X47.c Windows botnet offering AI API-draining and credential-theft tooling
Malware Activity
Summary
Hide ▲
Show ▼
The previously undocumented x47.c Windows botnet now appears in a seller offering 18 attack methods, including an AI API drain command that can burn paid credits at providers such as OpenAI and xAI. The same package also includes credential theft, SOCKS5 proxying, and AI-assisted persistence for infected hosts. The result is a modular botnet kit that can both extract value from AI accounts and expand control over compromised systems.
Related Happenings
Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration
Technical Analysis
H score59
First: 11.09.2026 17:29
Last: 11.09.2026 17:29
Sources 1
About this happening:
Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...
Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration
Technical AnalysisAbout this happening: Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...
Sality botnet payload distribution and propagation activity
Malware Activity
H score62
First: 02.09.2026 09:56
Last: 02.09.2026 09:56
Sources 1
About this happening:
The Sality P2P botnet has operated for more than 20 years and was disrupted in a US-led operation on August 31 with support from Bulgaria, Hungary, Romania, Euro...
Sality botnet payload distribution and propagation activity
Malware ActivityAbout this happening: The Sality P2P botnet has operated for more than 20 years and was disrupted in a US-led operation on August 31 with support from Bulgaria, Hungary, Romania, Euro...
SynkLoader Microsoft Teams help-desk phishing campaign
Campaign
H score35
First: 21.08.2026 21:01
Last: 21.08.2026 21:01
Sources 1
About this happening:
The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...
SynkLoader Microsoft Teams help-desk phishing campaign
CampaignAbout this happening: The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...
SynkLoader malware distribution via Microsoft Teams phishing
Malware Activity
H score26
First: 21.08.2026 21:01
Last: 21.08.2026 21:01
Sources 1
About this happening:
The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access...
SynkLoader malware distribution via Microsoft Teams phishing
Malware ActivityAbout this happening: The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access...
Dolphin X Windows infostealer and RAT with AI victim profiling
Malware Activity
H score29
First: 23.07.2026 13:19
Last: 23.07.2026 13:19
Sources 1
About this happening:
Dolphin X is a newly identified Windows infostealer and RAT that uses an AI Profiler to score, categorize, and rank infected users so attackers can prioritize higher...
Dolphin X Windows infostealer and RAT with AI victim profiling
Malware ActivityAbout this happening: Dolphin X is a newly identified Windows infostealer and RAT that uses an AI Profiler to score, categorize, and rank infected users so attackers can prioritize higher...
Timeline
-
23.09.2026 17:00 1 articles · 0h ago
WraithTools advertises x47.c botnet with credential theft and AI-assisted persistence
Campaign Scope UpdateA WraithTools advertisement dated August 3 priced the x47.c Windows botnet from $200 to $950 and listed a top package that adds credential theft, SOCKS5 proxying and AI-assisted persistence.
Show sources
- Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods — www.infosecurity-magazine.com — 23.09.2026 17:00
-
23.09.2026 17:00 2 articles · 0h ago
Qrator Research Labs reports x47.c Windows botnet with 18 attack methods
Initial DisclosureQrator Research Labs reported on September 23 that the previously undocumented x47.c Windows botnet offered 18 attack methods, including an AI API drain command that sends repeated billable requests to OpenAI, xAI or compatible chat APIs. The same findings described an AI Stealth module using xAI's Grok to assess infected hosts and choose persistence and concealment actions, plus Windows Defender exclusions and local fallbacks when model calls fail.
Show sources
- Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods — www.infosecurity-magazine.com — 23.09.2026 17:00
- Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods — www.infosecurity-magazine.com — 23.09.2026 17:00