# Researchers identify Windows malware advertised with Grok-assisted persistence

_Published Monday, October 5, 2026 at 3:18 PM EDT · Security · Latest · Tier 2 — Notable_

![x47.c malware uses Grok to steal passwords and maintain PC access — Primary](https://static.foxnews.com/foxnews.com/content/uploads/2026/10/man-working-on-laptop.jpg)

Windows malware called x47.c is advertised with features that use Grok to help maintain access to infected computers and drain paid AI accounts, according to Qrator Research Labs. Its findings draw on a seller's advertisement, technical documentation, screenshots and follow-up messages rather than evidence of widespread infections.

The Grok feature selects among predefined ways to restart the malware, including Windows startup entries and scheduled tasks. Built-in methods can take over if the AI request fails. Other advertised features steal credentials and browser sessions or relay traffic through victims' computers.

An API billing attack repeatedly sends requests to consume credits or increase charges. It requires an attacker to already possess a valid API key.

## Sources

- [Fox News](https://www.foxnews.com/tech/windows-malware-uses-grok-ai-help-stay-hidden-researchers-say)

---
Canonical: https://techandbusiness.org/newswire/zt-L-GQEc0rX2l2Ut5FB60
Published: 2026-10-05T19:18:20.662Z
Story chronology: 2026-10-05T18:30:45.000Z
Retrieved: 2026-10-05T21:59:18.119Z
Publisher: Tech & Business (techandbusiness.org)
