Skip to content

CLOSEDQUORUM

CLOSEDQUORUM is a Go-based, 64-bit Windows information-stealing implant that delegates bounded post-compromise tactical decisions to commercial large language models.

CLOSEDQUORUM

Family profile

CLOSEDQUORUM is a Go-based, 64-bit Windows information-stealing implant that delegates bounded post-compromise tactical decisions to commercial large language models. It sequentially queries up to four providers—DeepSeek, Qwen, Mistral, and Google Gemini—with host information, including Windows version, processor characteristics, administrative status, and target-process context. Structured model responses select among predefined theft, injection, persistence, and movement actions. The implant chooses the action receiving the most valid votes, resolves ties in a fixed provider order, and waits before retrying if no usable response is returned. This architecture replaces continuous operator tasking with model-assisted action selection rather than unrestricted AI-generated attack execution.

Its theft functionality dumps LSASS memory, collects saved credentials from Chrome, Microsoft Edge, and Firefox, and extracts MetaMask, Exodus, and Ethereum wallet data. Collected material is encrypted with AES-256-GCM using a date-derived key, Base64-encoded, segmented, and transmitted through a Discord webhook. The same channel carries model decisions and operational telemetry. Injection functionality supports process hollowing and Early Bird APC injection. Persistence mechanisms include logon autostart, scheduled tasks, and permanent WMI event subscriptions. Defense-evasion features include ETW suppression, delayed execution, and randomized activity intervals. Although the decision schema includes lateral movement, the analyzed distribution build has no implementation for that action.

Cisco Talos identified CLOSEDQUORUM through its CAIRN research project. The publicly examined build contains placeholder AI-service credentials and a dummy Discord webhook, making it nonfunctional as distributed; successful end-to-end execution and deployment in real-world attacks have not been confirmed. Its initial delivery mechanism, victim industries, and attribution to a named threat actor are not established. Dependence on external AI services introduces operational constraints, including provider refusals, rate limits, unavailable services, and malformed responses.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

MITRE ATT&CK

CLOSEDQUORUM in ATT&CK

37 distinct techniques

Reporting

Research mentioning CLOSEDQUORUM

Sep 22
Help Net Security

Researchers uncover malware that uses AI to choose its next move - Help Net Security

Cisco Talos reported CLOSEDQUORUM, a 64-bit Go-based Windows implant that delegates tactical command-and-control decisions to a plurality vote among commercial LLMs including DeepSeek, Qwen, Mistral, and Google Gemini. Rather than depending on a conventional attacker-controlled C2 server or continuous operator input, the malware can use the models' structured responses to select actions such as credential theft, persistence, and process injection—including techniques that can execute malicious code within legitimate processes and evade process-based defenses. The observed sample was an inert template containing placeholder API keys and a dummy Discord webhook, so Talos could not validate end-to-end execution or deployment in the wild. Build artifacts suggest customized variants may embed provider credentials and Discord endpoints for exfiltration; the implant targets LSASS memory, browser-stored credentials, and cryptocurrency wallets, encrypting and Base64-encoding data before segmented Discord delivery. Defenders should correlate anomalous traffic to multiple AI-provider APIs with LSASS access, process-injection behavior, persistence changes, and Discord communications.

Sep 22
Malware News

Introducing CAIRN: Frontier tracking for AI-integrated malware - Malware News - Malware Analysis, News and Indicators

Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network), an open-source toolkit for identifying, classifying, and tracking malware that incorporates AI or large-language-model capabilities. Rather than requiring analysts to download or execute suspected malware, CAIRN hunts for metadata-based cognitive artifacts, including embedded prompts, LLM-provider endpoints, API-key prefixes, orchestration logic, local-LLM runtime references, and AI-focused evasion strings. CAIRN combines acquisition filters, relationship graphs, a three-tier YARA classification model, and semantic clustering to link candidate samples with related infrastructure and campaigns. Talos reported that hunting of malware under active development since July 2025 showed a rapid shift from optional LLM features toward autonomous multi-model orchestration, alongside AI-specific evasion techniques appearing across independently developed malware. The company cautioned that AI-related artifacts can generate significant false positives and require reverse-engineering validation before attribution or definitive conclusions.

Sep 22
Malware News

The Closed Quorum: Inside the first reported autonomous AI C2 implant - Malware News - Malware Analysis, News and Indicators

Sep 22
Talosintelligence Other

The Closed Quorum: Inside the first reported autonomous AI C2 implant

Sep 22
Talosintelligence Other

Introducing CAIRN: Frontier tracking for AI-integrated malware

Sep 22
Wired Com Security

A New Tool Found Malware That’s Guided by an AI Hive Mind-No Humans in Sight | WIRED

Jul 23
Github Web

GitHub - Cisco-Talos/Cognitive-Artifact-Intelligence-Research-Network: Cognitive Artifact Intelligence Research Network · GitHub

Oct 1
Mitre Attack Website

Process Injection: Asynchronous Procedure Call, Sub-technique T1055.004 - Enterprise | MITRE ATT&CK®