Cybersecurity firm Qrator disclosed a Windows botnet called x47.c, sold by a threat actor for $200 to $950, that uses xAI’s Grok model to autonomously choose persistence actions on infected machines, such as creating startup entries and scheduled tasks, with local fallback logic if the AI call fails. The malware also includes an “AI drain mode” that targets OpenAI, xAI, and compatible APIs to consume victims’ paid AI credits, alongside DDoS, credential theft, and proxy capabilities. No specific victim organizations or total losses have been publicly confirmed.