# Emerging x47.c Botnet Utilizes AI to Drain API Credits

*Published September 28, 2026*
*Source: [https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/](https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/emerging-x47-c-botnet-utilizes-ai-to-drain-api-credits) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A new Windows botnet known as x47.c is causing disruptions by leveraging artificial intelligence to maintain control over infected systems. The botnet, sold by a threat actor called WraithTools, offers a range of capabilities including distributed denial-of-service (DDoS) attacks and credential theft. Among its features, the botnet employs a unique AI API drain technique to deplete a victim's paid AI credits without necessarily affecting the target application's accessibility.

The x47.c botnet is marketed with a base package costing $200, with additional DDoS functionalities available for $150, while the complete package is priced at $950. Users of this botnet are provided with a command-and-control panel that facilitates various malicious activities. This includes managing the botnet, configuring fast-flux domains for persistence, and utilizing SOCKS5 proxies to relay traffic.

In its DDoS arsenal, x47.c boasts 18 different attack methods such as HTTP floods, slow HTTP, TCP and UDP floods, and AI API draining. The AI drain mode specifically targets the API credits of services like OpenAI and xAI by using legitimate API keys, potentially leading to financial losses for the victims.

A notable aspect of x47.c is its AI stealth module, which ensures persistence through methods like startup entries and scheduled tasks, while also offering optional process hollowing and privilege escalation. The botnet can collect sensitive data, including credentials, browser cookies, and tokens from platforms such as Discord and AI sites.

The threat actor behind x47.c also promotes a rootkit module designed to eliminate competing malware from infected machines. This botnet illustrates a worrying trend of cybercriminals harnessing AI to enhance the sophistication and impact of their attacks.
