Check Point Research reported a technique dubbed “AI as a C2 proxy” in which attackers repurpose mainstream AI assistants—specifically xAI Grok (grok.com) and Microsoft Copilot (copilot.microsoft.com)—as covert relays for malware command-and-control traffic. The approach abuses the assistants’ web-browsing/URL-fetching features so malware can instruct the AI web interface to retrieve attacker-controlled URLs and return structured output that the malware parses into commands, creating a bidirectional C2 channel that blends into enterprise environments where AI service domains may be routinely allowed and less scrutinized.
In the proof-of-concept flow, malware collects host reconnaissance (e.g., username, domain, installed software, running processes), appends it to an attacker-controlled HTTPS URL (disguised as benign content), and prompts the AI assistant to summarize the page; the AI fetches the page and returns embedded instructions that the malware executes. The reporting notes this can work via public web interfaces and may not require an API key or registered account, reducing the effectiveness of account suspension or key revocation as mitigations. One demonstrated implementation used Windows 11 WebView2 to embed Grok/Copilot in a native application context (and could potentially ship WebView2 with the malware), and researchers stated they disclosed the findings to Microsoft and xAI.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Security news outlets reported Check Point's findings, warning that attackers could use Grok and Copilot as covert command-and-control intermediaries to evade some enterprise defenses. The coverage highlighted the use of WebView2, attacker-controlled URLs, and AI-generated responses to pass commands and exfiltrate data.
After developing the proof of concept, Check Point reported the issue to Microsoft and xAI as part of a responsible disclosure process. The researchers also recommended stronger monitoring, authentication, and visibility around AI URL-fetch features and AI-domain egress traffic.
Check Point Research identified and documented an "AI as a C2 proxy" technique in which malware abuses xAI Grok and Microsoft Copilot web interfaces to relay command-and-control traffic through trusted AI service domains. The proof of concept used URL-fetching and web-browsing features to create a bidirectional channel without requiring an API key or user account.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.