Fast Flux C2GUI v4.1 Title shown on the operator panel.
Package directory x47.c_FF_v4.1 Documented package directory.
Executable filename x47_bot.exe Documented EXE output.
DLL filename x47_bot.dll Documented DLL output.
Server script filename server_master.js Documented command-server script.
Relay handshake prefix REVERSE_PROXY| Documented reverse-proxy handshake prefix.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Built a Botnet That Doesn’t Just Steal Data, It Burns AI Credits appeared first on Cyber Security News.