CYBERSECURITYTRACKER
TRACKING
Permanent story citation

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8646

As cited

Copy frozen at (site build).

threat intel

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

A Windows botnet called x47.c leverages xAI's Grok artificial intelligence (AI) service to sustain its presence on infected systems by dynamically selecting from a set of predefined actions. The botnet drains the AI application programming interface (API) as part of its operational model.

Why it matters: Organizations running Windows systems need to monitor for x47.c infections and API-based abuse; defenders should track whether Grok API consumption spikes indicate botnet activity on their networks.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary