CLOSEDQUORUM: The Malware That Asks Four AI Models What to Steal Next

CLOSEDQUORUM: The Malware That Asks Four AI Models What to Steal Next

I usually trust malware stories more when a named lab walks me through the binary, not when a headline screams “AI takes over.”

On 22 September 2026, Cisco Talos’ Ryan Fetterman published CLOSEDQUORUM: a Windows implant that, after it lands, asks a small panel of commercial AI models what to do next — then runs the winning choice (Cisco Talos). The Hacker News covered it the next day (23 Sep 2026).

Talos has not confirmed in-the-wild victims. The public sample does not work as shipped. Still, the design is worth a defender’s time: it shows how attackers can hand a bounded attack phase to models you already allow on the network.

What CLOSEDQUORUM actually is

CLOSEDQUORUM is a 16.4 MB, 64-bit Windows executable written in Go, found through Talos’ CAIRN project — an open-source toolkit for hunting malware that talks to AI services. Talos released CAIRN the same day as this write-up (Cisco Talos).

To Talos’ knowledge, it is the first publicly documented Windows implant that treats a panel of commercial large language models as the tactical command-and-control (C2) layer. After deployment it does not need ongoing human commands or a classic attacker-run C2 server for those next-step choices. The loop is: gather host context → query models → tally votes → execute (Cisco Talos; The Hacker News).

Artifacts in the builds linked the developer to criminal-forum posts about carding dating back to 2025. Talos’ static analysis note in the published YARA metadata is dated 17 June 2026, so the family is at least a few months old by the September disclosure (Cisco Talos; The Hacker News).

How it gets onto a machine first is not described in these two sources. Don’t invent a delivery story from silence.

How the four-model vote works

The “quorum” is up to four providers, queried in sequence: DeepSeek, Qwen, Mistral, and Google Gemini (Cisco Talos).

On each cycle the implant folds basic host facts into a prompt — hostname, OS/architecture, CPU count, Windows version, admin status — plus a refreshed target-process field. The system prompt Talos extracted from the binary is blunt: “You are an advanced malware strategist. Provide ONLY executable decisions.” Models must answer in a typed JSON schema. Unusable answers get discarded (Cisco Talos; The Hacker News).

The four allowed moves

Decision What Talos says it does
steal Runs three theft paths together: LSASS memory dump, browser passwords (Chrome, Edge, Firefox), crypto wallet data (MetaMask, Exodus, Ethereum paths)
inject Generates shellcode, then Early Bird APC injection by default, or process hollowing if the model asks for process_hollow
persist Registry Run key (WindowsUpdate-themed), a scheduled task, and a WMI subscription that fires about every 60 seconds
move Named in the schema, but no handler in the public distribution build — picking it does nothing

Votes use plurality: the decision with the most valid responses wins. Ties follow a fixed order — DeepSeek first, then Qwen, then Mistral, then Gemini. If every model fails, the fallback is a non-action string (consensus) that makes the loop sleep and retry rather than invent a default attack (Cisco Talos; The Hacker News).

Talos also notes randomized 5–15 minute polling after a roughly five-minute initial delay — useful if you are writing detection windows (Cisco Talos).

Why attackers like this shape (without overselling it)

Classic C2 means the attacker rents or hosts a domain, IP, and listener that defenders can block and attribute. CLOSEDQUORUM instead calls commercial LLM endpoints that thousands of legit apps already use (Cisco Talos).

Talos frames this as effort displacement: a phase of the intrusion can keep going when no human operator is watching. The operator still gets telemetry — winning decision, model reasoning, and stolen material — through a Discord webhook. Stolen files are staged under C:\Windows\Temp\, encrypted with AES-256-GCM (key derived from the current date), Base64-encoded, and split into 1,900-byte chunks posted about one per second (Cisco Talos; The Hacker News).

The public sample is a dead template

Development builds show API keys and the Discord webhook injected at compile time. The public distribution binary initializes those to placeholder values (dummy_api_key, dummy_webhook_url), so Talos did not observe a full end-to-end run of the live architecture (Cisco Talos; The Hacker News).

