Threats Tagged 'lsass dumping'
View all threats tagged with 'lsass dumping'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'lsass dumping'
Click on any threat for detailed analysis and mitigation recommendations
CLOSEDQUORUM is a Windows malware binary representing the first documented implant utilizing autonomous AI-driven command and control. Discovered through Cisco Talos' CAIRN project, it delegates tactical decisions to a panel of commercial large language models including DeepSeek, Qwen, Mistral, and Google Gemini. The system operates through plurality voting among AI models to select actions for credential harvesting and crypto wallet theft, eliminating the need for continuous human operator involvement. The 16.4MB Go-compiled executable employs structured JSON schema to constrain LLM responses to executable attack choices. While containing placeholder credentials in public distribution, development builds demonstrate compile-time injection of operator-specific API keys and Discord webhooks. This architecture represents a significant shift toward effort displacement in cyber operations, where entire attack phases execute autonomously without human bottlenecks, though introducing new dependencies on commerci... Join the discussion | Cisco Talos | 09/22/2026, 11:35:55 UTC Added: 09/22/2026, 10:11:23 UTC |
Showing 1 to 1 of 1 result