Malware uses Grok AI to stay hidden and steal passwords
Malware is asking Grok AI how to hide. According to the security industry, a Windows malware known as x47.c has been found querying xAI's artificial intelligence Grok for instructions on how to conceal itself on infected computers and persist, then using the responses it receives.
x47.c can inflict a range of damage from a single infected PC. It can steal passwords and harvest browser cookies, redirect other traffic through the infected PC's internet connection, and drain credits from paid AI accounts.
Researchers at Qrator Research Labs discovered the malware while tracking cybercriminal activity. Among threat actors, a seller using the name WraithTools had been advertising access to the malware, which includes password-stealing and attack tools.
According to Qrator's analysis, x47.c uses Grok AI to determine how to keep itself running on infected Windows computers. Infected PCs can also be remotely controlled through the attacker's admin panel and used as part of a botnet. The analysis is based on the malware's design and advertising materials, and the current extent of x47.c infections has not been confirmed.
