Close Menu
  • News
  • Entertainment
  • Sports
  • World
  • Health
  • Lifetsyle
  • contact

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Windows malware uses Grok AI to help stay hidden, researchers say

October 5, 2026

Rahm Emanuel accuses anti-Israel Dems of having no Middle East plan besides cutting funding to Jewish state

October 5, 2026

'American Idol' contestant Caleb Flynn faces betrayed family after conviction for wife’s murder

October 5, 2026
Facebook X (Twitter) Instagram
Trending
  • Windows malware uses Grok AI to help stay hidden, researchers say
  • Rahm Emanuel accuses anti-Israel Dems of having no Middle East plan besides cutting funding to Jewish state
  • 'American Idol' contestant Caleb Flynn faces betrayed family after conviction for wife’s murder
  • Journalist hilariously fails claiming WNBA's popularity isn't affected by Caitlin Clark's playoff exit
  • House GOP bill moves to close whistleblower gaps exposed by Minnesota Medicaid fraud scandal
  • Karl-Anthony Towns, Knicks nowhere close to coming to terms on an extension according to the big man
  • Biden's 'anti-MAGA task force' sparked internal alarm across DOJ, new report shows
  • Spanberger voting-rights letters sent to dead felons amid ballot access push
Facebook X (Twitter) Instagram
NEW YORK TIMES POST
  • News
  • Entertainment
  • Sports
  • World
  • Health
  • Lifetsyle
  • contact
NEW YORK TIMES POST
Home»Health»Windows malware uses Grok AI to help stay hidden, researchers say
Health

Windows malware uses Grok AI to help stay hidden, researchers say

nytimespostBy nytimespostOctober 5, 2026No Comments
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


NEWYou can now listen to Fox News articles!

A new piece of Windows malware is giving cybercriminals a lot of ways to cause trouble from one infected PC. It can steal passwords, grab browser cookies, route internet traffic through your computer and even burn through paid AI credits. Then there is the part that caught my attention. The malware, called x47.c, can reportedly use xAI’s Grok to help decide how to keep itself running on an infected Windows computer.

Security researchers at Qrator Research Labs uncovered x47.c while tracking cybercrime activity. A threat actor using the name WraithTools has been advertising access to the malware, which comes with tools for stealing credentials and launching attacks. Qrator based its findings on the seller’s advertisement, technical documentation, screenshots and follow-up messages, so the research shows what x47.c is advertised and designed to do rather than how widely it is currently infecting Windows PCs. Here’s how it works, what the AI connection really means and the steps you can take to protect your Windows PC and accounts.

AI IS NOW POWERING CYBERATTACKS, MICROSOFT WARNS

A man typing on a laptop.

Qrator researchers say x47.c gives attackers one control panel for stealing credentials, managing infected PCs and launching attacks. (Kurt “Cyberguy” Knutsson)

Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better health care.

Our free CyberGuy LIVE class Get Better Healthcare with AI has ended, but you can still watch the full replay. Kurt “CyberGuy” Knutsson walks you through five practical ways AI can help you prepare for appointments, remember important details, understand complicated medical information, research prescription questions and organize your next steps. No technical experience is needed.

Plus, recordings of all our past classes are available, including How to Stop Spam, Phone Security and Financial Protection, each with a free downloadable checklist.

Watch the free replays and get your checklists at CyberGuyLive.com

How this Windows malware works

Once x47.c infects a Windows computer, the attacker can remotely control it through a management panel. Think of that infected PC as one computer in a larger network of machines controlled by the same criminal. Security researchers call that a botnet, but the important part for you is much simpler: someone else can potentially use your computer without your permission.

The operator can tell infected machines to launch online attacks. They can also steal information from those computers or use the victim’s internet connection to route other traffic. Qrator found 18 advertised attack methods built into x47.c. Some can overwhelm websites and online services with traffic. Another targets something far newer: paid AI accounts.

Hackers can burn through paid AI credits

Many developers and businesses pay OpenAI, xAI and other AI companies based on how much they use their services. Access to those services often relies on a secret API key. You can think of that key as a password that lets an app communicate with an AI service and charge usage to an account.

If an attacker gets a valid API key, x47.c includes a feature that can repeatedly send requests to the AI provider. Those requests can use up prepaid credits or increase the victim’s bill. Qrator describes this as a “Denial of Wallet” attack. The victim’s website could keep working normally while the AI account behind part of it quietly chews through its available balance.

There is an important limit here. The attacker already needs a valid API key. x47.c does not magically break into an OpenAI or xAI account and create one. Still, that can become expensive quickly if an account allows automatic top-ups or high spending limits.

Grok can help the malware stay on your PC

The Grok connection sounds complicated, but the basic idea is pretty straightforward. Malware often tries to make sure it starts again after you reboot your computer. Security researchers call that persistence. x47.c includes what its seller calls an “AI Stealth” feature. According to Qrator, it can use Grok to look at the state of the infected computer and select from a predefined list of ways to maintain that access.

