Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember.com

Always First. Fast SOC News.

Threat Intel · SAN JOSE

Talos Documents CLOSEDQUORUM, Windows Implant That Lets AI Models Vote on C2 Moves

By Priya Shah, Threat Intel, Singapore

SAN JOSE - Cisco Talos researchers have documented CLOSEDQUORUM, which they describe as the first publicly reported Windows implant in their knowledge that uses a panel of commercial large language models as tactical command and control after deployment. The finding appears in a Talos blog by Ryan Fetterman dated Tuesday, September 22, 2026, and was uncovered with CAIRN, Talos' new open-source toolkit for tracking AI-integrated malware. Talos has not confirmed in-the-wild deployment.

According to the analysis, CLOSEDQUORUM queries up to four LLM providers in sequence (DeepSeek, Qwen, Mistral, and Google Gemini), tallies their verdicts, and selects the next action by plurality vote. Allowed decisions are constrained to steal, inject, persist, and move, though the move action has no handler in the public distribution build. The implant's intent is credential and crypto-wallet theft, including LSASS memory, Chrome, Edge, and Firefox saved credentials, and MetaMask, Exodus, and Ethereum wallet material. Stolen data is AES-256-GCM encrypted with a key derived from the date and sent through a Discord webhook. There is no dedicated attacker C2 server for dynamic tasking.

Talos stresses that the public distribution build is inert: placeholder API keys and a dummy webhook prevent end-to-end execution. Development builds show compile-time injection of operator credentials. Binary artifacts were used to link the developer to carding-forum posts dating to 2025. Defenders should correlate behaviors rather than chase a single IOC: an unexpected Windows executable contacting multiple AI provider APIs plus Discord, alongside LSASS access, injection, or persistence, often on randomized 5 to 15 minute intervals.

For SOC teams, CLOSEDQUORUM is an early reference case for effort displacement, where a bounded post-compromise phase runs without live human tasking. It is not evidence of mass active exploitation or a counted victim set. Detection engineering should prioritize the correlated chain over domain blocklists alone, because legitimate apps may contact the same AI APIs or Discord in isolation.

Source: https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/

Priya Shah is a Threat Intel correspondent covering detection engineering and adversary tradecraft for SOCtember, based in Singapore.

Back to Threat Intel