CLOSEDQUORUM Malware Uses Four AI Models to Vote on Attack Actions Against Windows
Cisco Talos researchers have statically analyzed a Go-based Windows implant called CLOSEDQUORUM, which sends host information to up to four commercial large language models — DeepSeek, Qwen, Mistral, and Google Gemini — and executes whichever attack action receives the most votes. Capabilities built into the implant include credential theft from LSASS memory, browser data and cryptocurrency wallet harvesting, process injection, and persistence via Registry Run keys, scheduled tasks, or WMI subscriptions. Collected data is encrypted with AES-256-GCM, split into segments, and exfiltrated to a Discord webhook. The publicly available version contains placeholder API keys and webhooks, meaning it is non-functional as distributed, and no real-world deployment has been confirmed. The threat actor behind CLOSEDQUORUM remains unidentified, and no CVEs are associated with this implant.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in