Updated
Updated · Fox News · Oct 5
x47.c Malware Uses Grok for Persistence, Packs 18 Attack Methods
Updated
Updated · Fox News · Oct 5

x47.c Malware Uses Grok for Persistence, Packs 18 Attack Methods

2 articles · Updated · Fox News · Oct 5

Summary

  • Qrator Research says x47.c is being marketed as a Windows malware platform that can use xAI’s Grok to choose persistence methods, while also stealing credentials and remotely controlling infected PCs.
  • Grok’s role appears limited to selecting from built-in options such as startup entries and scheduled tasks; the malware can still fall back on its own persistence methods if AI access fails.
  • 18 advertised attack methods include password and browser-cookie theft, Discord and crypto token harvesting, SOCKS5 proxying through victims’ internet connections, and botnet-style attacks launched from a central panel.
  • A separate “Denial of Wallet” feature can drain paid AI credits by abusing already-stolen API keys, potentially running up bills without disrupting the victim’s website or app.
  • Qrator said its findings come from sales ads, technical documents, screenshots and follow-up messages, showing what x47.c is designed to do rather than how widely it has infected Windows machines.

Insights

Is the new AI-assisted stealth feature in Windows malware a genuine technical threat, or just a clever marketing gimmick by cybercriminals?
Could a hidden malware strain be quietly draining your company's AI budget without ever triggering a traditional security alarm?
Why does changing your passwords no longer protect your accounts after a device is infected by this new cybercriminal toolkit?