A newly developed Windows botnet, known as x47.c, is being marketed by a cybercriminal entity called WraithTools. This botnet is notable for employing artificial intelligence to maintain its hold on compromised systems, according to a recent report by Qrator.
Key Features and Pricing
The x47.c botnet is being sold with a base package price of $200, with an additional charge of $150 for DDoS capabilities. To access the full suite of features, buyers need to pay $950. This comprehensive package includes options for distributed denial-of-service attacks, credential theft, and SOCKS5 proxy usage, along with an AI-driven API drain technique.
A command-and-control (C&C) panel is provided to users, enabling them to manage bots, configure fast-flux DNS, access logs from information stealers, and initiate DDoS attacks. The panel offers 18 different attack methods, such as HTTP floods, AI API draining, and more. These methods are designed to deplete system resources and bandwidth or to consume the victim’s AI service credits.
Advanced Attack Techniques
In its AI API drain mode, the botnet targets accounts on platforms like OpenAI and xAI by utilizing a valid API key and model name. This method allows the botnet to drain AI credits directly, bypassing the victim’s application, ensuring continuous website availability while AI credits are exhausted.
The fast flux configuration aids in the botnet’s persistence, utilizing multiple domains and IP addresses to manage infected systems. Additionally, the botnet includes an “AI stealth” module that leverages xAI Grok for automated actions, such as setting startup entries and scheduling tasks, with optional process hollowing and privilege escalation.
Control and Persistence Capabilities
Operators of the x47.c botnet can execute various actions on infected hosts, including selecting DDoS targets and managing software installations. The botnet also features a rootkit module designed to eliminate competing malware from compromised systems.
Through a SOCKS5 proxy module, operators can relay traffic, monitor proxy connections, and evaluate their performance. The botnet’s credential harvesting capabilities include collecting browser-stored passwords, Discord tokens, wallet data, and AI-site tokens.
The x47.c botnet represents a significant advancement in cybercrime tactics, harnessing AI for both attack and persistence. Its sophisticated design poses a substantial threat, emphasizing the need for robust cybersecurity measures.
