Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Botnet x47.c Leverages AI for Advanced Cyber Attacks

New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Posted on September 26, 2026 By CWS

A newly developed Windows botnet, known as x47.c, is being marketed by a cybercriminal entity called WraithTools. This botnet is notable for employing artificial intelligence to maintain its hold on compromised systems, according to a recent report by Qrator.

Key Features and Pricing

The x47.c botnet is being sold with a base package price of $200, with an additional charge of $150 for DDoS capabilities. To access the full suite of features, buyers need to pay $950. This comprehensive package includes options for distributed denial-of-service attacks, credential theft, and SOCKS5 proxy usage, along with an AI-driven API drain technique.

A command-and-control (C&C) panel is provided to users, enabling them to manage bots, configure fast-flux DNS, access logs from information stealers, and initiate DDoS attacks. The panel offers 18 different attack methods, such as HTTP floods, AI API draining, and more. These methods are designed to deplete system resources and bandwidth or to consume the victim’s AI service credits.

Advanced Attack Techniques

In its AI API drain mode, the botnet targets accounts on platforms like OpenAI and xAI by utilizing a valid API key and model name. This method allows the botnet to drain AI credits directly, bypassing the victim’s application, ensuring continuous website availability while AI credits are exhausted.

The fast flux configuration aids in the botnet’s persistence, utilizing multiple domains and IP addresses to manage infected systems. Additionally, the botnet includes an “AI stealth” module that leverages xAI Grok for automated actions, such as setting startup entries and scheduling tasks, with optional process hollowing and privilege escalation.

Control and Persistence Capabilities

Operators of the x47.c botnet can execute various actions on infected hosts, including selecting DDoS targets and managing software installations. The botnet also features a rootkit module designed to eliminate competing malware from compromised systems.

Through a SOCKS5 proxy module, operators can relay traffic, monitor proxy connections, and evaluate their performance. The botnet’s credential harvesting capabilities include collecting browser-stored passwords, Discord tokens, wallet data, and AI-site tokens.

The x47.c botnet represents a significant advancement in cybercrime tactics, harnessing AI for both attack and persistence. Its sophisticated design poses a substantial threat, emphasizing the need for robust cybersecurity measures.

Security Week News Tags:AI, AI API drain, Botnet, credential theft, Cybersecurity, DDoS, fast flux, SOCKS5 proxies, WraithTools, x47.c

Post navigation

Previous Post: SharePoint and MikroTik Vulnerabilities Exploited
Next Post: Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat

Related Posts

Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments Security Week News
Landfall Android Spyware Targeted Samsung Phones via Zero-Day Landfall Android Spyware Targeted Samsung Phones via Zero-Day Security Week News
Mastodon Faces Major DDoS Attack Following Bluesky Incident Mastodon Faces Major DDoS Attack Following Bluesky Incident Security Week News
OT Network Segmentation Lacks Full Isolation: Study OT Network Segmentation Lacks Full Isolation: Study Security Week News
Pierce County Library Data Breach Impacts 340,000 Pierce County Library Data Breach Impacts 340,000 Security Week News
In Other News: Nvidia Says No to Backdoors, Satellite Hacking, Energy Sector Assessment In Other News: Nvidia Says No to Backdoors, Satellite Hacking, Energy Sector Assessment Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks
  • SharePoint and MikroTik Vulnerabilities Exploited
  • Teen Researcher Uncovers Major Microsoft Data Vulnerability
  • OpenAI AI Models Interact with US Government Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks
  • SharePoint and MikroTik Vulnerabilities Exploited
  • Teen Researcher Uncovers Major Microsoft Data Vulnerability
  • OpenAI AI Models Interact with US Government Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark