x47.c Windows Botnet Exploits xAI Grok AI API for Cybersecurity Threat
A cybercriminal group is offering access to a newly discovered Windows-based botnet that employs artificial intelligence to ensure long-term control over compromised systems, according to Qrator’s findings.
Pricing and Features
In early August, the threat actor listed the base package for $200 and a DDoS enhancement for $150, with the full suite of features available for $950. Subscribers gain access to a command-and-control (C&C) dashboard that enables management of botnet operations, configuration of fast-flux networking, monitoring of data exfiltration logs, proxy deployment, and execution of DDoS campaigns.
AI-Driven API Consumption
The platform includes 18 attack vectors, such as HTTP floods, AI API credit depletion, slow HTTP attacks, TCP and UDP floods, TLS stresser techniques, and reflection/amplification methods. While traditional methods target resource exhaustion, the AI API drain feature specifically exploits paid AI service credits by leveraging valid API keys from platforms like OpenAI and xAI.
Fast-Flux and Persistence
The botnet utilizes a fast-flux configuration to maintain control over infected devices, with six domain names and eight IP addresses listed in the management interface. This setup facilitates dynamic IP address rotation to evade detection. Additionally, x47.c incorporates an “AI stealth” module designed to establish persistence on compromised systems. This component leverages xAI Grok to execute predefined actions, including modifying startup entries and scheduling tasks.
Optional Features and Evasion
Optional features include process hollowing and privilege escalation, which are activated when an xAI API key is integrated into the botnet’s code. The system generates status updates detailing changes to system configurations, persistence mechanisms, and Windows Defender exclusions. It also includes fallback procedures to sustain operations if AI model interactions fail, ensuring uninterrupted control over infected hosts.
Credential Extraction and Traffic Routing
Operators can deploy the botnet for credential extraction from compromised machines or to route traffic through infected systems. The malware is capable of stealing browser-stored passwords, cookies, Discord authentication tokens, cryptocurrency wallet data, and AI platform credentials. Traffic is routed via a SOCKS5 proxy module, allowing administrators to monitor multiple proxy connections, assess their stability, and track timeout intervals.
Security Implications
The botnet’s architecture highlights the growing integration of AI technologies into malicious frameworks, with threat actors exploiting AI capabilities to enhance both attack efficiency and evasion tactics. Security researchers emphasize the need for robust monitoring of AI service usage and stricter API key management to mitigate risks associated with such threats.
“According to Qrator’s findings, the botnet, designated as x47.c, is marketed by the threat actor WraithTools and is claimed to offer distributed denial-of-service (DDoS) attacks, credential harvesting, SOCKS5 proxy services, and an AI-driven API consumption mechanism.”
