Wireva

Windows Malware x47.c Uses xAI's Grok to Stay Hidden, Researchers Say

Security researchers at Qrator Research Labs have uncovered a new Windows malware called x47.c that can reportedly use xAI's Grok chatbot to help maintain persistence on infected machines. The malware, advertised by a threat actor known as WraithTools, also steals passwords, browser cookies, and cryptocurrency wallet data, and can launch denial-of-wallet attacks against paid AI accounts.

A new Windows malware strain called x47.c can reportedly use xAI's Grok artificial intelligence chatbot to help decide how to keep itself running on infected computers, according to security researchers at Qrator Research Labs. The malware, which is being advertised by a threat actor using the name WraithTools, bundles credential theft, browser cookie collection, and traffic routing tools into a single package that gives cybercriminals multiple ways to profit from one compromised PC.

Qrator based its findings on the seller's advertisement, technical documentation, screenshots, and follow-up messages. That means the research shows what x47.c is advertised and designed to do rather than how widely it is currently infecting Windows machines. The malware's control panel allows an attacker to remotely manage infected computers, turning them into part of a botnet that can be used to launch online attacks, steal information, or route other traffic through the victim's internet connection.

The AI connection centers on a feature the seller calls «AI Stealth.» According to Qrator, x47.c can use Grok to examine the state of an infected computer and select from a predefined list of methods to maintain access after a reboot. Those options include adding programs that run when Windows starts and creating scheduled tasks that launch automatically. Grok does not appear to freely invent new attacks or control everything the malware does. Instead, it helps choose among options the malware already has, and the malware can fall back on its own built-in methods if the AI request fails. Cutting off access to Grok would not necessarily remove the infection.

Qrator found 18 advertised attack methods built into x47.c. Some can overwhelm websites and online services with traffic. Another targets paid AI accounts through what Qrator describes as a «Denial of Wallet» attack. Many developers and businesses pay OpenAI, xAI, and other AI companies based on usage, and access to those services often relies on a secret API key. If an attacker obtains a valid API key, x47.c includes a feature that can repeatedly send requests to the AI provider, using up prepaid credits or increasing the victim's bill. The attacker already needs a valid API key for this to work; the malware does not break into an AI account and create one. But the cost can escalate quickly if an account allows automatic top-ups or high spending limits.

For most Windows users, the credential theft features may be the most immediate concern. x47.c advertises the ability to steal passwords saved in browsers and collect browser cookies, Discord tokens, cryptocurrency wallet information, and tokens tied to AI websites. Browser cookies deserve special attention because some keep users signed in to websites. If malware steals an active login session, an attacker may be able to access an account without typing a password again. In some cases, changing the password alone may not immediately end a stolen session, so anyone dealing with an infected PC should also review active sessions and sign out of devices they do not recognize.

The malware also includes a SOCKS5 proxy feature, which means a criminal can potentially route internet traffic through the infected computer. Online activity generated by the attacker could then appear to come from the victim's internet connection. The malware's control panel lets operators see which infected computers are available to relay traffic and whether those connections are still working. Meanwhile, the attacker can continue using the same infected machine to steal information or take part in online attacks.

xAI did not respond to a request for comment on the reported use of Grok and the safeguards it has in place to detect this kind of activity. The findings add to growing warnings from security researchers and technology companies that artificial intelligence tools are increasingly being incorporated into cybercriminal operations, both as targets and as helpers.

Same event, other desks

Story file →