A new strain of Windows malware is raising eyebrows because it does more than the usual password theft and data grabbing. Researchers say x47.c can hijack infected PCs, steal browser cookies and even tap Grok AI to help decide how to stay hidden on the system.
Security teams found the malware while tracking cybercrime activity, and the public details come from seller ads, technical notes, screenshots and messages tied to the operation. That means the evidence shows how x47.c is being marketed and what it is built to do, not how many computers it has already reached.
The most troubling part is how many jobs one infected machine can end up doing for criminals. Once inside a Windows PC, the malware can be controlled through a panel that lets attackers issue commands, steal data and use the victim’s connection for their own traffic.
Researchers say the malware advertises 18 attack methods, including traffic flooding and account abuse. One of the newer twists is the ability to pressure AI services and drain paid credits when attackers already have a valid API key.
That is where the “Denial of Wallet” idea comes in. Instead of breaking an AI account outright, the malware can keep sending requests until usage charges climb or prepaid credits disappear, which can leave the victim with a nasty surprise on the bill.
The Grok tie-in is even stranger. x47.c reportedly includes an “AI Stealth” feature that checks the infected machine and then uses Grok to pick from a list of persistence tricks, such as startup entries or scheduled tasks that help the malware come back after a reboot.
Grok does not appear to be making up new tricks on the fly. It is being used more like a selector, helping the malware choose from options already built into the tool, while the code still has fallback methods if the AI call fails.
For everyday users, the biggest danger is often the old-school stuff. The malware is designed to grab saved passwords, browser cookies, Discord tokens, crypto wallet data and tokens tied to AI accounts, which can open the door to account takeover even after the computer looks normal again.
Stolen cookies are especially nasty because they can keep someone signed in without needing the password again. That means changing a password alone may not be enough if the attacker already has an active session sitting in the background.
x47.c also includes a SOCKS5 proxy feature, which lets criminals route traffic through the infected computer. In plain terms, the attacker can make online activity look like it came from the victim’s connection while the machine is also being used for theft or attacks.
Protection still comes down to the basics, and those basics matter a lot. Keep Windows updated, use reputable security software, avoid sketchy downloads and be suspicious of any page that pushes fake updates or tells you to paste commands into Run, PowerShell or Command Prompt.
Strong, unique passwords help limit the damage if one account gets hit. Turning on two-factor authentication adds another layer, but it should be treated as backup protection, not a magic shield against malware that can steal sessions.
If an infection is suspected, the response has to be quick and calm. Disconnect the PC, scan it with trusted security software, and then use another clean device to change important passwords, review active sessions and revoke any tokens or connected apps that look unfamiliar.
Developers and businesses using AI APIs need to be extra careful with keys and billing settings. API credentials should be treated like passwords, with spending caps, alerts and revocation ready to go if anything looks off.
The broader lesson here is that malware is getting more efficient, not necessarily more mysterious. One infected Windows machine can now be turned into a password thief, a traffic relay, an attack tool and a way to burn through AI money, all while trying to stick around for the long haul.
