New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Summary
A new Windows botnet called x47.c uses AI to stay hidden on infected computers and offers multiple attack capabilities including DDoS (distributed denial-of-service, overwhelming a target with traffic), credential theft, and an 'AI drain' method that consumes victims' paid API credits by sending requests directly to AI services like OpenAI and xAI Grok. The botnet is sold by a threat actor named WraithTools with packages ranging from $200 to $950, and includes a control panel that lets operators manage infected machines, choose attack methods, and maintain persistence using AI to decide which hiding techniques to use.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/
First tracked: September 26, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 92%