New Windows Malware Leverages Grok AI for Stealth and Data Theft
Researchers discover x47.c malware using xAI's Grok to maintain persistence and execute various cybercrimes, including API key exploitation.
A new piece of Windows malware, identified as x47.c, is equipped with advanced capabilities that allow cybercriminals to steal sensitive information, reroute internet traffic, and exploit paid AI services. Security researchers at Qrator Research Labs have uncovered the malware, which notably uses xAI's Grok AI to help maintain its presence on infected computers.
The threat actor known as WraithTools has been advertising access to x47.c, which is bundled with tools designed for credential theft and launching attacks. Qrator's findings are based on the seller's advertisements, technical documentation, and related communications, detailing the malware's advertised functionalities rather than its current infection prevalence.
Malware Functionality
Once x47.c infects a Windows computer, it establishes a remote control channel through a management panel, effectively turning the victim's machine into part of a botnet. Attackers can remotely command infected machines to launch online attacks, exfiltrate data, or utilize the victim's internet connection for illicit traffic relay. Qrator identified 18 advertised attack methods within x47.c.
Exploitation of AI Services
A significant feature of x47.c targets paid AI accounts, specifically utilizing a technique dubbed "Denial of Wallet" by Qrator. The malware can send repeated requests to AI providers, using a stolen API key to drain prepaid credits or inflate the victim's bill. This attack does not create new API keys but leverages existing, compromised ones. If an account has automatic top-ups or high spending limits, this can lead to substantial financial losses for the victim.
Grok's Role in Persistence
The integration of Grok AI into x47.c assists the malware in achieving persistence, meaning it attempts to ensure it remains active even after a system reboot. The malware's seller refers to this as an "AI Stealth" feature. According to Qrator, Grok helps the malware select from a pre-defined list of methods to maintain access, such as adding programs to Windows startup or creating scheduled tasks. While Grok aids in selecting existing persistence mechanisms, it does not appear to independently create new attack vectors. The malware can revert to its built-in methods if Grok access fails.
xAI was contacted for comment regarding the reported use of Grok and its safeguards against such activity but had not responded by the time of the report.
Data Theft Capabilities
x47.c is designed to steal a range of sensitive information from infected Windows PCs. This includes passwords saved in web browsers, browser cookies that can maintain active login sessions, cryptocurrency wallet information, and tokens associated with AI websites. The ability to steal browser cookies is particularly concerning, as it can allow attackers to hijack active sessions without needing the user's password.
Proxy Functionality
The malware also includes a SOCKS5 proxy feature, enabling attackers to route their internet traffic through the infected computer. This can mask the attacker's origin, making their online activities appear to originate from the victim's internet connection. The malware's control panel allows operators to manage these traffic relay connections.
Protective Measures
To mitigate the risks posed by x47.c and similar threats, users are advised to:
- Keep Windows Updated: Promptly install all Windows security updates to patch vulnerabilities. Be wary of fake update prompts from websites.
- Use Strong Security Software: Maintain updated antivirus and security software to detect and block malicious downloads and behavior.
- Exercise Caution with Downloads: Avoid software from untrusted sources, unsolicited email links, or pop-ups demanding urgent action. Be suspicious of instructions to run commands in Windows.
- Employ Unique Passwords: Use strong, unique passwords for all accounts and consider using a password manager.
- Enable Two-Factor Authentication (2FA): Implement 2FA wherever available as an additional security layer, understanding its limitations against session hijacking.
- Sign Out of Active Sessions: If an infection is suspected, review and sign out of all active login sessions on important accounts from a trusted device.
- Secure AI API Keys: Treat API keys as passwords, avoid exposing them publicly, monitor usage, and revoke compromised keys immediately. Utilize spending limits and alerts offered by AI providers.
- Isolate Infected PCs: If a computer is suspected of infection, disconnect it from the internet and run a full scan with security software.
- Change Sensitive Passwords: Use a separate, clean device to change passwords for critical accounts, starting with primary email and financial services.
Researchers emphasize that even after removing malware, stolen credentials and active sessions may remain compromised. Basic security hygiene remains the most effective defense against evolving cyber threats.