New Windows Malware Uses Grok AI to Evade Detection, Researchers Say
New Windows Malware Uses Grok AI to Evade Detection, Researchers Say

Technology

New Windows Malware Uses Grok AI to Evade Detection, Researchers Say

Researchers at Qrator Research Labs say a newly advertised Windows malware called x47.c can steal passwords and browser sessions, drain paid AI accounts, and use xAI’s Grok to help it stay running on infected machines.

Security researchers have identified a new strain of Windows malware that can steal passwords, hijack browser sessions, drain paid AI accounts and even call on xAI’s Grok chatbot to help it survive on an infected computer.

The malware, called x47.c, was uncovered by Qrator Research Labs while tracking cybercrime activity online. A threat actor using the name WraithTools has been advertising access to the tool, which comes bundled with credential-stealing features and attack capabilities. Qrator’s findings are based on the seller’s advertisement, technical documentation, screenshots and follow-up messages, meaning the research describes what x47.c is designed and marketed to do rather than how widely it has already spread.

Once installed on a Windows PC, x47.c lets an attacker control the machine remotely through a management panel, effectively folding it into a network of hijacked computers known as a botnet. From there, the operator can steal information, route other internet traffic through the victim’s connection, or order the machine to join online attacks. Qrator counted 18 advertised attack methods built into the malware, some aimed at overwhelming websites with traffic.

Targeting AI accounts directly

One feature targets something newer: paid AI accounts. Many developers and businesses pay companies such as OpenAI and xAI based on usage, accessed through a secret API key that functions like a password linking an app to billing. If an attacker obtains a valid key, x47.c can flood the AI provider with repeated requests, burning through prepaid credits or driving up the victim’s bill. Qrator calls this a “Denial of Wallet” attack — the victim’s website may keep functioning normally while the AI account behind it quietly runs out of money.

The malware cannot manufacture its own API key; it needs one that’s already been compromised. But for accounts with automatic top-ups or high spending limits, the costs can escalate quickly.

How Grok fits in

The malware’s seller advertises an “AI Stealth” feature that, according to Qrator, can use Grok to assess an infected computer’s state and choose from a predefined list of ways to keep the malware running after a reboot — a capability researchers call persistence. Those options include adding programs that launch when Windows starts or creating scheduled tasks. Grok does not appear to invent new attack methods or control the malware broadly; it selects among options the malware already has built in, and the malware can fall back on its own methods if the AI request fails.

xAI was asked for comment on the reported use of Grok and what safeguards it has in place to detect this kind of activity but did not respond before publication.

What else it can steal

For most users, the more immediate concern is x47.c’s ability to steal passwords saved in web browsers, along with browser cookies, Discord tokens, cryptocurrency wallet information and tokens tied to AI websites. Stolen cookies can be particularly damaging because some keep users signed in to accounts; if a malware operator grabs an active login session, they may be able to access that account without ever needing the password. Changing a password alone does not necessarily end a session that’s already been hijacked.

The malware also includes a SOCKS5 proxy feature, which lets an attacker route their own internet traffic through an infected computer so it appears to come from the victim’s connection — all while that same machine continues to be mined for stolen data or used in attacks.

Protecting yourself

  • Install Windows security updates promptly through Settings > Windows Update, and be suspicious of any website urging you to download an update directly.
  • Keep antivirus or security software running and updated.
  • Avoid downloads from unfamiliar sites, unexpected email links, or pop-ups demanding urgent updates. Be especially wary of any webpage instructing you to paste commands into Windows Run, PowerShell or Command Prompt.
  • Use a unique, strong password for every important account, ideally with a password manager.
  • Enable two-factor authentication as an added layer, recognizing it won’t stop session-theft attacks on its own.

If a PC is believed to be infected, Qrator warns that removing the malware does not undo any credentials or tokens already stolen. Victims should disconnect the device from the internet, run a full scan with trusted security software, and then — from a separate clean device — change passwords starting with the primary email account, since password-reset messages for other services typically route there. Users should also review active login sessions on email, financial and social accounts, sign out of unrecognized devices, and revoke unfamiliar authentication tokens or connected apps.

Developers and businesses using AI APIs should treat their keys like passwords: never publish them in public code repositories, review billing for unrecognized usage, revoke and replace any key suspected of leaking, and use spending limits or billing alerts where providers offer them.

Click to comment

You must be logged in to post a comment Login

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

You May Also Like

US Politics

I do not even know where to begin with this one.  Just when you think you have seen the worst that humanity has to...

Government Corruption

Updated 5/17/19 9:52am Jack Crane | Opinion  James Baker, Former-FBI General Counsel has joined Russian hoax media collaborator Michael Isikoff on his podcast, yesterday....

US News

Education is considered to be one of the pillars of a successful life. Without a college degree, many believe these students will earn lower...

US News

ICYMI| If it were not for Tom Fitton and Judicial Watch, it is more than likely that the world would never know the extent...