A recently discovered Windows botnet, known as x47.c, poses significant cybersecurity threats by targeting victims’ paid AI credits, stealing sensitive data, and launching website disruptions. Marketed as an attack toolkit for remote use, its capabilities are advertised rather than confirmed through widespread infection or documented cases.
Botnet Capabilities and Threats
The x47.c botnet enables operators to take over infected Windows systems, accessing browser passwords, cookies, and Discord tokens. Despite its advertised capabilities, researchers have yet to determine how these machines initially become infected.
The botnet’s potential attacks on online services and paid AI accounts were identified by analysts at Qrator Labs during routine security evaluations. Their findings reveal the botnet’s capacity to consume AI credits, among other threats.
Financial and Operational Risks
According to a report by Qrator Labs shared with Cyber Security News, the botnet’s seller, WraithTools, offers packages starting at $200, with a DDoS add-on for $150 and a full package for $950. Although the extent of infections and financial losses remains unverified, the combination of data theft, service interruptions, and unauthorized billing poses a significant risk.
To exploit AI credits, the botnet requires a valid API key, enabling unauthorized requests to AI providers. This capability is compatible with OpenAI, xAI, and other chat APIs, but cannot proceed without the necessary account key.
Mitigation and Defensive Measures
The botnet’s attack methods include HTTP floods, slow connections, and various network stress techniques. However, researchers have found no evidence supporting the advertised effectiveness of these methods in bypassing defenses.
Defensive strategies should focus on isolating infected systems, removing persistent threats, and revoking compromised credentials. Comparing AI usage against billing records and rotating keys can help mitigate unauthorized charges. Additionally, preparations should be made against potential application and network flooding.
Although the botnet poses a real threat, no successful campaigns or proven attack performances have been documented. Nevertheless, it serves as a reminder of the evolving risks associated with access to paid AI accounts and other online resources.
