Security researchers have identified a new strain of Windows malware, called x47.c, that can enlist xAI’s Grok chatbot to help it stay hidden on infected computers while also stealing passwords, hijacking browser sessions and draining victims’ AI service accounts.
Qrator Research Labs uncovered the malware while tracking cybercrime activity online. A threat actor using the name WraithTools has been advertising access to x47.c, which comes bundled with tools for stealing credentials and launching attacks. Qrator’s findings are based on the seller’s advertisement, technical documentation, screenshots and follow-up messages. That means the research describes what x47.c is designed and marketed to do, not necessarily how widely it has already spread across Windows machines.
What the malware can do
Once x47.c infects a computer, an attacker can control it remotely through a management panel, effectively folding the machine into a larger network of hijacked computers known as a botnet. From there, the operator can direct infected machines to launch online attacks, steal data, or route other internet traffic through the victim’s connection. Qrator counted 18 advertised attack methods built into the malware, including tools capable of overwhelming websites and online services with traffic.
One of those methods targets something newer: paid AI accounts. Many developers and businesses pay AI companies like OpenAI and xAI based on usage, accessed through a secret API key that functions like a password linking an app to a billing account. If an attacker obtains a valid key, x47.c can repeatedly send requests to the AI provider, burning through prepaid credits or inflating a victim’s bill — what Qrator calls a “Denial of Wallet” attack. The malware cannot create a key out of nothing; it needs one that’s already been compromised. But if an account allows automatic top-ups or high spending limits, the financial damage can add up fast.
The Grok connection
Malware authors have long built in ways to make sure their code restarts after a victim reboots their machine, a technique researchers call persistence. x47.c includes a feature its seller calls “AI Stealth,” which, according to Qrator, can call on Grok to assess the state of an infected computer and choose from a predefined list of methods to maintain access — such as adding programs that launch at Windows startup or creating scheduled tasks.
Grok does not appear to invent new attack techniques or control the malware outright. It selects among options the malware already has built in, and the malware can fall back on its own methods if the AI request fails, meaning cutting off access to Grok would not eliminate an infection. xAI did not respond to a request for comment on the reported use of Grok or what safeguards it has to detect this kind of misuse.
What’s at stake for ordinary users
For most Windows users, the more immediate danger is simpler: x47.c advertises the ability to steal passwords saved in browsers, along with browser cookies, Discord tokens, cryptocurrency wallet information and tokens tied to AI websites. Stolen cookies are particularly concerning because some keep users signed in to accounts without re-entering a password — meaning a changed password alone may not end a hijacked session.
The malware also includes a SOCKS5 proxy feature, letting an attacker route their own internet traffic through a victim’s computer so it appears to originate from the victim’s connection — all while continuing to steal data or participate in attacks from the same machine.
How to protect yourself
- Install Windows security updates promptly through Settings > Windows Update > Check for updates. Be wary of any website urging you to download a Windows update directly — legitimate updates come through Windows itself.
- Keep antivirus or security software running and updated to catch malicious downloads before they take hold.
- Avoid software from unfamiliar download sites, unexpected email links or urgent-update pop-ups, and never paste commands into Windows Run, PowerShell or Command Prompt at a webpage’s instruction.
- Use strong, unique passwords for every important account, ideally with a password manager, so one stolen password doesn’t compromise multiple accounts.
- Enable two-factor authentication as an added layer, though it won’t stop malware that steals active browser sessions outright.
Anyone who suspects infection should do more than change passwords: from a separate trusted device, review active login sessions on email, financial and social accounts, sign out of unrecognized sessions, and revoke unfamiliar authentication tokens or connected apps. Qrator notes that removing the malware itself does not undo any credentials or tokens already stolen.
Developers and businesses using AI APIs should treat keys like passwords — never publishing them in public code repositories — and should review billing activity regularly, revoke and replace any key suspected of leaking, and use spending limits or billing alerts where providers offer them.
If a computer is showing signs of infection, disconnect it from the internet, run a full scan with trusted security software, and avoid following instructions from unexpected pop-ups. If a browser may have been compromised, change passwords for critical accounts from a separate clean device, starting with the primary email account since password resets for other services typically route through it.
