Wireva

Windows Malware x47.c Uses Grok AI to Evade Detection, Researchers Say

Security researchers at Qrator Research Labs have uncovered a new Windows malware called x47.c that reportedly uses xAI's Grok chatbot to help it maintain persistence on infected computers. The malware, advertised by a threat actor known as WraithTools, also steals passwords, browser cookies, and cryptocurrency wallet data, and can launch denial-of-wallet attacks against paid AI accounts.

A new Windows malware strain called x47.c is using xAI's Grok chatbot to help it stay hidden on infected computers, according to security researchers at Qrator Research Labs. The malware, which is being advertised by a threat actor using the name WraithTools, combines credential theft, browser cookie harvesting, and proxy capabilities with an AI-assisted persistence feature that researchers say represents a notable evolution in cybercriminal tooling.

Qrator based its findings on the seller's advertisement, technical documentation, screenshots, and follow-up messages. The research therefore shows what x47.c is advertised and designed to do rather than how widely it is currently infecting Windows PCs. The malware's control panel allows an attacker to remotely manage infected machines, turning them into part of a botnet that can be used for a range of criminal activities.

The most unusual feature is what the seller calls «AI Stealth.» According to Qrator, x47.c can use Grok to examine the state of an infected computer and then select from a predefined list of methods to maintain access after a reboot. Those options include adding programs that run when Windows starts and creating scheduled tasks that launch automatically. Grok does not appear to freely invent new attacks or control the malware's overall operation. Instead, it helps choose among options the malware already has. The malware can also fall back on its own built-in methods if the AI request fails, meaning that cutting off its access to Grok would not necessarily remove the infection.

Qrator found 18 advertised attack methods built into x47.c. Some are designed to overwhelm websites and online services with traffic. Another targets paid AI accounts. Many developers and businesses pay OpenAI, xAI, and other AI companies based on how much they use their services, and access often relies on a secret API key. If an attacker obtains a valid key, x47.c includes a feature that can repeatedly send requests to the AI provider, using up prepaid credits or increasing the victim's bill. Qrator describes this as a «Denial of Wallet» attack. The victim's website could keep working normally while the AI account behind part of it quietly chews through its available balance. The attacker already needs a valid API key; x47.c does not break into an OpenAI or xAI account to create one. Still, the costs can add up quickly if an account allows automatic top-ups or high spending limits.

For most Windows users, the credential theft capabilities may be the most immediate concern. x47.c advertises the ability to steal passwords saved in browsers. It can also collect browser cookies, Discord tokens, cryptocurrency wallet information, and tokens tied to AI websites. Browser cookies deserve special attention because some keep users signed in to websites. If malware steals an active login session, an attacker may be able to access an account without typing a password again. In some cases, changing the password alone may not immediately end a stolen session, so anyone dealing with an infected PC should also review active sessions and sign out of devices they do not recognize.

x47.c also includes a SOCKS5 proxy feature, which means a criminal can potentially route internet traffic through the infected computer. Online activity generated by the attacker could then appear to come from the victim's internet connection. The malware's control panel lets operators see which infected computers are available to relay traffic and whether those connections are still working. Meanwhile, the attacker can continue using the same infected machine to steal information or take part in online attacks.

The reported use of Grok highlights a growing intersection between artificial intelligence and cybercrime. Microsoft has previously warned that AI is now powering cyberattacks, and researchers have documented malware that can rewrite itself to evade detection. In this case, the AI component is limited to selecting among existing persistence methods rather than generating new ones, but it still represents a meaningful shift in how malware operators may seek to automate decisions that were once manual.

xAI did not respond to a request for comment on the reported use of Grok and the safeguards it has in place to detect this kind of activity. For Windows users, the practical takeaways remain familiar: keep software updated, use reputable security tools, monitor account sessions for unfamiliar devices, and treat saved browser passwords and active cookies as sensitive data that can be exploited if a machine is compromised.

Same event, other desks

Story file →