x47.c Malware Leverages Grok AI to Maintain Persistence and Drain API Credits

Security researchers at Qrator Research Labs identified x47.c, a Windows malware advertised by the threat actor WraithTools that integrates xAI's Grok to maintain persistence on infected machines. The tool steals browser cookies, passwords, and cryptocurrency tokens while enabling a 'Denial of Wallet' attack that burns through paid AI API credits. Although the malware uses AI to select from predefined persistence methods, it retains fallback options if AI requests fail, and its primary risk remains credential theft and traffic routing rather than autonomous attack generation.
Key points
- Qrator Research Labs discovered x47.c through the WraithTools marketplace, confirming its capabilities via technical documentation and screenshots rather than widespread infection data.
- The malware includes an 'AI Stealth' feature that uses Grok to analyze system states and select from a predefined list of persistence methods, such as scheduled tasks and startup programs.
- x47.c offers 18 advertised attack methods, including credential theft for browsers, Discord, and crypto wallets, as well as a SOCKS5 proxy to route traffic through victim machines.
- A 'Denial of Wallet' feature allows attackers to use stolen API keys to exhaust prepaid credits or inflate bills for OpenAI and xAI services, though it requires pre-existing valid keys.
- Security experts advise that removing the malware does not undo stolen credentials, urging users to review active sessions and revoke tokens from trusted devices after any suspected infection.
Background
This development follows a trend of AI-integrated malware observed in late 2026, including the RatHat Android malware, which used AI to navigate devices and capture credentials via touch inputs. While RatHat targeted mobile accessibility permissions, x47.c focuses on Windows persistence and financial exploitation of AI service credits, marking a shift toward leveraging AI for operational efficiency rather than just evasion.
How outlets are covering it
Fox News and CyberGuy emphasize the multifaceted nature of x47.c, highlighting its ability to combine credential theft, traffic routing, and AI credit draining in a single tool. They stress that while Grok assists with persistence, the malware retains non-AI fallbacks, meaning blocking AI access does not guarantee removal. CyberSecurityNews frames the story around the novel 'Denial of Wallet' attack, focusing on the financial impact on developers and businesses using AI APIs. All sources agree that the threat is currently advertised rather than widely deployed, but they differ in emphasis: Fox News focuses on user protection steps, while CyberSecurityNews highlights the economic risk to AI service users.
Why it matters
The integration of AI into malware persistence and financial attacks signals a maturation of cyber threats, where AI is used not just for evasion but for operational decision-making. The 'Denial of Wallet' attack introduces a new vector for financial harm, potentially affecting businesses reliant on AI APIs. This underscores the need for robust API key management and session hygiene, as traditional password changes may not suffice if active browser sessions are compromised.
What to watch
Security firms will likely monitor for widespread deployment of x47.c beyond the WraithTools marketplace. AI providers like xAI may implement stricter monitoring for anomalous API usage patterns to detect 'Denial of Wallet' attacks. Users and businesses should prioritize securing API keys, enabling two-factor authentication, and regularly reviewing active sessions to mitigate risks from credential theft and session hijacking.
- Windows malware uses Grok AI to help stay hidden, researchers say Fox News
- Hackers find a new way to attack companies: Draining their AI credits Escudo Digital
- New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits gbhackers.com
- Hackers Built a Botnet That Doesn’t Just Steal Data, It Burns AI Credits CyberSecurityNews
- Windows malware uses Grok AI to help stay hidden Kurt the CyberGuy
Want the full story? Read the original reporting
Read on Fox News