Cybercriminals have found a cunning new way to hide their attacks by hijacking popular AI tools like Grok and Microsoft Copilot.
Researchers at Check Point Research (CPR) revealed this technique, which turns everyday AI web services into secret tunnels for command-and-control (C2) communication.
Attackers exploit the AI’s web browsing and URL-fetching features to route malicious traffic through trusted enterprise channels.
This makes it tough for security teams to spot the threat, as the traffic looks like normal user queries to legitimate domains.
In their report, CPR demonstrated how malware on a victim’s machine uses an embedded browser, such as WebView2 on Windows, to quietly interact with AI interfaces.
No API keys or accounts are needed
Just public web access. The malware sends a prompt telling the AI to visit an attacker-controlled URL.
The AI fetches the data, which hides commands or payloads in HTML, and sends it back. For proof, researchers set up a fake site about Siamese cats as a C2 server.
Both Grok and Copilot retrieved hidden instructions without raising flags. Traffic to AI domains slips past firewalls and monitors since it mimics benign activity. This enables data exfiltration and remote command execution without linking to suspicious IPs.
Abusing AI as Proxies and Future Malware Brains
The “AI as a proxy” method creates a bidirectional channel free from traditional C2 red flags. CPR’s findings point to a bigger shift: AI-driven (AID) malware. Beyond chatting, these threats could use AI as smart decision engines.

Malware might scan the victim’s setup system details, user roles, network info, and ask the AI to analyze it.
The AI could spot if it’s a real workstation or a security sandbox, keeping the threat dormant until a high-value target confirms.
This adapts malware from rigid code to dynamic behavior, automating attacks like AIOps-C&C campaigns.
As AI embeds deeper into workplaces, distinguishing legit use from malice gets harder. Defenders must watch for odd AI prompts, unusual web fetches, and environment queries.
| Vulnerability/Technique | CVSS Score | Description | Affected Platforms |
|---|---|---|---|
| AI Proxy C2 Abuse | N/A (Technique) | Malware uses AI web interfaces for hidden C2 via URL fetching | Grok, Copilot, WebView2 (Windows) |
Key IOCs
| Indicator Type | Value | Description |
|---|---|---|
| Domain (Fake C2) | siamesecats.example.com | Attacker-controlled site for command retrieval (PoC) |
| SHA-256 Hash | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | Sample malware implant (research PoC) |
| User-Agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 | Embedded browser in AI queries |
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google