According to SecurityWeek, a Windows botnet tracked as x47.c has added an unusual AI component. The malware reportedly uses xAI's Grok model to help maintain persistence on infected machines, with Grok choosing from a set of predefined actions rather than generating novel commands.

The report also highlights AI API draining as a key element of the campaign. This suggests the attackers are abusing AI services as part of their operation, though the excerpt provides few technical details beyond that framing.

Because this is based on a single source, the full scope of the botnet's capabilities and the extent of the API abuse are not independently confirmed.