Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A Windows botnet called x47.c can spend victims’ paid AI credits, steal data, and flood websites. Its operator markets it as an attack toolkit for remote use.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Startup entries and scheduled tasks support persistence; fallback actions work if the model call fails.
Startup entries and scheduled tasks support persistence; fallback actions work if the model call fails.
“Optional process hollowing and privilege escalation capabilities are also available.”
The botnet, sold by WraithTools, includes capabilities for credential theft, SOCKS5 proxying, and an AI module for malware persistence.
The stealer targets browser passwords, cookies and Discord tokens.
Other modules collect browser data and turn infected machines into SOCKS5 traffic relays... The relay sends traffic out through the victim’s network, potentially hiding where the operator actually sits.
The AI drain feature requires a valid API key for the account being charged... bots send requests directly to an AI provider. Accepted requests consume credits or generate charges.
“The DDoS section provides 18 attack methods, including HTTP floods, slow HTTP attacks, TCP and UDP floods, TLS stresser activity, and reflection and amplification techniques.”
The panel also offers HTTP floods, slow connections, TCP and UDP floods, and other service disruption methods.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows botnet and operator toolkit that provides control of compromised hosts, steals browser passwords, cookies, Discord tokens, and advertised wallet/AI-site tokens; supports HTTP, TCP, UDP, slow-connection, TLS-stress, and reflection flood methods; can operate infected systems as SOCKS5 relays; and uses startup entries and scheduled tasks for persistence. Its advertised AI-credit-drain capability requires an operator-supplied valid API key and sends requests directly to compatible AI-provider APIs. The report documents advertised functionality rather than verified infections, victims, attack performance, or losses.
Windows botnet sold by WraithTools that provides command-and-control of infected hosts, steals browser passwords, cookies, Discord tokens, cryptocurrency-wallet data, and AI-service tokens; supports SOCKS5 proxying, DDoS attacks, and direct API-request abuse to deplete paid AI credits. Its advertised AI-stealth module uses xAI Grok-assisted selection of persistence actions such as startup entries and scheduled tasks, with local fallbacks; optional process hollowing, privilege escalation, and rootkit functionality are also promoted.
Windows botnet sold as a service that provides DDoS capabilities, credential and browser-cookie theft, SOCKS5 proxying, software download/update/removal, optional process hollowing and privilege escalation, and a rootkit module to remove rival artifacts. Its AI-stealth persistence module uses xAI Grok to select from predefined persistence actions such as startup entries and scheduled tasks, with local fallback behavior when AI calls fail. It can also use stolen AI API keys to directly exhaust victims' paid AI credits.
Windows botnet sold by WraithTools. It supports credential theft, SOCKS5 proxying, HTTP and UDP flooding, and AI-assisted host assessment and concealment. Its AI API-drain function abuses valid API keys to issue billable requests directly to AI providers, depleting a victim's paid AI credits in a denial-of-wallet attack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.