Advisory
Published 2026-08-31
Verified 2026-09-19

Gryxa: AI-built Windows toolkit watches defender cleanup and fights back

ReliaQuest Threat Research describes Gryxa, a financially motivated Windows toolkit ReliaQuest assesses was substantially built with a commercial AI coding agent (AI co-author metadata on most commits in the actor's public repo). Delivery is likely an invoice-themed 19 MB SFX (invoice_<10 digits>.exe). After the visible RMM implant is removed, a surviving component collects Windows logs and host artefacts and uploads them so the operator sees the remediation. If the actor's relay is unreachable for two consecutive five-minute checks, Gryxa disables Defender and listed EDR; at three failures it attempts a silent uninstall. ReliaQuest's analysis of the actor console listed 324 hosts (69 reporting online at the time of writing); not every listed host is a confirmed victim. Credential theft targets Chromium saved logins (including App-Bound Encryption bypass paths in code) and flags wallet extensions. IoCs (defanged): wirbe[.]com, seczio[.]com, gryxa[.]com, sevrz[.]com and related hosts in ReliaQuest's table. Cyber Security News 31 August. Do not invent CVSS.

Product
Windows hosts (abused RMM + custom persistence)
Versions
n/a (malware toolkit)
Exploited in Australia?
unknown
Patch to
Block actor infra first, then remove RMM + seven scheduled tasks + WMI subscription + WinRTCS/WER/Diagnosis folders in one pass (ReliaQuest order)

Primary: ReliaQuest (Gryxa threat spotlight) ยท Vendor: Cyber Security News (31 Aug; secondary)

ai identity