Gryxa Toolkit Uses AI-Assisted Development and Monitors Its Removal

· Original article ↗

Summary

ReliaQuest details Gryxa, a financially motivated toolkit linked to a console listing 324 hosts. It uses RMM access, layered persistence, credential theft and endpoint-protection tampering, while collecting logs after defenders remove its visible implant.

Key points

  • ReliaQuest assesses that a commercial AI coding agent helped develop substantial parts of Gryxa, based partly on co-author metadata in the actor’s public repository.
  • The toolkit likely arrives through phishing and abuses legitimate remote monitoring and management software for covert access; its console listed 324 hosts, 69 reporting online.
  • Gryxa steals credentials from accessible Chromium browser profiles and identifies cryptocurrency wallet extensions; researchers confirmed the relevant code paths but did not verify every claimed decryption route.
  • It maintains access with at least seven scheduled tasks, a permanent Windows event subscription and a backup copy of its files, enabling components to restore one another.
  • After two failed checks for its relay, Gryxa disables Microsoft Defender and targets other endpoint protection; after a third, it attempts to uninstall the security agent.
  • A surviving component collected Windows logs and host artifacts after defenders removed the visible RMM implant, then uploaded them to actor-controlled infrastructure. The toolkit returned within seven days in the observed investigation.
  • ReliaQuest recommends blocking the actor’s infrastructure before removing the RMM service, all persistence mechanisms and working files together; it also advises treating accessible browser credentials as exposed.

Article Details

Attack Vectors
  • An invoice-themed self-extracting executable was observed; ReliaQuest considers phishing a likely delivery route but did not observe delivery.
  • The installer retrieves components over HTTPS from actor infrastructure and a public code-hosting service.
  • The toolkit uses an RMM client for remote access and restores access through scheduled tasks, a permanent WMI event subscription, and an off-path file copy.
  • A credential module attempts to decrypt passwords saved in Chromium-based browsers. Code review identified three routes intended to work against Chrome App-Bound Encryption, but ReliaQuest did not verify successful decryption against every listed browser version.
  • A component that survived removal of the visible RMM implant collected Windows logs and host artifacts and uploaded them to actor-controlled infrastructure.
Defensive Notes
  • Block actor infrastructure at the network edge before removing the RMM service, then remove all seven scheduled tasks, the WMI event subscription, and every working folder in one pass; otherwise the toolkit can restore itself.
  • Enable endpoint-agent Uninstall Protection where available. Loss of the actor relay can trigger attempts to disable endpoint protection and silently uninstall an agent within roughly 10–13 minutes.
  • Check Defender exclusions and Group Policy overrides directly: the toolkit can re-enable Defender after connectivity returns without reverting its exclusions.
  • Do not deploy a remediation RMM tool to a live Gryxa host; the toolkit may uninstall an installation whose fingerprint does not match its own.
  • If the credential module ran, treat credentials in accessible browser profiles as exposed, rotate them, and investigate what the accounts could access. Account for identities and devices outside centralized directory coverage.
  • Prioritize behavior-based detection over file hashes because the toolkit can update its components across hosts.

Indicators of compromise

TypeIndicatorContext
DOMAINgryxa[.]comActor-controlled legacy infrastructure still in use.
DOMAINseczio[.]comActor-controlled legacy infrastructure still in use.
DOMAINsevrz[.]comActor-controlled legacy infrastructure still in use.
DOMAINwirbe[.]comActor-controlled domain.
HOSTNAMEcdn[.]wirbe[.]comActor-controlled hostname.
HOSTNAMEdebian[.]seczio[.]comActor-controlled legacy infrastructure still in use.
HOSTNAMEmesh[.]wirbe[.]comActor-controlled hostname.
HOSTNAMEui[.]gryxa[.]comActor-controlled legacy infrastructure still in use.
HOSTNAMEui[.]sevrz[.]comActor-controlled legacy infrastructure still in use.
HOSTNAMEupdate[.]gryxa[.]comActor-controlled legacy infrastructure still in use.
HOSTNAMEupdate[.]sevrz[.]comActor-controlled legacy infrastructure still in use.
HOSTNAMEver[.]wirbe[.]comActor-controlled hostname.
HOSTNAMEworld[.]wirbe[.]comActor-controlled hostname.
IPV4144[.]172[.]107[.]56IP address of actor-controlled infrastructure.
IPV4209[.]145[.]55[.]189IP address of actor-controlled infrastructure.

MITRE ATT&CK

Malware

Vendors

Products

Related Articles