Skip to content
New Windows Malware x47.c Uses AI to Evade Detection and Exploit Systems

New Windows Malware x47.c Uses AI to Evade Detection and Exploit Systems

First seen 5 Oct 2026, 20:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 21:26 UTC
  • •x47.c malware uses Grok AI for enhanced evasion tactics.
  • •It can steal sensitive information and exhaust AI service credits.
  • •The malware creates a botnet, allowing remote control of infected PCs.

A new Windows malware named x47.c has emerged, leveraging xAI's Grok AI to enhance its evasion techniques. This malware can steal passwords, capture browser cookies, and route internet traffic through infected PCs, effectively creating a botnet for attackers. It features 18 different attack methods, including the ability to exhaust paid AI credits through a 'Denial of Wallet' attack. Victims may experience increased bills from AI service providers as the malware can repeatedly send requests using stolen API keys. The malware's capabilities allow attackers to remotely control infected machines and launch various online attacks. The full scope of its impact is still being assessed, but it poses a significant threat to users of Windows systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
x47.c malware discovered
Researchers identified the x47.c malware, which uses AI to evade detection and exploit systems.
Foxnews

More articles in this cluster (2)

Following this threat?

Track X47.c in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected by x47.c?
The x47.c malware primarily targets Windows operating systems.
How does x47.c use AI?
x47.c employs xAI's Grok to enhance its evasion techniques and maintain persistence on infected systems.
What should users do to protect themselves?
Users should ensure their systems are updated and consider monitoring for unusual activity related to AI service usage.