Skip to main content

The Closed Quorum: Inside the first reported autonomous AI C2 implant

0
High
Published: 09/22/2026 (09/22/2026, 11:35:55 UTC)
Source: Cisco Talos

Description

CLOSEDQUORUM is a Windows malware binary representing the first documented implant utilizing autonomous AI-driven command and control. Discovered through Cisco Talos' CAIRN project, it delegates tactical decisions to a panel of commercial large language models including DeepSeek, Qwen, Mistral, and Google Gemini. The system operates through plurality voting among AI models to select actions for credential harvesting and crypto wallet theft, eliminating the need for continuous human operator involvement. The 16.4MB Go-compiled executable employs structured JSON schema to constrain LLM responses to executable attack choices. While containing placeholder credentials in public distribution, development builds demonstrate compile-time injection of operator-specific API keys and Discord webhooks. This architecture represents a significant shift toward effort displacement in cyber operations, where entire attack phases execute autonomously without human bottlenecks, though introducing new dependencies on commerci...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 10:11:28 UTC

Technical Analysis

CLOSEDQUORUM is the first publicly documented Windows implant that uses a closed quorum of up to four commercial LLM providers (DeepSeek, Qwen, Mistral, Google Gemini) as its C2 infrastructure. Instead of traditional C2 servers, it queries these LLMs sequentially, each providing a decision from a constrained JSON schema representing specific attack actions. The malware aggregates these decisions by plurality vote and executes the winning action autonomously, without human operator commands. Actions include stealing credentials, dumping browser data, extracting crypto wallets, injecting shellcode, and establishing persistence. The malware is compiled in Go with embedded C code for direct Windows system calls. The design reduces attacker infrastructure footprint and increases resilience by leveraging widely used LLM endpoints. The public distribution build uses dummy API keys, limiting observed execution. This malware exemplifies AI-driven effort displacement in offensive cyber operations, where AI systems replace human operators in attack phases.

Potential Impact

If deployed, CLOSEDQUORUM could autonomously execute phases of an attack chain, including credential theft and crypto wallet extraction, without requiring ongoing attacker control. This reduces the need for attacker infrastructure and human involvement, potentially increasing attack persistence and scale. The malware's use of commercial LLM endpoints for C2 complicates detection and blocking, as these services are widely used and legitimate. However, there is no confirmed active exploitation in the wild at this time.

Defensive Guidance

No official patch or remediation is available as this is a novel malware implant rather than a software vulnerability. Detection efforts should focus on identifying unusual use of LLM API endpoints from endpoints and monitoring for behaviors consistent with credential and crypto wallet theft. Traditional C2 blocking techniques may be less effective due to the use of commercial LLM services. Security teams should stay informed on research developments from Cisco Talos’ CAIRN project and apply threat intelligence updates accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.91,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/","fetched":true,"fetchedAt":"2026-09-22T10:11:23.036Z","wordCount":3007}

Indicators of Compromise

Hash

ValueDescriptionCopy
hash250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
hash39ceeb8fd9a17098092434f43edaed18
hashb8644f66e695101b1a3ff5a57be09c073db7922f
hash5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
hashc13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
hashc4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
hasheddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5
hashf5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c

Threat ID: 6ab2544bf7a7c54106047e1b

Added to database: 09/22/2026, 10:11:23 UTC

Last enriched: 09/22/2026, 10:11:28 UTC

Last updated: 09/23/2026, 13:02:49 UTC

Views: 34

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses