Cloud Security·
Hyperautomation·
Zero Trust · SASE·
NextGen MSSP for Cloud Security·
Cloud Platforms·
Managed Services·
Data & AI Security·
Identity Protection·
Security Automation·
Threat Intelligence·
Cloud Security·
Hyperautomation·
Zero Trust · SASE·
NextGen MSSP for Cloud Security·
Cloud Platforms·
Managed Services·
Data & AI Security·
Identity Protection·
Security Automation·
Threat Intelligence·
Data & AI 2 min read19 February 2026

AI as C2: Copilot and Grok Abused as Covert Attack Channels

New research shows AI assistants like Copilot and Grok abused as covert C2 channels. Learn how this attack hides in legitimate traffic and why to monitor it.

Y

Yossi Pinhasov

YouCC Technologies

AI as C2: When Copilot and Grok Become Attack Channels

New research reveals a clever and concerning technique that turns AI assistants such as Copilot and Grok into proxies for command-and-control (C2) communication. The takeaway for defenders is direct: AI is no longer just a productivity tool — it is becoming a transparent attack vector that security teams need to start monitoring.

How it works

The technique abuses the browsing capabilities built into AI assistants. Malware uses the AI's ability to fetch and process web content to pull down commands and to exfiltrate data, routing its C2 traffic through the assistant rather than connecting to a malicious server directly.

Why it matters

The approach is dangerous precisely because it blends in:

  • The traffic looks completely legitimate. It is HTTPS to trusted destinations, letting attackers disappear into normal organizational noise.
  • No API key or registered account is required, which makes standard blocklists and account-based controls ineffective.
  • Detection assumptions break down. Security tooling that trusts traffic to well-known AI domains gives this channel a free pass.

This is a shift in how AI fits the threat model. The assistant is not the target — it is the carrier. Traffic to a reputable AI service is exactly the kind of activity most environments do not scrutinize, which is what makes it an effective covert channel.

What to do

Start treating AI assistant traffic as something to monitor, not automatically trust. Build visibility into how AI tools are used and where they reach out, and watch for anomalous patterns even when the destination is reputable. For the full technical details, read the research write-up at The Hacker News.


Shared from the CSC - Cloud Security Community community, by Yossi Pinhasov.

Want more like this? Join the CSC - Cloud Security Community → https://youcc.co.il/community