Security researchers at Qrator Research Labs have uncovered a new Windows malware family, dubbed x47.c, that incorporates artificial intelligence to help it stay hidden on compromised computers. The threat actor behind the tool, known as WraithTools, advertises a suite of credential‑stealing and attack capabilities, and the researchers based their analysis on the seller’s own marketing materials, screenshots and follow‑up messages.
How the malware works
Once installed, x47.c gives the attacker remote control of the infected machine through a management panel, effectively turning the PC into a node of a larger botnet. The operator can launch a variety of attacks, including Distributed Denial of Service (DDoS) floods, data exfiltration, and a novel “Denial of Wallet” attack that abuses valid AI service API keys to consume prepaid credits or trigger high usage charges.
The AI component, called an “AI Stealth” feature, calls xAI’s Grok to evaluate the state of the host system and select from a predefined list of persistence methods. These include adding programs to the Windows startup sequence and creating scheduled tasks that automatically relaunch the malware after a reboot. Grok does not create new attacks on its own; it simply helps the malware pick the most effective existing technique.
Potential impact on users
According to Qrator, x47.c can harvest saved browser passwords, cookies, Discord tokens, cryptocurrency wallet information and tokens for AI services. Stolen cookies can keep attackers logged into victim accounts even after a password change, making session termination a critical step for anyone who suspects infection.
The malware also includes a SOCKS5 proxy function, allowing criminals to route internet traffic through the victim’s connection. This can mask the true source of malicious activity and make it appear as though the victim’s IP address is responsible for the traffic.
Protecting your Windows PC
While the technical details may seem daunting, there are practical steps every Windows user can take to reduce the risk of infection and limit damage if compromised:
- Keep Windows up to date. Install security updates promptly via Settings → Windows Update. Even though no specific vulnerability has been linked to x47.c, updates close known gaps that attackers often exploit.
- Use reputable antivirus or endpoint‑security software. Modern security suites can detect suspicious behavior and block malicious downloads before they take hold.
- Download software only from trusted sources. Avoid unfamiliar download sites, unexpected email links, and pop‑ups that claim an urgent update is required.
- Be wary of scripts. Do not run PowerShell, Command Prompt or Windows Run commands pasted from unknown webpages.
- Employ unique, strong passwords for each account. A password manager can generate and store complex passwords, preventing a single breach from compromising multiple services.
- Enable two‑factor authentication (2FA) wherever possible. While 2FA adds an extra barrier, remember that stolen active sessions can still bypass it, so combine it with regular password changes and session reviews.
What to do if you suspect infection
If you notice unusual system behavior, unexpected network traffic or unexplained charges on AI service accounts, run a full scan with your security software and change passwords for any accounts that may have been accessed. Review active browser sessions and sign out of devices you do not recognize.
Because the AI‑assisted persistence feature can fall back on built‑in methods, simply cutting off Grok access may not fully remove the malware. A thorough cleanup—potentially involving a clean reinstall of Windows—may be necessary.
Industry response
The researchers reached out to xAI for comment on the reported use of Grok and any safeguards the company has in place to detect such abuse, but had not received a response at the time of publication.
As AI tools become more integrated into everyday software, security professionals warn that threat actors will continue to explore ways to weaponize these capabilities. Staying informed, maintaining good cyber hygiene, and keeping systems patched remain the most effective defenses against emerging threats like x47.c.
Original reporting: Fox News (HLL/CB) — read the source article.