Find notable cyber news and cases, enriched with sources, timelines, and signals.

X47.c Windows botnet offering AI API-draining and credential-theft tooling

Malware Activity
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

The previously undocumented x47.c Windows botnet now appears in a seller offering 18 attack methods, including an AI API drain command that can burn paid credits at providers such as OpenAI and xAI. The same package also includes credential theft, SOCKS5 proxying, and AI-assisted persistence for infected hosts. The result is a modular botnet kit that can both extract value from AI accounts and expand control over compromised systems.

Related Happenings

Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration

Technical Analysis
H score59 First: 11.09.2026 17:29 Last: 11.09.2026 17:29 Sources 1

About this happening: Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...

Sality botnet payload distribution and propagation activity

Malware Activity
H score62 First: 02.09.2026 09:56 Last: 02.09.2026 09:56 Sources 1

About this happening: The Sality P2P botnet has operated for more than 20 years and was disrupted in a US-led operation on August 31 with support from Bulgaria, Hungary, Romania, Euro...

SynkLoader Microsoft Teams help-desk phishing campaign

Campaign
H score35 First: 21.08.2026 21:01 Last: 21.08.2026 21:01 Sources 1

About this happening: The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...

SynkLoader malware distribution via Microsoft Teams phishing

Malware Activity
H score26 First: 21.08.2026 21:01 Last: 21.08.2026 21:01 Sources 1

About this happening: The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access...

Dolphin X Windows infostealer and RAT with AI victim profiling

Malware Activity
H score29 First: 23.07.2026 13:19 Last: 23.07.2026 13:19 Sources 1

About this happening: Dolphin X is a newly identified Windows infostealer and RAT that uses an AI Profiler to score, categorize, and rank infected users so attackers can prioritize higher...

Timeline

  1. 23.09.2026 17:00 1 articles · 0h ago

    WraithTools advertises x47.c botnet with credential theft and AI-assisted persistence

    Campaign Scope Update

    A WraithTools advertisement dated August 3 priced the x47.c Windows botnet from $200 to $950 and listed a top package that adds credential theft, SOCKS5 proxying and AI-assisted persistence.

    Show sources
  2. 23.09.2026 17:00 2 articles · 0h ago

    Qrator Research Labs reports x47.c Windows botnet with 18 attack methods

    Initial Disclosure

    Qrator Research Labs reported on September 23 that the previously undocumented x47.c Windows botnet offered 18 attack methods, including an AI API drain command that sends repeated billable requests to OpenAI, xAI or compatible chat APIs. The same findings described an AI Stealth module using xAI's Grok to assess infected hosts and choose persistence and concealment actions, plus Windows Defender exclusions and local fallbacks when model calls fail.

    Show sources