x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining

 

A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks, SOCKS5 proxy access and a method designed to drain paid AI credits. According to Qrator, the malware also uses artificial intelligence to help maintain persistence on infected systems. 
The botnet is advertised by a threat actor known as WraithTools. In early August, the operator offered the base x47.c package for $200, with a DDoS add-on priced at $150. The complete package, including its full range of capabilities, was offered for $950.

Customers receive access to a command-and-control panel that allows them to manage infected machines and access features including fast-flux configuration, information-stealing logs, proxies, concealment capabilities and DDoS operations. 
The DDoS section provides 18 attack methods, including HTTP floods, slow HTTP attacks, TCP and UDP floods, TLS stresser activity, and reflection and amplification techniques.

One feature specifically targets paid artificial intelligence services. The AI drain mode is designed to consume a victim’s AI credits by sending requests directly to an AI provider. The operator supplies a model name and a valid API key for accounts using OpenAI, xAI and compatible chat APIs. Because the requests are sent directly to the provider, the targeted website can remain accessible while the account’s available AI credits are depleted.

x47.c also incorporates an “AI stealth” module designed to maintain persistence on compromised Windows systems. 
The feature is advertised as using xAI Grok to select actions from a predefined list, including startup entries and scheduled tasks. Optional process hollowing and privilege escalation capabilities are also available.

According to Qrator, the operator activates the AI functionality by including an xAI key in the botnet build. Status messages can indicate startup changes, persistence repairs and Windows Defender exclusions. The malware also has local fallback actions that allow maintenance operations to continue when an AI model call fails. 
The botnet provides operators with additional control over infected systems. They can select DDoS targets and download, update or remove software from compromised hosts. A rootkit module is also promoted for removing artifacts associated with rival malware.

Beyond DDoS activity, x47.c can harvest passwords and cookies from browsers, along with Discord tokens, cryptocurrency wallet data and AI-service tokens. 
Its SOCKS5 module allows compromised systems to relay traffic, while operators can monitor proxy connections and review their health status and timeouts.

The combination of AI-assisted persistence, credential theft, proxy capabilities, DDoS functions and AI credit draining makes x47.c a broad Windows botnet offering multiple ways to abuse compromised systems and online services.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: