x47.c Malware Uses Grok for Persistence, Packs 18 Attack Methods
Updated
Updated · Fox News · Oct 5
x47.c Malware Uses Grok for Persistence, Packs 18 Attack Methods
2 articles · Updated · Fox News · Oct 5
Summary
Qrator Research says x47.c is being marketed as a Windows malware platform that can use xAI’s Grok to choose persistence methods, while also stealing credentials and remotely controlling infected PCs.
Grok’s role appears limited to selecting from built-in options such as startup entries and scheduled tasks; the malware can still fall back on its own persistence methods if AI access fails.
18 advertised attack methods include password and browser-cookie theft, Discord and crypto token harvesting, SOCKS5 proxying through victims’ internet connections, and botnet-style attacks launched from a central panel.
A separate “Denial of Wallet” feature can drain paid AI credits by abusing already-stolen API keys, potentially running up bills without disrupting the victim’s website or app.
Qrator said its findings come from sales ads, technical documents, screenshots and follow-up messages, showing what x47.c is designed to do rather than how widely it has infected Windows machines.