A newly documented Windows botnet, x47.c, adds a feature that hits a victim’s wallet instead of their servers. Qrator Research Labs found it being sold by a seller called WraithTools.
It bundles DDoS attacks, credential theft, SOCKS5 proxying, and AI-assisted persistence. Qrator Research Labs spotted x47.c during routine threat hunting. Its researchers reviewed the seller’s advertisement, technical documentation, panel screenshots, and follow-up messages.
The August 3, 2026 advertisement lists a $200 base package and a $150 DDoS add-on. The full $950 package adds credential theft, SOCKS5 proxies, and AI-assisted persistence.
New x47.c Botnet Sells 18 Attack Methods
The operator panel is titled “x47 Fast Flux C2GUI v4.1” and has separate tabs for bots, fast flux, proxies, stealer logs, stealth, and DDoS.

The “AI API drain” command needs a valid API key for the account being targeted, plus a model name. For OpenAI, xAI and compatible chat APIs, the bot then sends billable requests straight to the provider. OWASP calls this class of abuse Denial of Wallet (DoW).
Because the requests bypass the victim’s application, the website can stay online while its AI features stop working. This happens if the provider rejects requests after the balance runs out or a spending limit is hit. The seller also points to automatic top-ups as a way to keep generating charges.
Suggested targets include chatbots, AI-connected content management systems, trading bots, and scanners. WraithTools also pitches the method for use against competitors.
Anyone with a valid key could script this. What stands out is that a botnet seller markets it as a built-in attack.
The other 17 methods include HTTP floods, slow HTTP connections, TCP and UDP floods, TLS connection stress, and reflection and amplification techniques. Each bot runs one attack at a time.
The SYN mode uses raw sockets when privileges allow, and otherwise falls back to ordinary TCP connections. Qrator found no throughput data backing the advertised protection-bypass modes, so their effectiveness is unproven.
For resilience, bots remember their last working C2 destination and try alternatives on failure. The panel shows six domains and eight IP addresses. Documentation says several domains can point to one VPS, so the domain count does not prove there are independent servers.
An “AI Stealth” module uses xAI Grok to assess the host and pick predefined persistence and concealment actions. It needs an xAI key in the build and falls back to local actions if a model call fails. Persistence options include startup entries and scheduled tasks. Process hollowing and privilege elevation are optional.

The stealer targets browser passwords, cookies, and Discord tokens. The advertisement also lists wallets and AI-site tokens. The documentation does not show stolen tokens being converted into API keys for the drain command. The SOCKS5 module uses a reverse connection through C2 to relay traffic through the victim’s network.
Defenders face three separate problems.
- Endpoints: AV/EDR should block the malware before it persists. Isolate infected hosts, remove the bot and its persistence, and revoke stolen credentials, cookies, and tokens.
- AI accounts: Revoke exposed keys, compare billing with real application usage, set spending caps, and restrict automatic top-ups. Filtering website traffic will not stop these direct provider calls.
- DDoS: Protection must cover both application and network layers.
Corroborate these filenames and strings with host and network activity.
| Type | Indicator |
|---|---|
| Seller username | WraithTools |
| Product | x47.c, Fast Flux Edition v4.1 |
| Panel title | x47 Fast Flux C2GUI v4.1 |
| Package directory | x47.c_FF_v4.1 |
| EXE output | x47_bot.exe |
| DLL output | x47_bot.dll |
| C2 server script | server_master.js |
| Relay handshake prefix | REVERSE_PROXY| |
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.