The Your
Oct 07, 2026
HyperLocal Loop
The Your

Close to home. Always in the loop.

New Windows malware x47.c leverages xAI’s Grok to evade detection

Security researchers at Qrator Research Labs have uncovered a new Windows malware family, dubbed x47.c, that incorporates artificial intelligence to help it stay hidden on compromised computers. The threat actor behind the tool, known as WraithTools, advertises a suite of credential‑stealing and attack capabilities, and the researchers based their analysis on the seller’s own marketing materials, screenshots and follow‑up messages.

How the malware works

Once installed, x47.c gives the attacker remote control of the infected machine through a management panel, effectively turning the PC into a node of a larger botnet. The operator can launch a variety of attacks, including Distributed Denial of Service (DDoS) floods, data exfiltration, and a novel “Denial of Wallet” attack that abuses valid AI service API keys to consume prepaid credits or trigger high usage charges.

The AI component, called an “AI Stealth” feature, calls xAI’s Grok to evaluate the state of the host system and select from a predefined list of persistence methods. These include adding programs to the Windows startup sequence and creating scheduled tasks that automatically relaunch the malware after a reboot. Grok does not create new attacks on its own; it simply helps the malware pick the most effective existing technique.

Potential impact on users

According to Qrator, x47.c can harvest saved browser passwords, cookies, Discord tokens, cryptocurrency wallet information and tokens for AI services. Stolen cookies can keep attackers logged into victim accounts even after a password change, making session termination a critical step for anyone who suspects infection.

The malware also includes a SOCKS5 proxy function, allowing criminals to route internet traffic through the victim’s connection. This can mask the true source of malicious activity and make it appear as though the victim’s IP address is responsible for the traffic.

Protecting your Windows PC

While the technical details may seem daunting, there are practical steps every Windows user can take to reduce the risk of infection and limit damage if compromised:

  • Keep Windows up to date. Install security updates promptly via Settings → Windows Update. Even though no specific vulnerability has been linked to x47.c, updates close known gaps that attackers often exploit.
  • Use reputable antivirus or endpoint‑security software. Modern security suites can detect suspicious behavior and block malicious downloads before they take hold.
  • Download software only from trusted sources. Avoid unfamiliar download sites, unexpected email links, and pop‑ups that claim an urgent update is required.
  • Be wary of scripts. Do not run PowerShell, Command Prompt or Windows Run commands pasted from unknown webpages.
  • Employ unique, strong passwords for each account. A password manager can generate and store complex passwords, preventing a single breach from compromising multiple services.
  • Enable two‑factor authentication (2FA) wherever possible. While 2FA adds an extra barrier, remember that stolen active sessions can still bypass it, so combine it with regular password changes and session reviews.

What to do if you suspect infection

If you notice unusual system behavior, unexpected network traffic or unexplained charges on AI service accounts, run a full scan with your security software and change passwords for any accounts that may have been accessed. Review active browser sessions and sign out of devices you do not recognize.

Because the AI‑assisted persistence feature can fall back on built‑in methods, simply cutting off Grok access may not fully remove the malware. A thorough cleanup—potentially involving a clean reinstall of Windows—may be necessary.

Industry response

The researchers reached out to xAI for comment on the reported use of Grok and any safeguards the company has in place to detect such abuse, but had not received a response at the time of publication.

As AI tools become more integrated into everyday software, security professionals warn that threat actors will continue to explore ways to weaponize these capabilities. Staying informed, maintaining good cyber hygiene, and keeping systems patched remain the most effective defenses against emerging threats like x47.c.


Original reporting: Fox News (HLL/CB) — read the source article.

OBBM Network Editorial Staff

[email protected]

Editorial team behind OBBM Network — independent, hyper-local journalism syndicated through HyperLocalLoop and OBBM Network TV.

Leave a Reply

Your email address will not be published. Required fields are marked *

Recent News

Trending

Community News

Quick Start Deal

Turn Local Reach Into Real Leads

A monthly bundle that puts your business in front of local audiences across HyperLocal Loop and the OBBM Network — and delivers ready-to-contact buyers to your team.

$500 Per Month
What's Included
  • LeadEngine · 1,000 Contacts Verified, buyer-intent prospects in your market, delivered to your team
  • DataPulse · 1,000 Matches Identify and retarget anonymous visitors to your site
  • Banner Ads · 3 Cities Geo-targeted display placement across HyperLocal Loop in three cities
  • Video Commercial · 3 Cities Your commercial airs on the local OBBM channel in three cities
  • Audio · 10,000 Impressions Podcast ad impressions across the OBBM Network
  • Geo-Targeting City or regional targeting via AdServe
  • Real-Time Reporting Track campaign performance as it happens
Questions about any of this? Ask Ben →
Get Started
Secure checkout · Cancel anytime
Quick Start Deal

Get Loop-Ready in One Move

A low-commitment monthly bundle that keeps your business in front of local audiences across HyperLocal Loop and the OBBM Network.

$350 Per Month
What's Included
  • DataPulse · 1,000 Matches Identify and retarget anonymous visitors to your site
  • Banner Ads Geo-targeted display placement across HyperLocal Loop
  • Video Ad Airs on your Local OBBM Channel
  • Business Advertorial A featured sponsored article telling your story
Questions about any of this? Ask Ben →
Get Started
Secure checkout · Cancel anytime
§ 04 · Choose Your Package

Three levels. Up to 60% off.

Every Patriot Package is priced at over 40% off standard AdRevv list rates — and the discount deepens as you scale, up to 60% off at the Enterprise tier.

Tier I · Local
The Patriot
For local & regional brands launching with the network.
List Price: $835/mo
$500/mo
★ Save $335 — 40% Off
Monthly Allotment
  • Audio: 10,000Podcast impressions
  • Video: 10,000Streaming TV impressions
  • Banners: 50,000HyperLocal Loop geo-targeted banner impressions
  • DataPulse: First 1,000visitor matches included
  • City or regional geo-targeting via AdServe
  • Real-time campaign reporting
Start The Patriot
Tier III · National
The Enterprise
For national brands ready to dominate the network.
List Price: $5,065/mo
$2026/mo
★ Save $3,039 — 60% Off
Monthly Allotment
  • Audio: 14,000Podcast impressions
  • Video: 10,000Streaming TV impressions
  • Banners: 100,000HyperLocal Loop geo-targeted impressions
  • DataPulse: 5,000visitor matches included
  • LeadEngine: 20,000actionable buyer-intent contacts
  • Host Endorsements: 9podcast host-read spots
  • National geo-targeting + dedicated campaign manager
  • Priority creative production support
★ Bonus Included ★
Free 1-Year Freedom Chamber Membership
Faith, Family & Freedom business community at freedomchamber.net.
Start Enterprise

Need a custom configuration? Build your own package →