The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM is a Windows malware binary representing the first documented implant utilizing autonomous AI-driven command and control. Discovered through Cisco Talos' CAIRN project, it delegates tactical decisions to a panel of commercial large language models including DeepSeek, Qwen, Mistral, and Google Gemini. The system operates through plurality voting among AI models to select actions for credential harvesting and crypto wallet theft, eliminating the need for continuous human operator involvement. The 16.4MB Go-compiled executable employs structured JSON schema to constrain LLM responses to executable attack choices. While containing placeholder credentials in public distribution, development builds demonstrate compile-time injection of operator-specific API keys and Discord webhooks. This architecture represents a significant shift toward effort displacement in cyber operations, where entire attack phases execute autonomously without human bottlenecks, though introducing new dependencies on commerci...
AI Analysis
Technical Summary
CLOSEDQUORUM is the first publicly documented Windows implant that uses a closed quorum of up to four commercial LLM providers (DeepSeek, Qwen, Mistral, Google Gemini) as its C2 infrastructure. Instead of traditional C2 servers, it queries these LLMs sequentially, each providing a decision from a constrained JSON schema representing specific attack actions. The malware aggregates these decisions by plurality vote and executes the winning action autonomously, without human operator commands. Actions include stealing credentials, dumping browser data, extracting crypto wallets, injecting shellcode, and establishing persistence. The malware is compiled in Go with embedded C code for direct Windows system calls. The design reduces attacker infrastructure footprint and increases resilience by leveraging widely used LLM endpoints. The public distribution build uses dummy API keys, limiting observed execution. This malware exemplifies AI-driven effort displacement in offensive cyber operations, where AI systems replace human operators in attack phases.
Potential Impact
If deployed, CLOSEDQUORUM could autonomously execute phases of an attack chain, including credential theft and crypto wallet extraction, without requiring ongoing attacker control. This reduces the need for attacker infrastructure and human involvement, potentially increasing attack persistence and scale. The malware's use of commercial LLM endpoints for C2 complicates detection and blocking, as these services are widely used and legitimate. However, there is no confirmed active exploitation in the wild at this time.
Mitigation Recommendations
No official patch or remediation is available as this is a novel malware implant rather than a software vulnerability. Detection efforts should focus on identifying unusual use of LLM API endpoints from endpoints and monitoring for behaviors consistent with credential and crypto wallet theft. Traditional C2 blocking techniques may be less effective due to the use of commercial LLM services. Security teams should stay informed on research developments from Cisco Talos’ CAIRN project and apply threat intelligence updates accordingly.
Indicators of Compromise
- hash: 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
- hash: 39ceeb8fd9a17098092434f43edaed18
- hash: b8644f66e695101b1a3ff5a57be09c073db7922f
- hash: 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
- hash: c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
- hash: c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
- hash: eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5
- hash: f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c
The Closed Quorum: Inside the first reported autonomous AI C2 implant
Description
CLOSEDQUORUM is a Windows malware binary representing the first documented implant utilizing autonomous AI-driven command and control. Discovered through Cisco Talos' CAIRN project, it delegates tactical decisions to a panel of commercial large language models including DeepSeek, Qwen, Mistral, and Google Gemini. The system operates through plurality voting among AI models to select actions for credential harvesting and crypto wallet theft, eliminating the need for continuous human operator involvement. The 16.4MB Go-compiled executable employs structured JSON schema to constrain LLM responses to executable attack choices. While containing placeholder credentials in public distribution, development builds demonstrate compile-time injection of operator-specific API keys and Discord webhooks. This architecture represents a significant shift toward effort displacement in cyber operations, where entire attack phases execute autonomously without human bottlenecks, though introducing new dependencies on commerci...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CLOSEDQUORUM is the first publicly documented Windows implant that uses a closed quorum of up to four commercial LLM providers (DeepSeek, Qwen, Mistral, Google Gemini) as its C2 infrastructure. Instead of traditional C2 servers, it queries these LLMs sequentially, each providing a decision from a constrained JSON schema representing specific attack actions. The malware aggregates these decisions by plurality vote and executes the winning action autonomously, without human operator commands. Actions include stealing credentials, dumping browser data, extracting crypto wallets, injecting shellcode, and establishing persistence. The malware is compiled in Go with embedded C code for direct Windows system calls. The design reduces attacker infrastructure footprint and increases resilience by leveraging widely used LLM endpoints. The public distribution build uses dummy API keys, limiting observed execution. This malware exemplifies AI-driven effort displacement in offensive cyber operations, where AI systems replace human operators in attack phases.
Potential Impact
If deployed, CLOSEDQUORUM could autonomously execute phases of an attack chain, including credential theft and crypto wallet extraction, without requiring ongoing attacker control. This reduces the need for attacker infrastructure and human involvement, potentially increasing attack persistence and scale. The malware's use of commercial LLM endpoints for C2 complicates detection and blocking, as these services are widely used and legitimate. However, there is no confirmed active exploitation in the wild at this time.
Defensive Guidance
No official patch or remediation is available as this is a novel malware implant rather than a software vulnerability. Detection efforts should focus on identifying unusual use of LLM API endpoints from endpoints and monitoring for behaviors consistent with credential and crypto wallet theft. Traditional C2 blocking techniques may be less effective due to the use of commercial LLM services. Security teams should stay informed on research developments from Cisco Talos’ CAIRN project and apply threat intelligence updates accordingly.
Technical Details
- Classification
- {"confidence":0.91,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/","fetched":true,"fetchedAt":"2026-09-22T10:11:23.036Z","wordCount":3007}
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7 | — | |
hash39ceeb8fd9a17098092434f43edaed18 | — | |
hashb8644f66e695101b1a3ff5a57be09c073db7922f | — | |
hash5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb | — | |
hashc13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f | — | |
hashc4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7 | — | |
hasheddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5 | — | |
hashf5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c | — |
Threat ID: 6ab2544bf7a7c54106047e1b
Added to database: 09/22/2026, 10:11:23 UTC
Last enriched: 09/22/2026, 10:11:28 UTC
Last updated: 09/23/2026, 13:02:49 UTC
Views: 34
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.