
CLOSEDQUORUM Malware Delegates Command Decisions to Four-Model AI Vote
CLOSEDQUORUM marks the first documented Windows malware to hand C2 task selection to an AI ensemble vote. It exposes operational trade-offs between reduced attacker infrastructure and new failure modes from commercial AI services. Early code ties suggest criminal rather than state development.
Cisco Talos discovered CLOSEDQUORUM via its new CAIRN tool in code dated June 17 2026. The malware packages system metadata and a fixed action list (steal, inject, persist, move) into prompts sent to DeepSeek, Qwen, Mistral, and Gemini. Valid JSON-formatted replies are tallied; the plurality action executes while results stream to a Discord webhook. Public builds contain placeholder API keys and lack implementation for the move action, preventing end-to-end operation.
Code artifacts link the author to 2025 carding forum activity. Unlike LAMEHUG, which used an LLM only to generate commands for hardcoded tasks, CLOSEDQUORUM outsources task selection itself. Reliance on external services introduces rate limits, refusals, and logging risks that traditional C2 avoids, yet removes the need for live attacker infrastructure after initial deployment.
Defenders gain new signals from anomalous API calls to AI endpoints and Discord webhooks carrying credential dumps. The pattern foreshadows broader experimentation with AI-mediated implants that reduce operator exposure while increasing dependence on third-party availability and policy enforcement.
Talos: Production CLOSEDQUORUM variants with live API keys will appear in public malware repositories within 90 days.
Sources (2)
- [1]Cisco Talos CLOSEDQUORUM Analysis(https://blog.talosintelligence.com/closedquorum-ai-vote/)
- [2]CERT-UA LAMEHUG Report(https://cert.gov.ua/article/62784)