• News/
  • https://www.bleepingcomputer.com/news/security/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/

Threat actors abuse X’s Grok AI to spread malicious links

BleepingComputer
·
Bill Toulas
·
Published Sep 3, 2025
·
Updated

Threat actors are using Grok, X's built-in AI assistant, to bypass link posting restrictions that the platform introduced to reduce malicious advertising. As discovered by Guardio Labs' researcher Nati Tal, mavertisers often run sketchy video ads containing adult content baits and avoid including a link to the main body to avoid being blocked by X. Instead, they hide it in the small "From:" metadata field under the video card, which apparently isn't scanned by the social media platform for malicious links. Next, (likely) the same actors ask Grok via a reply to the ad something about the post, like "where is this video from," or "what is the link to this video." Grok parses the hidden "From:" field and replies with the full malicious link in clickable format, allowing users to click it and go straight to the malicious site. Because Grok is automatically a trusted system account on the X platform, its post boosts the link's credibility, reach, SEO, and reputation, increasing the likelihood that it will be broadcast to a large number of users. The researcher has found that many of these links funnel through shady ad networks, leading to scams such as fake CAPTCHA tests, information-stealing malware, and other malicious payloads. Instead of being blocked by X, they are instead promoted to users on the platform via malicious ads that receive a further boost from Grok. Tal calls the technique of exploiting this loophole "Grokking," and notes that it's very effective, in some cases...

Read full article

Affected Software

1 affected component
X Grok
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how threat actors are exploiting X's Grok AI to distribute malicious links despite the platform's attempts to restrict such activities.

2

What security implications are discussed?

The security implications involve the potential for increased cybersecurity threats and the challenges in preventing malicious content from being shared on social media platforms.

3

What products or software are affected?

The main product affected is X's Grok AI, which is being misused to propagate harmful links.

4

How are threat actors bypassing restrictions on X's platform?

Threat actors are using Grok AI to evade the link posting restrictions implemented by X to combat malicious advertising.

5

Who identified the abuse of Grok AI by threat actors?

The abuse of Grok AI was discovered by researcher Nati Tal from Guardio Labs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203