Cisco Talos has published static analysis of CLOSEDQUORUM, a 16.4 MB 64-bit Go implant it describes as the first publicly documented Windows malware to apply AI to tactical command and control. Instead of attacker-operated C2 infrastructure — a domain, an IP, a protocol and a listener, all attributable, blockable and costly to rotate — the binary queries up to four commercial LLM providers (DeepSeek, Qwen, Mistral and Google Gemini) in sequence, tallies their independent verdicts on the next action and executes the plurality decision. A ModelOrchestrator aggregates the responses and interModelDiscussion() resolves them; the intended ends are LSASS dumping, crypto-wallet extraction, early-bird process injection and exfiltration to Discord. Talos is explicit about the limits: it has no confirmation of in-the-wild deployment, the public distribution build ships placeholder API keys and a dummy webhook, and the payload's developer was connected to criminal carding-forum postings dating to 2025. Talos frames the significance as effort displacement — moving a whole attack phase from the operator to the system, so the intrusion does not stop when the attacker sleeps. The analysis accompanies Talos's release of CAIRN, an open-source toolkit for tracking AI-integrated malware.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-23 |
| Source | Talos Intelligence |
| Reliability | Tier 2 |