HomeSecurityCopilot and Grok are used as Malware C2 Proxies

Copilot and Grok are used as Malware C2 Proxies

Cybersecurity researchers have revealed that artificial intelligence (AI) assistants that support web browsing or URL retrieval capabilities, such as Copilot and Grok, can be turned into discreet command and control (C2) intermediaries, a technique that could allow attackers to integrate into legitimate business communications and evade detection.

See also: xAI accused of destroying evidence in antitrust case

Copilot and Grok

The attack method, demonstrated against Microsoft Copilot and xAI Grok, was characterized as  AI as a C2 proxy by Check Point. It uses “anonymous web access combined with browsing and summary prompts.” The same mechanism can also enable AI-powered malware functionality, including creating recognition workflows, creating scenarios for attacker actions, and dynamically deciding “what to do next” during an intrusion.

This development marks another significant advancement in how malicious actors could exploit AI systems, not only to scale or accelerate various phases of the cyberattack cycle, but also to use APIs to dynamically generate code at runtime that can adapt its behavior based on information gathered from the compromised computer and evade detection.

AI tools already act as a force multiplier for adversaries, allowing them to outsource key steps in their campaigns, whether it’s conducting reconnaissance, scanning for vulnerabilities, crafting convincing phishing emails, creating synthetic identities, debugging code, or deploying malware. However, AI as a C2 broker goes a step further.

Essentially, it uses the web browsing and URL retrieval capabilities of Grok and Microsoft Copilot to retrieve URLs controlled by attackers and return responses via their web interfaces, turning them into a two-way communication channel to accept commands issued by the operator and funnel victim data. Importantly, all of this works without requiring an API key or registered account, rendering traditional approaches such as key revocation or account suspension ineffective.

See also: French prosecutors raid X offices over Grok

Copilot and Grok are used as Malware C2 Proxies

This approach is similar to attack campaigns that have weaponized trusted services to distribute malware and C2, also known as living-off-trusted-sites (LOTS).

For this to happen, a key prerequisite is that the malicious actor must have already compromised a machine in some other way and installed malware, which then uses Copilot or Grok as a C2 channel with specially crafted prompts that cause the AI ​​agent to communicate with the infrastructure controlled by the attacker and pass the response containing the command to be executed on the computer back to the malware.

Check Point noted that an attacker could go beyond creating commands to use the AI ​​agent to plan an evasion strategy and determine the next course of action by conveying details about the system and verifying whether it is worth exploiting.

The revelation comes just weeks after Palo Alto Networks Unit 42 demonstrated a new attack technique where a seemingly innocent website can be transformed into a phishing site using client-side API calls to trusted large language model (LLM) services to dynamically generate malicious JavaScript in real time.

See also: Ireland investigates X over Grok's "sexual images"

Copilot and Grok are used as Malware C2 Proxies

The method is similar to Last Mile Reassembly (LMR) attacks , which involve secretly transporting malware over the network via unmonitored channels such as WebRTC and WebSocket and assembling it directly in the victim's browser, effectively bypassing security checks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS