At a Glance
| Actor / group | Unnamed financially motivated actor; assessed as a likely single operator |
| Activity type | Initial-access operation, RMM abuse, credential and crypto theft |
| Targets / victims | Windows hosts; console listed 324 hosts, 69 reporting online |
| Scale | 324 listed hosts across one management console |
| Attribution status | No named actor; no public law-enforcement action reported |
| Source | ReliaQuest Threat Research |
TL;DR
ReliaQuest found a new toolkit called Gryxa that a financially motivated actor built largely with an AI coding agent. The Gryxa toolkit turns legitimate remote software into hidden access and steals crypto credentials. Most strikingly, it watches how defenders try to remove it.
What Happened
ReliaQuest identified the toolkit through the actor’s own public code repository, where it is named “Gryxa.” The kit abuses legitimate remote monitoring and management (RMM) software for covert access. It then steals credentials saved in Chromium-based browsers.
Delivery was likely phishing. Researchers observed a 19MB self-extracting file with an invoice-themed name. The installer then pulls its parts over HTTPS from the actor’s server and a public code host.
The AI-built malware spreads files across four hidden folders. It builds heavy persistence on top: at least seven scheduled tasks, a permanent WMI event subscription, and an off-path copy of its files. Delete one piece, and the others rebuild it within a minute.
Who Is Behind It
ReliaQuest has not named a specific actor or group. Analysts assess with high confidence that AI helped build the operation. The evidence is direct: a commercial AI coding agent appears as co-author on most commits in the repository.
The report calls this a first. It states this is “the first case we’ve observed where AI has helped build the entire operation, from the toolkit to the console the actor runs it from.”
The actor apparently framed the work as authorized lab testing to get past the AI model’s safeguards. Two scripts carry a false comment claiming “lab/competition scope only.” ReliaQuest notes this framing “costs an actor nothing.”
Impact and Scale
The actor manages victims through a web console. At analysis time, it listed 324 hosts, with 69 reporting online. ReliaQuest cautions that not every listed host is a confirmed victim.
The credential module checks stolen logins against about 40 cryptocurrency and fintech domains. It also flags around 69 wallet extensions for manual theft later. Stolen data leaves the host through Telegram bots that all report to one personal account.
Two behaviors make the AI-built malware unusual. First, cutting the actor’s connection triggers a fight-back routine. After repeated failures to reach its relay, Gryxa disables Microsoft Defender and tries to uninstall endpoint protection within roughly 10 minutes. Second, and rarer, a surviving component collects Windows logs after defenders remove the visible implant. It uploads them so the attacker effectively sees the remediation.
How to Stay Protected
Containment order matters here. ReliaQuest advises blocking the actor’s infrastructure first, then removing every persistence mechanism in one pass. Cutting the remote-access service on its own can trigger the endpoint-protection attack.
Treat any browser credential on an affected host as exposed, and rotate it. Turn on Uninstall Protection for your endpoint agent, which blocks the final removal stage. Do not drop your own remote-access tool onto a live Gryxa host, since the implant may uninstall it.
Because the toolkit updates itself, file hashes go stale fast. ReliaQuest recommends behavior-based detection over chasing individual samples. The bigger lesson is that one person now builds at a scale that once implied a team. Defenders should plan for more actors, not only more advanced ones.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!