#6
SecurityWeek
general
September 26, 2026 at 12:00 UTC
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
By Ionut Arghire
AI Summary
A newly identified Windows botnet dubbed 'x47.c' uses the xAI Grok API to dynamically select persistence and evasion actions from a predefined set, representing an early example of AI-driven decision-making in botnet operations. The botnet also drains the Grok API credits of compromised hosts, adding a financial impact vector for victims beyond standard botnet harms. Security teams should monitor for anomalous xAI API usage and outbound connections to Grok endpoints as potential indicators of x47.c compromise.
Relevance score: 72.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →