Gryxa: AI-built Windows toolkit watches defender cleanup and fights back
ReliaQuest Threat Research describes Gryxa, a financially motivated Windows toolkit ReliaQuest assesses was substantially built with a commercial AI coding agent (AI co-author metadata on most commits in the actor's public repo). Delivery is likely an invoice-themed 19 MB SFX (invoice_<10 digits>.exe). After the visible RMM implant is removed, a surviving component collects Windows logs and host artefacts and uploads them so the operator sees the remediation. If the actor's relay is unreachable for two consecutive five-minute checks, Gryxa disables Defender and listed EDR; at three failures it attempts a silent uninstall. ReliaQuest's analysis of the actor console listed 324 hosts (69 reporting online at the time of writing); not every listed host is a confirmed victim. Credential theft targets Chromium saved logins (including App-Bound Encryption bypass paths in code) and flags wallet extensions. IoCs (defanged): wirbe[.]com, seczio[.]com, gryxa[.]com, sevrz[.]com and related hosts in ReliaQuest's table. Cyber Security News 31 August. Do not invent CVSS.
- Product
- Windows hosts (abused RMM + custom persistence)
- Versions
- n/a (malware toolkit)
- Exploited in Australia?
- unknown
- Patch to
- Block actor infra first, then remove RMM + seven scheduled tasks + WMI subscription + WinRTCS/WER/Diagnosis folders in one pass (ReliaQuest order)
Primary: ReliaQuest (Gryxa threat spotlight) ยท Vendor: Cyber Security News (31 Aug; secondary)
