New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
A threat actor has been selling access to a new Windows botnet that relies on AI to maintain persistence on infected hosts, Qrator reports.
Dubbed x47.c, it is advertised by a threat actor named WraithTools as providing distributed denial-of-service (DDoS) and credential theft capabilities, SOCKS5 proxies, and an AI API drain method.
In early August, the threat actor offered the botnet’s base package for $200 and asked $150 for the DDoS add-on. The entire x47.c package, containing the full botnet capabilities, was priced at $950.
Users are provided with a command-and-control (C&C) panel that provides access to bot management, fast-flux configuration options, information stealer logs, proxies, concealment capabilities, and DDoS attack options.
The panel’s DDoS tab provides access to 18 attack methods, including HTTP floods, AI API draining, slow HTTP, TCP and UDP floods, TLS stresser, and various reflection and amplification techniques.
While the HTTP, TCP, and UDP methods...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE