Gryxa Toolkit Uses AI-Assisted Development and Monitors Its Removal

Summary
ReliaQuest details Gryxa, a financially motivated toolkit linked to a console listing 324 hosts. It uses RMM access, layered persistence, credential theft and endpoint-protection tampering, while collecting logs after defenders remove its visible implant.
Key points
- ReliaQuest assesses that a commercial AI coding agent helped develop substantial parts of Gryxa, based partly on co-author metadata in the actor’s public repository.
- The toolkit likely arrives through phishing and abuses legitimate remote monitoring and management software for covert access; its console listed 324 hosts, 69 reporting online.
- Gryxa steals credentials from accessible Chromium browser profiles and identifies cryptocurrency wallet extensions; researchers confirmed the relevant code paths but did not verify every claimed decryption route.
- It maintains access with at least seven scheduled tasks, a permanent Windows event subscription and a backup copy of its files, enabling components to restore one another.
- After two failed checks for its relay, Gryxa disables Microsoft Defender and targets other endpoint protection; after a third, it attempts to uninstall the security agent.
- A surviving component collected Windows logs and host artifacts after defenders removed the visible RMM implant, then uploaded them to actor-controlled infrastructure. The toolkit returned within seven days in the observed investigation.
- ReliaQuest recommends blocking the actor’s infrastructure before removing the RMM service, all persistence mechanisms and working files together; it also advises treating accessible browser credentials as exposed.
Article Details
- Attack Vectors
- An invoice-themed self-extracting executable was observed; ReliaQuest considers phishing a likely delivery route but did not observe delivery.
- The installer retrieves components over HTTPS from actor infrastructure and a public code-hosting service.
- The toolkit uses an RMM client for remote access and restores access through scheduled tasks, a permanent WMI event subscription, and an off-path file copy.
- A credential module attempts to decrypt passwords saved in Chromium-based browsers. Code review identified three routes intended to work against Chrome App-Bound Encryption, but ReliaQuest did not verify successful decryption against every listed browser version.
- A component that survived removal of the visible RMM implant collected Windows logs and host artifacts and uploaded them to actor-controlled infrastructure.
- Defensive Notes
- Block actor infrastructure at the network edge before removing the RMM service, then remove all seven scheduled tasks, the WMI event subscription, and every working folder in one pass; otherwise the toolkit can restore itself.
- Enable endpoint-agent Uninstall Protection where available. Loss of the actor relay can trigger attempts to disable endpoint protection and silently uninstall an agent within roughly 10–13 minutes.
- Check Defender exclusions and Group Policy overrides directly: the toolkit can re-enable Defender after connectivity returns without reverting its exclusions.
- Do not deploy a remediation RMM tool to a live Gryxa host; the toolkit may uninstall an installation whose fingerprint does not match its own.
- If the credential module ran, treat credentials in accessible browser profiles as exposed, rotate them, and investigate what the accounts could access. Account for identities and devices outside centralized directory coverage.
- Prioritize behavior-based detection over file hashes because the toolkit can update its components across hosts.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | gryxa[.]com | Actor-controlled legacy infrastructure still in use. |
| DOMAIN | seczio[.]com | Actor-controlled legacy infrastructure still in use. |
| DOMAIN | sevrz[.]com | Actor-controlled legacy infrastructure still in use. |
| DOMAIN | wirbe[.]com | Actor-controlled domain. |
| HOSTNAME | cdn[.]wirbe[.]com | Actor-controlled hostname. |
| HOSTNAME | debian[.]seczio[.]com | Actor-controlled legacy infrastructure still in use. |
| HOSTNAME | mesh[.]wirbe[.]com | Actor-controlled hostname. |
| HOSTNAME | ui[.]gryxa[.]com | Actor-controlled legacy infrastructure still in use. |
| HOSTNAME | ui[.]sevrz[.]com | Actor-controlled legacy infrastructure still in use. |
| HOSTNAME | update[.]gryxa[.]com | Actor-controlled legacy infrastructure still in use. |
| HOSTNAME | update[.]sevrz[.]com | Actor-controlled legacy infrastructure still in use. |
| HOSTNAME | ver[.]wirbe[.]com | Actor-controlled hostname. |
| HOSTNAME | world[.]wirbe[.]com | Actor-controlled hostname. |
| IPV4 | 144[.]172[.]107[.]56 | IP address of actor-controlled infrastructure. |
| IPV4 | 209[.]145[.]55[.]189 | IP address of actor-controlled infrastructure. |
MITRE ATT&CK
T1005 · Data from Local SystemAfter removal of the visible RMM implant, a surviving component collects local Windows logs, task and event-subscription details, and host artifacts.T1036 · MasqueradingKeeper directories and scheduled-task names are chosen to resemble legitimate Windows paths and Microsoft tasks.T1053.005 · Scheduled TaskGryxa uses at least seven scheduled tasks across two layers to run and restore its components.T1105 · Ingress Tool TransferThe installer downloads additional toolkit components over HTTPS, and the update mechanism retrieves changed components.T1546.003 · Windows Management Instrumentation Event SubscriptionA permanent WMI event subscription provides execution that survives reboots and scheduled-task deletion.T1555.003 · Credentials from Web BrowsersThe credential module attempts to decrypt saved Chromium-based browser logins and sends selected credentials to the actor.T1562.001 · Disable or Modify ToolsWhen its relay becomes unreachable, Gryxa attempts to disable Defender and other endpoint protection, then silently uninstall a security agent.T1564.001 · Hidden Files and DirectoriesThe toolkit marks its working folders hidden so they do not appear in a default file listing.T1567 · Exfiltration Over Web ServiceThe credential module sends stolen logins through Telegram bots rather than the toolkit's own C2 channel.
Malware
Vendors
GoogleEncryption protects those credentials by tying the encryption key to the browser itself—a control Google introduced in 2024 to stop other processes decrypting them. Other Chromium-based browsers vary in whatMicrosoftC:\ProgramData\Microsoft\Windows\WER\Temp\.wucache (keeper)ReliaQuestThis is external threat intelligence from the ReliaQuest Threat Research team. The findings describe threats, vulnerabilities, and attacker activity affecting third parties and the broader threat landscape—not
Products
Google ChromeApproximately one hour elapsed between the first repository reference to Chrome App-Bound Encryption (a feature that protects saved browser passwords) and a commit containing code intended to bypass it.GreyMatter Agentic AIGreyMatter Agentic AI: Correlates behaviors across an intrusion that look low confidence in isolation. An RMM client connecting to an unrecognized destination, a SYSTEM-level scheduled task created alongside a WMI eventGreyMatter AttackGreyMatter Attack: Safely test the behaviors in this report against your environment to confirm whether you detect SYSTEM-level scheduled task creation and WMI event subscription persistence. That surfaces visibilityGreyMatter TransitGreyMatter Transit: Provides visibility into network telemetry while it’s still in motion. Gryxa restores a deleted component within roughly a minute, so any time a detection spends waiting on log ingestion is time theMicrosoft DefenderAt two consecutive failures the toolkit disables Microsoft Defender and issues service stop and disable commands against EDR products from a hard-coded list. At three, it reads the uninstall string for the securityMicrosoft Windowsremove the visible remote monitoring and management (RMM) implant, a surviving Gryxa component collects Windows logs and host artifacts and uploads them to the threat actor, so the attacker effectively sees the