WraithTools is the seller name associated with marketing x47.c, a Windows botnet and remotely operated attack toolkit. The offering is sold in tiered packages and is marketed with a command-and-control panel, fast-flux configuration, information-stealer logging, proxy management, host software-management functions, concealment features, and distributed-denial-of-service operations. x47.c is advertised as supporting browser-password, cookie, Discord-token, cryptocurrency-wallet-data, and AI-service-token theft; SOCKS5 relaying through compromised hosts; and DDoS methods including HTTP, slow-connection, TCP, UDP, TLS-stress, reflection, and amplification attacks. WraithTools also promotes an AI API credit-draining function that sends billable requests directly to AI providers using an operator-supplied valid API key, potentially exhausting prepaid credits or generating charges. Advertised host-maintenance and concealment features include startup-entry and scheduled-task persistence, local fallback actions, Windows Defender exclusions, optional process hollowing and privilege escalation, and a rootkit module intended to remove artifacts from other malware. The advertised AI-assisted persistence module uses xAI Grok to select from predefined maintenance actions. Available evidence establishes the marketing and claimed functionality of x47.c, but does not establish its initial-access mechanism, scale of infections, verified victims, measured attack capacity, or confirmed losses.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Markets and operates the x47.c botnet toolkit, which advertises browser credential, cookie, Discord-token and wallet/token theft; SOCKS5 proxy relays; persistence; and HTTP, TCP, UDP, slow-connection, TLS-stress, and reflection DDoS capabilities. It also advertises an AI-credit-draining function that uses an operator-supplied valid API key to send requests directly to supported AI APIs. The report documents advertised capabilities rather than confirmed infections, victims, campaign activity, or operational performance.
Commercially selling and operating the x47.c Windows botnet offering, which supports credential theft, DDoS attacks, SOCKS5 proxying, AI-service credit draining, persistence, and remote control of compromised hosts.
Sells access to the x47.c Windows botnet, which supports DDoS attacks, credential and token theft, SOCKS5 proxying, fast-flux command-and-control, and AI API credit-draining attacks against accounts using OpenAI, xAI, and compatible chat APIs.
Markets the x47.c Windows botnet, including a denial-of-wallet capability that abuses valid AI-service API keys to submit billable requests and exhaust victims' AI credits.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.