Those options include adding programs that run when Windows starts and creating scheduled tasks that can launch automatically. Grok does not appear to freely invent new attacks or control everything the malware does. Instead, it helps choose among options that the malware already has. The malware can also fall back on its own built-in methods if the AI request fails. So, cutting off its access to Grok would not necessarily remove the infection. We reached out to xAI for comment on the reported use of Grok and the safeguards it has in place to detect this kind of activity but did not hear back before our deadline.

Your saved passwords and browser sessions are targets

For most Windows users, this may be the most important part. x47.c advertises the ability to steal passwords saved in your browser. It can also collect browser cookies, Discord tokens, cryptocurrency wallet information and tokens tied to AI websites.

Browser cookies deserve special attention because some of them keep you signed in to websites. If malware steals an active login session, an attacker may be able to access an account without typing your password again. In some cases, changing the password alone may not immediately end a stolen session. That is why anyone dealing with an infected PC should also review active sessions and sign out of devices they do not recognize.

AI MALWARE CAN REWRITE ITSELF TO EVADE DETECTION

A smartphone screen displays a folder containing AI applications Claude, ChatGPT, Gemini, Perplexity, Grok, Copilot and DeepSeek. (Samuel Boivin/NurPhoto via Getty Images / Getty Images)

The malware can use xAI’s Grok to help choose from built-in ways to stay active on an infected Windows computer. (Samuel Boivin/NurPhoto via Getty Images)

Your computer can also become someone else’s internet connection

x47.c includes another feature called a SOCKS5 proxy. In plain English, that means a criminal can potentially route internet traffic through the infected computer. Online activity generated by the attacker could then appear to come from the victim’s internet connection.

The malware’s control panel lets operators see which infected computers are available to relay that traffic and whether those connections are still working. Meanwhile, the attacker can continue using the same infected machine to steal information or take part in online attacks.

9 ways to protect your Windows PC and accounts

You do not need to understand every technical feature inside x47.c to protect yourself. These steps can reduce your chances of getting infected and limit the damage if malware does reach your computer.

1) Keep Windows updated

Install Windows security updates promptly. Updates fix security weaknesses that attackers can use against PCs, even though Qrator has not identified a specific Windows vulnerability or infection method tied to x47.c. Go to Settings > Windows Update > Check for updates and install anything available.

Also remember that legitimate Windows updates come through Windows itself. A website that suddenly tells you to download a Windows update should make you suspicious. CyberGuy has previously covered fake Windows update pages that actually install malware.

2) Use strong security software

Keep strong antivirus or security software running and updated. Security tools can help catch malicious downloads and suspicious behavior before malware becomes deeply established on your computer. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.

3) Be careful about what you download

Avoid software from unfamiliar download sites, unexpected email links or pop-ups telling you that something needs an urgent update. Also be especially cautious if a webpage tells you to open Windows Run, PowerShell or Command Prompt and paste something into it. Cybercriminals increasingly use that trick to persuade people to install malware themselves. We recently covered thousands of hacked websites using fake verification prompts to push malicious Windows commands.

4) Use unique passwords

If malware steals one password, password reuse can turn one compromised account into several. Use a strong, unique password for every important account. A password manager can help create and store them.

5) Turn on two-factor authentication

Enable two-factor authentication (2FA) wherever possible. It gives attackers another obstacle if they obtain your password. However, remember that malware capable of stealing active browser sessions creates another risk, so 2FA should be one layer of your protection rather than your only one.

HALLUSQUATTING AI ATTACK COULD HIJACK YOUR COMPUTER

A person types on a laptop.

Researchers found x47.c also includes an AI API drain feature that can use a valid stolen key to burn through paid credits or increase charges. (pocketlight/Getty Images)

6) Sign out of active sessions after an infection

If you believe your PC has been infected, changing passwords should not be your only account step. From a separate trusted device, review active login sessions for your email, financial accounts, social accounts and other important services. Sign out of unfamiliar sessions or use the service’s option to sign out everywhere. Also revoke authentication tokens or connected apps you no longer recognize. Qrator specifically warns that removing the malware does not undo credentials or tokens that attackers may have already stolen.

7) Protect your AI API keys

This one mainly applies to developers, businesses and anyone paying for AI through an API. Treat an API key like a password. Never publish it in a public code repository or leave it sitting in a document that other people can access. Review AI account usage and billing for requests you do not recognize. If you think a key has leaked, revoke it and create a new one. Also use spending limits, billing alerts and controls on automatic top-ups when your AI provider offers them. Those safeguards can limit how much an attacker could spend with a stolen key.

8) Disconnect the PC if you think it has been hacked

If your computer suddenly behaves strangely or you discover malware, disconnect it from the internet. Then open your trusted security software directly and run a full scan. Do not call phone numbers in pop-ups or follow instructions from unexpected warnings on your screen. Our CyberGuy guide on what to do if your computer has been hacked walks through the next steps.

