New Windows Botnet Uses Grok AI to Dodge Antivirus, Drain Credits

A new Windows botnet called x47.c uses xAI's Grok to hide from antivirus tools and drain victims' paid AI API credits, researchers say.

Sep 29, 2026 - 07:07
5 min read
 0
New Windows Botnet Uses Grok AI to Dodge Antivirus, Drain Credits

Picture a piece of malware that doesn't just try to delete your antivirus and hope for the best, but stops mid-attack to ask a chatbot what to do next — then acts on the answer. That's not a hypothetical anymore. Security researchers have found a Windows botnet, tracked as x47.c, that leans on xAI's Grok to decide how to stay hidden on an infected machine, alongside a separate trick built to quietly run up victims' AI bills.

What x47.c Actually Does

A botnet, in plain terms, is a network of hijacked computers a criminal controls remotely, usually to launch attacks or steal data without the owners noticing anything's wrong. Researchers at Qrator Research Labs documented x47.c in a report published on September 23, after spotting it being sold on underground forums by a seller going by WraithTools. The listing isn't subtle about what's on offer: 18 separate attack methods bundled together, including distributed denial-of-service (DDoS) attacks that flood a target with traffic until it buckles, credential theft, and SOCKS5 proxy access that lets buyers route their own traffic through infected machines. Pricing starts around $200 for the base package, with a DDoS add-on for $150, and the full kit going for roughly $950 — malware-as-a-service pricing that wouldn't look out of place on a legitimate software vendor's site.

An AI That Picks Its Own Hiding Spots

The part that's actually new is a module the seller calls "AI Stealth." Instead of following a fixed script to avoid detection, x47.c can query xAI's Grok model and ask it to choose from a list of predefined persistence actions — things like adding startup entries, creating scheduled tasks, or carving out exclusions in Windows Defender so the malware stops getting scanned. Status messages pulled from the malware describe it reporting back on persistence repairs and Defender exclusions as they happen, and if the call to Grok fails for any reason, the malware falls back to a hardcoded local routine instead of just giving up. It's a small design choice, but it tells you the people building this expect their tools to keep working even when one piece breaks.

Malware that can ask an AI model how to hide better, on the fly, is a meaningfully different problem than malware built around a checklist someone wrote six months ago.

The "Denial of Wallet" Trick

The second AI-related feature is arguably the more original one. x47.c includes an "AI API drain" command that takes a stolen or leaked API key — for OpenAI, xAI, or a similar chat service — and fires a stream of billable requests straight at the provider. Security researchers call this a denial-of-wallet attack: rather than knocking a website offline, the attacker just burns through the victim's prepaid or metered AI credits in the background. The application itself can stay online the whole time, which means the first sign of trouble is often a shockingly large invoice, not a service outage.

Why This Matters for India's AI Boom

This lands at an awkward moment for Indian software teams. Startups from Bengaluru to Pune have spent the last two years bolting AI API calls onto everything from customer support bots to internal tools, often with API keys sitting in code repositories, CI pipelines, or laptops that aren't locked down as tightly as production servers. A leaked key in any of those places is now a direct financial exposure, not just a security embarrassment. CERT-In, the government's nodal cybersecurity agency, already pushes regular advisories on credential hygiene and incident reporting timelines under Indian law, and a threat built specifically to monetize leaked AI keys is exactly the kind of thing that should push smaller Indian AI startups to rotate keys and set hard spending caps with their model providers, rather than treating API budgets as an afterthought. Piracy and cracked-software use remain common on Indian home and small-business PCs too, which is historically how botnets like this one find their first few thousand victims.

It also reinforces a point Code24 covered recently around Palo Alto Networks' big bet on agentic AI security: the same AI capability that's supposed to make defense smarter is just as available to whoever's on the attacking side. Nobody has exclusive rights to Grok or GPT-style reasoning — a criminal with $950 gets access to broadly the same class of model as a security operations center evaluating six-figure enterprise tools.

A few things worth flagging if you're responsible for security at an Indian startup or SME right now:

  • Rotate and scope any AI API keys that have ever touched a developer laptop, not just production servers.
  • Set hard monthly spend caps with your model provider — most now support this — so a drain attack fails loudly instead of just showing up on the bill.
  • Treat unexplained Windows Defender exclusions or scheduled tasks on end-user machines as worth investigating, not routine noise.
  • Keep antivirus and OS licensing genuine; cracked software remains one of the most common infection paths for exactly this kind of botnet.

None of this requires panic. x47.c is one botnet among many, and "AI-assisted persistence" is still mostly a cost-cutting move for criminals rather than some unstoppable new capability. But it's a preview of where commodity malware is heading: attackers renting a slice of the same AI infrastructure everyone else is racing to adopt, and pointing it at whichever task used to need a human's judgment. The defenders who assume that shift is coming will have a much easier time than the ones who find out from an invoice.

Short URL: https://code24.in/af0507c0

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Code24 Team Code24 Team