Home · Technology · Oct 5 archive
New Windows Malware Uses AI to Stay Hidden
Confirmed
In Short: Security researchers have discovered a new piece of Windows malware, x47.c, which reportedly uses Grok AI from xAI to help it stay hidden on infected computers.

According to Qrator researchers, x47.c can use Grok to analyze the state of an infected computer and choose from a predefined list of methods to maintain access.
These methods include adding programs that run on startup and creating scheduled tasks.
The malware also uses NetSupport RAT, a well-known tool that allows attackers to remotely control infected computers.
Once x47.c infects a Windows computer, attackers can use a control panel to steal credentials, manage infected PCs, and launch attacks.
Researchers warn that x47.c can survive computer restarts and secretly communicate with attackers through a Telegram bot.
Another campaign involves compromised websites using fake verification prompts to trick users into opening the Windows Run dialog and pasting a command that launches malware.
This technique, known as ClickFix, is a social engineering method that tricks users into executing malicious commands on their own devices.
Island researchers noted that legitimate CAPTCHAs should never instruct users to open Windows Run or paste a command.
The malware campaign also targets users searching for ChatGPT, redirecting them to a fake page that claims high traffic and directs them to a supposed backup domain.
Proofpoint researchers discovered BlueMoon, an exploit kit that chains three vulnerabilities to install malware.
BlueMoon targets critical vulnerabilities in Chromium-based browsers and older versions of Windows.
Proofpoint hypothesized that the exploit kit took advantage of a 'patch gap' in the Chromium supply chain, where vulnerabilities were known but not yet patched in public browser releases.
What this adds
This report adds details on how x47.c uses Grok AI to maintain access on infected computers, as well as the broader context of exploit kits like BlueMoon targeting vulnerabilities in Chromium-based browsers and older versions of Windows.
Background
Security researchers at Huntress uncovered a new malware campaign that uses a real ChatGPT page to trick users into installing malware.
What's confirmed
- According to Qrator researchers, x47.c can use Grok to analyze the state of an infected computer and choose from a predefined list of methods to maintain access.
- These methods include adding programs that run on startup and creating scheduled tasks.
- The malware also uses NetSupport RAT, a well-known tool that allows attackers to remotely control infected computers.
- Once x47.c infects a Windows computer, attackers can use a control panel to steal credentials, manage infected PCs, and launch attacks.
- Researchers warn that x47.c can survive computer restarts and secretly communicate with attackers through a Telegram bot.
- Another campaign involves compromised websites using fake verification prompts to trick users into opening the Windows Run dialog and pasting a command that launches malware.
- This technique, known as ClickFix, is a social engineering method that tricks users into executing malicious commands on their own devices.
- Island researchers noted that legitimate CAPTCHAs should never instruct users to open Windows Run or paste a command.
- The malware campaign also targets users searching for ChatGPT, redirecting them to a fake page that claims high traffic and directs them to a supposed backup domain.
- Proofpoint researchers discovered BlueMoon, an exploit kit that chains three vulnerabilities to install malware.
- BlueMoon targets critical vulnerabilities in Chromium-based browsers and older versions of Windows.
- Proofpoint hypothesized that the exploit kit took advantage of a 'patch gap' in the Chromium supply chain, where vulnerabilities were known but not yet patched in public browser releases.
What's still developing
- A new piece of Windows malware is giving cybercriminals a lot of ways to cause trouble from one infected PC.
- The malware, called x47.c, can reportedly use xAI's Grok to help decide how to keep itself running on an infected Windows computer.
- Malware often tries to make sure it starts again after you reboot your computer.
- We reached out to xAI for comment on the reported use of Grok and the safeguards it has in place to detect this kind of activity but did not hear back before our deadline.
- Watch the replay and discover 5 ways AI can help you get better health care.
- Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you prepare for appointments, remember important details, understand complicated medical information, research prescription questions and organize your next steps.
- Security researchers call that a botnet, but the important part for you is much simpler: someone else can potentially use your computer without your permission.
- Researchers at Island say that attackers are creating their own content inside ChatGPT – via CustomGPT – and then buying Google ads to direct people to it.
- A routine Google search for ChatGPT is being turned into a malware trap targeting Windows users, researchers have warned.
- Videos shared on social media showed people leaning out of windows for fresh air as thick black smoke and bright orange flames engulfed part of the historic building.
- “Both V8 vulnerabilities were ‘patch-gap’ zero-days at the time of the observed activity,” Proofpoint said.
- A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.