Talos’ assessment of the business model: customized binaries for operators (credentials-as-a-service style), with the buyer handling delivery. That is an assessment from build evidence, not a confirmed victim list.

Autonomy also adds failure modes Talos calls out plainly: provider refusals, rate limits, malformed JSON, predictable tie-breaks, a tiny action menu, and dependence on APIs the attacker does not own (Cisco Talos).

What defenders should actually look for

Talos’ clearest advice: hunt behavior, don’t only block AI vendor domains. Plenty of legit software talks to DeepSeek, Mistral, Gemini, Discord, or OpenRouter (another service named in Talos’ defensive notes). Far fewer should hit several of those while also touching LSASS, injecting into suspended processes, or creating WMI persistence (Cisco Talos, The Hacker News).

Correlation checklist (from Talos / THN)

No single signal names the family alone. The combination is what stands out:

  1. Unexpected Windows process making AI-provider API traffic
  2. Similar requests to multiple model providers in a short window
  3. Structured prompts with host context or offensive wording (often only visible with TLS inspection or provider-side logs)
  4. Process injection, LSASS access, or new persistence on the same host/process
  5. Discord webhook traffic from that same process or host
  6. Activity repeating on a 5–15 minute random cadence

Host leftovers Talos/THN flag if persistence ran:

  • Registry Run value named like WindowsUpdate under the current user
  • PowerShell script path consistent with C:\Windows\Temp\wmi.ps1
  • Permanent WMI subscription with Windows Update-themed names (~60-second trigger)

Detection packages Talos published

  • YARA rule CLOSEDQUORUM_LLM_Autonomous_Implant (CAIRN/Talos) — partly aimed at VirusTotal metadata; binary strings (system prompt, DWARF symbols) need a file scan (Cisco Talos)
  • Snort rule 1:66984 for the malware’s prompts to AI services — THN notes it likely needs TLS inspection to fire (The Hacker News)
  • Six SHA-256 hashes for the developer’s ~week build chain (see Sources / IOCs below)

THN checked CAIRN’s shipped rule file on 23 September 2026 and did not find a CLOSEDQUORUM rule bundled yet — operators would add Talos’ rule themselves (The Hacker News).

My short defender checklist

If you run Windows endpoints or a SOC today:

  • Correlate, don’t just block: multi-provider LLM traffic + LSASS / injection / WMI / Discord from one odd process.
  • Import Talos’ YARA and review Snort 1:66984; plan for TLS inspection if you want prompt-content matches.
  • Hash-hunt the six published SHA-256s; watch for Go binaries with baked-in provider key symbols (deepseekAPIKey, geminiAPIKey style strings Talos called out).
  • Alert on current-user Run keys / WMI consumers themed like WindowsUpdate that you did not deploy.
  • Stage-path watch: sudden credential/wallet files under C:\Windows\Temp\ plus Discord webhook POSTs.
  • Keep a calm inventory of which internal tools are allowed to call commercial LLM APIs — so “unexpected Windows executable → AI API” is measurable.
  • Remember the public sample is inert; treat this as an architecture preview with real techniques, not a confirmed mass outbreak.

I’m not going to pretend one blog post makes your network “AI-proof.” What Talos handed defenders is clearer: a named sample, a voting loop you can describe in one sentence, and a short list of behaviors that already look weird together. That is enough to write detections this week.


Sources (named)

  1. Cisco Talos — Ryan Fetterman, 22 Sep 2026: The Closed Quorum: Inside the first reported autonomous AI C2 implant (primary technical analysis, CAIRN context, voting/tie-break, capabilities, defensive notes, YARA, hashes).
  2. https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/

  1. The Hacker News — Swati Khandelwal, 23 Sep 2026: This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move (secondary summary; Snort 1:66984; CAIRN rule-file check; host leftovers).
  2. https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html

Research capped at these two named sources for claims in this draft (plus discovery searches that led to them). No dollar figures appeared in either source for this story; none invented.

IOCs (from Talos, as published)

SHA-256 (developer build chain, ~7 days):

  • 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
  • c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
  • c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
  • f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c
  • 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
  • eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5
Spread the words..

Leave a Reply

Your email address will not be published. Required fields are marked *