Wfmd New Windows Malware x47.c Uses AI to Evade Detection and Exploit Systems
Article Content
- •x47.c malware uses Grok AI for enhanced evasion tactics.
- •It can steal sensitive information and exhaust AI service credits.
- •The malware creates a botnet, allowing remote control of infected PCs.
A new Windows malware named x47.c has emerged, leveraging xAI's Grok AI to enhance its evasion techniques. This malware can steal passwords, capture browser cookies, and route internet traffic through infected PCs, effectively creating a botnet for attackers. It features 18 different attack methods, including the ability to exhaust paid AI credits through a 'Denial of Wallet' attack. Victims may experience increased bills from AI service providers as the malware can repeatedly send requests using stolen API keys. The malware's capabilities allow attackers to remotely control infected machines and launch various online attacks. The full scope of its impact is still being assessed, but it poses a significant threat to users of Windows systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track X47.c in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected by x47.c?
How does x47.c use AI?
What should users do to protect themselves?
Continue Reading
New x47.c Botnet Targets AI Services with API Draining Attacks A new Windows botnet, x47.c, has been discovered offering 18 attack methods, including a feature to drain AI credits from victims' accounts. This botnet, sold by a seller known as WraithTools, allows attackers to exploit valid API keys for services like OpenAI and xAI, executing a denial-of-wallet (DoW) attack. The…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…