New Windows malware x47.c leverages Grok AI to evade detection
Researchers identified a Windows malware called x47.c that can steal credentials, route traffic and use xAI's Grok to help maintain persistence.
Security analysts at Qrator Research Labs discovered a Windows-based malware family named x47.c, promoted by a cybercriminal group called WraithTools. The toolset includes functions for stealing saved passwords, browser cookies, Discord tokens and cryptocurrency wallet data, as well as a SOCKS5 proxy that can relay an attacker’s traffic through the victim’s PC. It also features a mechanism to repeatedly call AI services using stolen API keys, potentially exhausting prepaid credits in a "Denial of Wallet" attack.
The malware’s "AI Stealth" module can query xAI's Grok to select among pre-programmed persistence techniques such as startup entries or scheduled tasks, though it can fall back on its own methods if the AI request fails. Researchers recommend keeping Windows updated, running reputable antivirus software, avoiding suspicious downloads, using unique passwords, enabling two-factor authentication, and securing AI API keys. In case of infection, users should disconnect from the internet, scan the system, and change passwords from a clean device while reviewing active sessions.
Why it matters
The malware shows how AI services can be abused to enhance cyber-attacks, raising risks for both users and developers.
In this story
