⌁AI·CYBER·BRIEF▌
AI Threats10 min read

CLOSEDQUORUM: malware that asks four AI models what to do next — and nobody has seen it used

Cisco Talos documented a Windows implant that replaces its command-and-control server with a vote among four commercial LLMs. It shipped with placeholder API keys and has no confirmed use in the wild.

On 22 September 2026, Cisco Talos published an analysis of CLOSEDQUORUM, a Windows implant that does not phone home to an attacker-controlled server. Instead it asks four commercial language models what to do next, tallies their answers, and executes whichever action wins the vote. Talos could not confirm that it has ever been deployed against a real target: the binary it analysed contained placeholder API keys and a placeholder Discord webhook, and one of its four capabilities is not actually implemented.

That last paragraph is the whole story, and it needs to stay attached to every retelling of it. What Talos found is not an attack. It is a piece of software that shows where attack tooling is heading, which is genuinely worth understanding — but it is a capability disclosure, not an incident, and the distance between those two things is the difference between useful threat intelligence and marketing.

The short version

Every piece of remote-access malware needs a way to receive instructions. Traditionally that means a command-and-control server: infrastructure the attacker owns, which has to stay online, which defenders can block, and which is the single best starting point for attribution and takedown. C2 is the most fragile and most incriminating part of an intrusion.

CLOSEDQUORUM removes it. After landing on a host, the implant gathers information about its environment, packages that into a structured prompt, and sends the same prompt to four separate model providers — DeepSeek, Qwen, Mistral and Google Gemini. Each is asked to pick the next action from a fixed menu of four: steal, inject, persist, or move. The implant counts the responses and does whatever the majority chose. If the vote ties, a hardcoded hierarchy decides, with DeepSeek getting priority.

From a defender's perspective the consequence is uncomfortable. There is no attacker-owned domain to blocklist, because the decision-making traffic goes to the same model APIs that the organisation's own developers and business units are calling all day.

Timeline

What we know

All technical detail below is Talos's, as reported in its analysis and in coverage carrying its comment.

The artefact. A 16.4 MB executable compiled from Go, targeting Windows.

The decision loop. Up to four commercial model providers are queried sequentially with the same structured prompt. Output is constrained to a JSON schema offering exactly four choices, which prevents the model from returning something the implant cannot act on. Majority vote wins; DeepSeek breaks ties.

What the four verbs do. Steal collects credentials from LSASS memory, from browser password stores including Chrome, Edge and Firefox, and from cryptocurrency wallets including MetaMask and Exodus. Inject runs shellcode using a delivery method the model recommends. Persist establishes survival across reboots. Move — lateral movement — exists in the code but is not functionally implemented.

Exfiltration. Stolen data is encrypted with AES-256-GCM and sent out through a Discord webhook rather than to dedicated attacker infrastructure.

Persistence and injection techniques. Talos reports registry-based persistence, scheduled tasks and WMI, plus process injection via asynchronous procedure calls and process hollowing. These are all long-established techniques.

No confirmed deployment. Talos states it could not confirm use in the wild. The analysed binary carried placeholder values — Talos describes placeholder API keys for the model providers and a placeholder Discord webhook URL. Per SC Media's reporting, Talos reads this as consistent with software built to be distributed to operators who would insert their own keys at compile time.

Talos's framing. Researcher Ryan Fetterman is quoted on the significance: "Effort displacement compounds the effects of speed and scale because the human-in-the-loop is no longer the bottleneck." Talos presents the finding as an early warning and an argument for studying this frontier now, not as evidence of an active campaign.

Technical analysis

The interesting engineering question is why anyone would build a four-model quorum. Consensus voting is expensive: four API calls instead of one, four sets of credentials to acquire and pay for, four providers who might change their terms. If the goal were simply "let a model choose the next step", one model would do. So what does the fourth vote buy?

Our assessment: the quorum is not there for intelligence. It is there for reliability against refusal. A model asked to select the next action in what is transparently an intrusion may decline, hedge, or return something unusable. One refusal in a single-model design stalls the implant. In a four-model majority vote, a refusal is simply outvoted — the operation continues on the strength of the providers that answered. The architecture converts each provider's safety behaviour from a hard stop into a minority opinion. Structuring the output as a four-option JSON schema serves the same end from a different direction: a constrained schema is much easier for a model to complete without recognising the request as a full attack plan than an open-ended "what should I do to this machine" would be.

That reading is consistent with the tie-break hierarchy too. Ordering the providers by preference is what you do when you have observed that they differ in how often they cooperate.

