Infosecurity Magazine iconInfosecurity MagazineSep 23, 2026 ~4 min source read

New x47.c Windows Botnet Advertises AI API Draining and 18 Attack Modes

Qrator Research Labs analyzed seller materials for a previously undocumented Windows botnet called x47.c that offers an AI API drain command plus credential theft, SOCKS5 proxying, DDoS methods and an AI-assisted persistence module.

Share this story

Send the public story page.

Useful takeaways from this story.

x47.c includes an "AI API drain" command that sends repeated billable requests to AI providers using a valid API key, creating a denial-of-wallet attack without taking the victim application offline.

The botnet bundles 18 attack methods: credential theft, SOCKS5 proxying, multiple DDoS techniques, and an AI-based "stealth" module that aims to maintain persistence and disable protections.

The stealer targets browser passwords, cookies and Discord tokens, and documentation lists AI-site tokens as targets but does not show them converted into API keys for the drain command.

# What x47.c is and why it matters Qrator Research Labs published an analysis of seller materials for a Windows botnet called x47.c. The package advertises 18 attack methods and an "AI API drain" feature that uses valid API keys to generate billable requests against AI providers such as OpenAI and xAI. Because the drain requests are sent directly to the provider, an application can remain online while the AI feature's credit balance is exhausted.

# How the AI API drain works The advertised AI API drain takes a valid API key and issues repeated, billable calls to a chat or compatible API. This technique is a form of denial of wallet: it consumes paid credits tied to a key rather than aiming to take services offline. The seller pitched the method against chatbots, AI-connected content management systems, trading bots and automated scanners, and suggested using automatic top-ups to keep charges accumulating after a balance is exhausted.

# Other capabilities in the x47.c offering The x47.c package lists a mix of data-theft, proxying and denial-of-service techniques:

  • Credential and token theft: the stealer targets saved browser passwords, cookies and Discord tokens.
  • SOCKS5 proxy module: infected machines can be turned into outbound relays to route attacker traffic through victims' networks.
  • DDoS suite: HTTP floods, slow HTTP connection attacks, TCP and UDP floods, TLS connection stress, and reflection/amplification methods are in the advertised toolkit.
  • Fast-flux and C2 resiliency: seller materials include domain rotation options that give bots alternative domains and IPs (some domains can still point to the same server).

# AI-assisted persistence and concealment

# What Qrator found and did not find Qrator's conclusions are based on the advertisement, technical documentation, panel screenshots and follow-up messages supplied by the seller. The research notes the stealer lists AI-site tokens among targets but the documentation does not show those tokens being converted into API keys for the drain command. Qrator also found no test results supporting the seller's claims that protection-bypass or other advertised defensive-evasion modes were validated.

# Pricing and distribution

# Practical defensive steps Qrator recommended immediate containment steps for organizations that suspect exposure to this threat or similar attacks:

  • Revoke any exposed AI API keys and rotate credentials.
  • Review billing closely for anomalous AI usage and set spending limits and controls on automatic top-ups.
  • Clean endpoints of infection indicators and review persistence mechanisms, including Defender exclusion lists.
  • Deploy DDoS protection at both the application and network layers to limit the impact of volumetric and connection-based attacks.

# Bottom line x47.c packages multiple commercially familiar malware features with a specialized AI billing-abuse capability. The risk vector is straightforward when an attacker has a valid API key: repeated provider calls can deplete paid credits while leaving applications operational. Addressing exposed keys, enforcing billing controls and hardening endpoints and DDoS defenses reduce the immediate risk.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app