Windows Malware x47.c Uses Grok AI for Persistence, a New Threat to Credentials and AI Credits
Baca dalam 60 detik
- Malware x47.c yang dijual oleh aktor ancaman WraithTools dilaporkan memakai Grok AI untuk memilih metode persistensi di komputer Windows yang terinfeksi.
- Selain mencuri kata sandi dan cookie browser, malware ini menawarkan 18 metode serangan, termasuk serangan Denial of Wallet yang menguras kredit API AI.
- Pengguna Windows dan pengembang diimbau memperbarui sistem, menggunakan autentikasi dua faktor, serta memantau penggunaan API dan sesi login secara berkala.

A Windows malware called x47.c is reported to use xAI's Grok AI to determine how to survive on infected computers. The finding was disclosed by Qrator Research Labs after tracking malware sales activity by a threat actor calling itself WraithTools. If accurate, this marks a new shift: AI is no longer merely a defensive tool, but is starting to be integrated into the cyber attack chain.
According to Qrator's report, x47.c is designed as a multipurpose attack package. From a single infected PC, attackers can steal credentials, grab browser cookies, route internet traffic through the victim's computer, and drain AI API credits. Qrator found 18 attack methods on offer, including traffic flooding attacks (DDoS) and a feature called "Denial of Wallet"—exhausting prepaid balances or inflating the victim's bill by sending repeated requests to AI providers using stolen API keys.
What sets x47.c apart from conventional malware is its "AI Stealth" feature. Instead of relying solely on built-in persistence mechanisms, the malware asks Grok to analyze the condition of the infected system and choose from a predefined list of methods—such as adding a startup program or creating a scheduled task—to maintain access. Grok does not create new attacks; it helps select existing options. If the request to Grok fails, the malware can fall back to its internal methods. That means cutting off access to Grok does not automatically remove the infection.
The impact on victims can be layered. Session cookie theft allows attackers to access accounts without needing a password, even after the victim changes it. Meanwhile, the SOCKS5 proxy feature lets attackers hide their online activity behind the victim's internet connection. For companies using AI APIs, a key leak can lead to unexpected bills, especially if the account allows automatic top-ups.
"What is interesting is not just the AI label on the malware, but the amount of work that can be handled from a single infected PC," a Qrator researcher said, stressing that the most important lesson still comes back to security fundamentals.
As of this report, xAI has not commented on the finding. Qrator emphasized that their findings come from a seller's advertisement, technical documentation, screenshots, and follow-up messages—not from direct infection analysis. Nevertheless, the report is enough to spark discussion about AI providers' responsibility to detect misuse of their tools.
For users in Indonesia, this threat is relevant given the high adoption of AI services such as OpenAI and xAI among local developers and businesses. Many startups and technology companies in the country use API keys to access large language models, often without strict oversight of usage and billing. An API key leak can lead to significant financial losses, especially if the account is linked to automatic payment methods. Therefore, basic security practices—such as not storing API keys in public repositories, enabling spending limits, and monitoring suspicious activity—are becoming increasingly crucial.
Mitigation steps recommended by Qrator include regularly updating Windows, using reliable antivirus software, and being wary of unknown download sites or requests to run PowerShell commands. If infected, victims are advised to disconnect from the internet, run a full scan, and from another clean device, review active login sessions and revoke unknown tokens. Changing passwords alone is not enough because stolen sessions may still be valid.
Going forward, the integration of AI into malware such as x47.c could trigger a new arms race between attackers and security service providers. The question is whether AI companies will take a more active role in detecting misuse of their tools, or whether responsibility remains with users. Without proactive steps, this gap could become an entry point for a generation of cyber attacks that are smarter and harder to detect.