The detection problem is real and is not about AI. Historically, C2 detection has leaned on the fact that the destination is anomalous: a domain nobody else in the enterprise talks to, a certificate that looks wrong, a beacon with suspicious timing. CLOSEDQUORUM's decision traffic goes to major model APIs over TLS. In an organisation where engineering, support and marketing all legitimately call those endpoints, destination reputation is worthless as a signal. What remains is behavioural: which process is making the call. A Go binary in a user's temp directory holding a conversation with a model provider is not normal, even though the destination is entirely normal. That is an endpoint question, not a network one — and it is the same lesson as the finding that 95% of endpoint malware now arrives over TLS. Encrypted, legitimate-looking transport is the default, so the identity of the process matters more than the identity of the destination.

The economics cut the other way, though. Removing the C2 server removes attacker infrastructure costs and takedown exposure, but it introduces a dependency that is arguably worse: the operation now requires valid, funded API credentials at four commercial providers, and it generates billable usage on every decision. Those accounts are a paper trail, they can be revoked, and abnormal usage patterns are visible to the providers in a way that traffic to a bulletproof-hosted VPS is not. An implant that must authenticate to Google to decide whether to dump LSASS has handed a large, well-instrumented company a view of its own operation. Our assessment: this is the design's central weakness, and it is a meaningful lever for defenders and providers.

How finished is this? Not very. Move being present but non-functional, and the shipped placeholders, both point to software in development rather than in service. The capability set that is implemented — LSASS, browser stores, wallets, Discord exfiltration, registry and WMI persistence, APC injection and hollowing — is conventional commodity infostealer work. Strip out the voting layer and this is an unremarkable stealer. That is not a reason to dismiss it; it is the reason to be precise about what is new. The novel component is the control channel, and it is bolted onto ordinary crimeware.

What remains unclear

  • Whether it has ever run against a real target. Talos says it could not confirm in-the-wild use. Nothing in the public record contradicts that, and nothing confirms deployment either.
  • Whether the quorum design actually works in practice. With placeholder keys in the analysed sample, there is no public evidence of how the four providers respond to the implant's prompts, how often they refuse, or whether the voting produces coherent attack sequences. The refusal-resistance reading above is an inference from the design, not an observed result.
  • Who the developer is. Talos links artefacts to carding-forum activity from 2025 but does not name an actor, and neither do we.
  • The distribution model. The placeholder keys are consistent with a builder or malware-as-a-service offering, which is Talos's reading, but no advertisement, pricing or customer base has been publicly documented.
  • Whether any provider has acted. No statement from DeepSeek, Qwen, Mistral or Google on this implant has appeared in the material reviewed here.
  • How the implant is delivered. The analysis covers post-compromise behaviour. Initial access is not described.

Lessons and what to do

For security teams. The actionable takeaway is narrow and cheap: know which processes on your endpoints are allowed to talk to model APIs. Build the inventory now, while it is still short. Then alert on the inverse — an unsigned binary, a process running from a temporary or user-writable directory, or anything outside your approved AI tooling making outbound calls to model provider endpoints. Note that this rule catches CLOSEDQUORUM-style tooling as a side effect of catching a much broader class of things you already care about, which is what makes it worth building before any of this is in the wild. Discord webhook egress from servers and developer workstations is a separate, older control gap and remains worth closing.

For AI builders and model providers. The dependency described above is leverage. An implant that must authenticate to a commercial API to function is observable at the provider. Usage patterns consisting of short, schema-constrained completions with host-reconnaissance context, arriving from residential or hosting IP space at machine cadence, are not what normal customers look like. Providers already run abuse detection; this is a concrete pattern to add. Separately, the four-option schema trick is worth internalising: a request is not safe merely because each individual completion looks innocuous. Constrained outputs can decompose a harmful plan into steps that each pass review.

For leadership. Treat this one as calibration rather than as an emergency. When a vendor report describes "the first autonomous AI malware", the question to ask is whether anyone has been attacked with it. Here the honest answer is no, and Talos says so plainly — the alarm in some of the coverage was added downstream. Budget accordingly: the controls that address this threat are the same endpoint-visibility and egress-control investments that address commodity infostealers, which are attacking you today. Nothing here justifies a separate line item.

The broader pattern. Taken together with Mandiant's report on hijacked developer AI sessions and Gambit's reconstruction of an agent-driven skimming campaign, CLOSEDQUORUM fits a consistent shape: attackers are not gaining new capabilities from AI so much as removing humans from loops that used to constrain tempo. The implant does nothing a competent operator could not do manually. It just does not need the operator to be awake.

Sources

Primary

Coverage:

Get the daily brief

AI + security signal by email: headlines, a two-line summary, a link. No noise, no spam.

How often