9) Change sensitive passwords from another trusted device

If malware may have stolen information from your browser, use another clean device to change the passwords for your most important accounts. Start with your primary email account because password-reset messages for other services often go there. Then move to financial accounts and other sensitive services. After changing each password, review account activity and recovery information for anything you do not recognize.

Kurt’s key takeaways

What gets my attention here isn’t simply that the malware has the word AI attached to it. We’ve seen plenty of cyberthreats use AI as part of the sales pitch. What feels different with x47.c is how many jobs the attacker can handle from the same infected Windows PC. The malware can steal passwords and browser sessions, turn the computer into a traffic relay and help launch attacks. Then Grok can assist with choosing how the malware tries to keep its foothold on that machine. Still, the most useful lesson for you comes back to the security basics. Keep Windows updated, protect your accounts and be careful about what gets installed on your PC. And if you ever discover an infection, remember that cleaning the computer is only part of the job. You also have to assume passwords, browser sessions or other account access may already be in someone else’s hands.

Should AI companies be responsible for detecting when their tools are being used in malware and alerting authorities about that kind of activity? Let us know by writing to us at CyberGuy.com.

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Copyright 2026 CyberGuy.com. All rights reserved.

Kurt “CyberGuy” Knutsson is an award-winning tech journalist who has a deep love of technology, gear and gadgets that make life better with his contributions for Fox News & FOX Business beginning mornings on “FOX & Friends.” Got a tech question? Get Kurt’s free CyberGuy Newsletter, share your voice, a story idea or comment at CyberGuy.com.

artificial intelligence cybercrime Grok hidden malware researchers security stay virus windows windows os
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related Posts

Betr Promo Code FOXNEWS: Claim $200 in Bonuses for Monday Night Football, Monday MLB Playoff Action

October 5, 2026

Country boys in Kentucky hear knocks in woods at night before one catches glimpse of Bigfoot with spotlight

October 5, 2026

Human vs humanoid robot cage fight goes viral

October 5, 2026
Leave A Reply Cancel Reply

The Latest News
  • Windows malware uses Grok AI to help stay hidden, researchers say October 5, 2026
  • Rahm Emanuel accuses anti-Israel Dems of having no Middle East plan besides cutting funding to Jewish state October 5, 2026
  • 'American Idol' contestant Caleb Flynn faces betrayed family after conviction for wife’s murder October 5, 2026
  • Journalist hilariously fails claiming WNBA's popularity isn't affected by Caitlin Clark's playoff exit October 5, 2026
  • House GOP bill moves to close whistleblower gaps exposed by Minnesota Medicaid fraud scandal October 5, 2026
  • Karl-Anthony Towns, Knicks nowhere close to coming to terms on an extension according to the big man October 5, 2026
Top Posts

Windows malware uses Grok AI to help stay hidden, researchers say

October 5, 2026

Faculty Members Suspended From Harvard’s Main Library After ‘Study-In’ Protest

January 14, 2021
7.2

Review: Amazon’s War on Bloat Alienates Workers and Pleases Wall Street

January 20, 2021

Korea Closes 4 Diplomatic Missions, Suggesting Economic Woes

January 14, 2021
Don't Miss
Health

Windows malware uses Grok AI to help stay hidden, researchers say

By nytimespostOctober 5, 2026

NEWYou can now listen to Fox News articles! A new piece of Windows malware is…

Rahm Emanuel accuses anti-Israel Dems of having no Middle East plan besides cutting funding to Jewish state

October 5, 2026

'American Idol' contestant Caleb Flynn faces betrayed family after conviction for wife’s murder

October 5, 2026

Journalist hilariously fails claiming WNBA's popularity isn't affected by Caitlin Clark's playoff exit

October 5, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

NEW YORK TIMES POST

 

Categories
  • Business
  • Culture
  • Fashion
  • Food
  • Tech
  • Sports
  • Travel
  • Nature
Services
  • News
  • Entertainment
  • Sports
  • World
  • Health
  • Lifetsyle
  • contact
About Us

Email Us: info@nytimespost.com
Contact:

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Windows malware uses Grok AI to help stay hidden, researchers say

October 5, 2026

Rahm Emanuel accuses anti-Israel Dems of having no Middle East plan besides cutting funding to Jewish state

October 5, 2026

'American Idol' contestant Caleb Flynn faces betrayed family after conviction for wife’s murder

October 5, 2026
Most Popular

Windows malware uses Grok AI to help stay hidden, researchers say

October 5, 2026

Faculty Members Suspended From Harvard’s Main Library After ‘Study-In’ Protest

January 14, 2021
7.2

Review: Amazon’s War on Bloat Alienates Workers and Pleases Wall Street

January 20, 2021
© 2026 NY TIMES POST by NEW TORK TIMES POST.

Type above and press Enter to search. Press Esc to cancel.