Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label AI cybersecurity risks. Show all posts

x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining

 

A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks, SOCKS5 proxy access and a method designed to drain paid AI credits. According to Qrator, the malware also uses artificial intelligence to help maintain persistence on infected systems. 

The botnet is advertised by a threat actor known as WraithTools. In early August, the operator offered the base x47.c package for $200, with a DDoS add-on priced at $150. The complete package, including its full range of capabilities, was offered for $950. Customers receive access to a command-and-control panel that allows them to manage infected machines and access features including fast-flux configuration, information-stealing logs, proxies, concealment capabilities and DDoS operations. 

The DDoS section provides 18 attack methods, including HTTP floods, slow HTTP attacks, TCP and UDP floods, TLS stresser activity, and reflection and amplification techniques. One feature specifically targets paid artificial intelligence services. The AI drain mode is designed to consume a victim’s AI credits by sending requests directly to an AI provider. The operator supplies a model name and a valid API key for accounts using OpenAI, xAI and compatible chat APIs. Because the requests are sent directly to the provider, the targeted website can remain accessible while the account’s available AI credits are depleted. x47.c also incorporates an “AI stealth” module designed to maintain persistence on compromised Windows systems. 

The feature is advertised as using xAI Grok to select actions from a predefined list, including startup entries and scheduled tasks. Optional process hollowing and privilege escalation capabilities are also available. According to Qrator, the operator activates the AI functionality by including an xAI key in the botnet build. Status messages can indicate startup changes, persistence repairs and Windows Defender exclusions. The malware also has local fallback actions that allow maintenance operations to continue when an AI model call fails. 

The botnet provides operators with additional control over infected systems. They can select DDoS targets and download, update or remove software from compromised hosts. A rootkit module is also promoted for removing artifacts associated with rival malware. Beyond DDoS activity, x47.c can harvest passwords and cookies from browsers, along with Discord tokens, cryptocurrency wallet data and AI-service tokens. 

Its SOCKS5 module allows compromised systems to relay traffic, while operators can monitor proxy connections and review their health status and timeouts. The combination of AI-assisted persistence, credential theft, proxy capabilities, DDoS functions and AI credit draining makes x47.c a broad Windows botnet offering multiple ways to abuse compromised systems and online services.

AI Adoption Surges Faster Than Cybersecurity Awareness, Study Reveals

 

A recent study has revealed that the rapid adoption of AI tools like ChatGPT and Gemini is far outpacing efforts to educate users about the cybersecurity risks associated with them. The research, conducted by the National Cybersecurity Alliance (NCA) — a nonprofit organization promoting data privacy and online safety — in collaboration with cybersecurity firm CybNet, surveyed over 6,500 participants across seven countries, including the United States.

The findings show that 65% of respondents now use AI tools daily, reflecting a 21% increase compared to last year. However, 58% of users said they had not received any formal training from their employers on the data security and privacy risks of using such technologies.

"People are embracing AI in their personal and professional lives faster than they are being educated on its risks," said Lisa Plaggemier, Executive Director at the NCA. Alarmingly, 43% of respondents admitted to sharing sensitive information — including financial and client data — in conversations with AI tools. This underscores the growing gap between AI adoption and cybersecurity preparedness.

The NCA-CybNet report adds weight to a growing concern among experts that the surge in AI use is not being matched by adequate awareness or safety measures. Earlier this year, a SailPoint survey found that 96% of IT professionals viewed AI agents as potential security risks, yet 84% said their companies had already begun deploying them internally.

AI agents, designed to automate complex tasks and boost efficiency, often require access to internal systems and sensitive documents — a setup that could lead to data leaks or breaches. Some incidents, such as AI tools accidentally deleting entire company databases, highlight how vulnerabilities can quickly escalate into serious problems.

Even conventional chatbots carry risks. Besides producing inaccurate information, many also store user interactions as training data, making privacy a persistent concern. The 2023 case of Samsung engineers inadvertently leaking confidential data to ChatGPT serves as a cautionary example, prompting the company to prohibit employee use of the chatbot.

As generative AI becomes embedded in everyday tools — Microsoft recently added AI features to Word, Excel, and PowerPoint — users may be adopting it without realizing the full scope of its implications. Without robust cybersecurity education, individuals and businesses could expose themselves to significant risks in pursuit of productivity and convenience.