Subscribe Sign in

Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions

2 min read Rewritten in plain language

Security

Rules applied: D2×2 D3×3 D4 F2×3 all 30 rules
  • A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’ credentials and cryptocurrency wallets.
  • Talos discovered the binary with its new CAIRN (Cognitive Artifact Intelligence Research Network) toolkit for hunting, classifying, and tracking emerging AI-integrated malware, which the security shop also made available as an open source repository on Tuesday.
  • After deployment, the Go-based malware delegates its next action to a quorum of LLMs that vote on what it should do next.
  • The models’ decisions are limited to the pre-defined actions, and they must choose “ONLY executable decisions,” according to a system prompt that Talos’ researchers extracted from the binary.
  • Steal, which simultaneously runs commands to dump LSASS memory for Windows credentials, steal saved browser passwords across Google Chrome, Microsoft Edge, and Mozilla Firefox, and extract cryptocurrency wallet data including MetaMask, Exodus, and Ethereum.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked

Read the full reportHide the full report2 min

'first' publicly documented Windows implant to use LLMs for C2

A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’ credentials and cryptocurrency wallets.

Once deployed, the malware does not require continued commands from a human operator, according to Cisco Talos, which describes it as, to its knowledge, the first publicly documented Windows implant to use this approach for command-and-control (C2).

Talos discovered the binary with its new CAIRN (Cognitive Artifact Intelligence Research Network) toolkit for hunting, classifying, and tracking emerging AI-integrated malware, which the security shop also made available as an open source repository on Tuesday.

While the threat hunters haven’t observed any in-the-wild deployment of CLOSEDQUORUM, they said that artifacts from the binary link the malware’s developer to postings that date back to 2025 on criminal forums related to carding.

After deployment, the Go-based malware delegates its next action to a quorum of LLMs that vote on what it should do next. If the vote is tied, DeepSeek’s vote takes precedence, followed by Qwen, Mistral, and Gemini.

“The session is closed; no humans are admitted,” Talos analyst Ryan Fetterman said on Tuesday. “Four models are queried in sequence, their independent verdicts tallied, and the binary acts, based on their judgment.”

This type of “effort displacement,” which transfers a phase of the attack from a human operator to AI systems, can compound the speed and scale advantages of an intrusion by removing the human bottleneck, Fetterman added.

“Human operators are bound by attention, working hours, and cognitive load,” he wrote in the Tuesday blog. “An AI system capable of executing a phase of the attack chain can continue when the operator is no longer watching. It does not go offline when the attacker sleeps.”

The models’ decisions are limited to the pre-defined actions, and they must choose “ONLY executable decisions,” according to a system prompt that Talos’ researchers extracted from the binary. It tells each model: “You are an advanced malware strategist.”

And then the models choose what the malware should do from these capability modules:

Steal, which simultaneously runs commands to dump LSASS memory for Windows credentials, steal saved browser passwords across Google Chrome, Microsoft Edge, and Mozilla Firefox, and extract cryptocurrency wallet data including MetaMask, Exodus, and Ethereum.

Inject generates shellcode and then uses process hollowing or Early Bird injection to execute malicious code.

Persist establishes persistence on the infected device.

Talos believes the developer provides each operator with a customized executable containing that operator’s Discord webhook and LLM API keys, which are injected at compile time.

Stolen credentials land in the operator’s Discord channel and are AES-256-GCM encrypted with a daily rotating key that the operator derives from the message timestamp.

According to Fetterman, the “most useful detection strategy” is to look at behavioral characteristics, not domain blocking.

“Legitimate applications may contact DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently,” he wrote. “Far fewer should contact several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence.”®

You are reading our version, not theirs. This is The Register's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 7.1 10 68 0.1 43.4
Mundane Readneutralized from The Register 7.1 10 68 0.1 43.4

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works