Executive Summary
Cisco Talos discovered CLOSEDQUORUM, a Windows infostealer malware that represents the first publicly documented implant to use AI models for command and control decisions. Instead of receiving orders from traditional C2 servers, the malware queries up to four commercial AI services (DeepSeek, Qwen, Mistral, and Google Gemini) to vote on its next actions, including credential theft, browser password extraction, and crypto wallet data harvesting. The malware sends basic system information to the AI models and executes the action receiving the most votes, with results communicated via Discord webhooks. While the public version contains placeholder values and is non-functional, Talos linked the developer to criminal carding forum activities dating to 2025.
This incident highlights the emerging threat of AI-integrated malware, representing a significant evolution in autonomous attack capabilities that could reshape how cybercriminals conduct operations while creating new dependencies on commercial AI services.
Why This Matters Now
The discovery of AI-driven autonomous malware marks a critical inflection point in cyber threats, demonstrating how attackers are weaponizing commercial AI services to create self-directing implants that operate independently of traditional command infrastructure, requiring immediate defensive adaptations.
Attack Path Analysis
CLOSEDQUORUM malware establishes initial foothold through unknown delivery mechanism, escalates privileges through LSASS memory dumps and credential theft, maintains persistence through multiple mechanisms, establishes AI-driven C2 using commercial models for decision-making, exfiltrates stolen credentials and crypto wallet data via Discord webhooks, and achieves impact through autonomous data theft operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Malware delivered to Windows system through unknown vector, likely phishing or drive-by download based on carding forum association
MITRE ATT&CK® Techniques
LSASS Memory
Credentials from Web Browsers
Registry Run Keys / Startup Folder
Scheduled Task
Windows Management Instrumentation Event Subscription
Asynchronous Procedure Call
Exfiltration to Text Storage Sites
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography and Security Protocols
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Network Traffic Analysis
Control ID: ED.AM-04
NIS2 Directive – Incident Handling
Control ID: Article 21(2)(a)
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
AI-driven infostealer targeting credentials and crypto wallets poses severe threats to financial data integrity and regulatory compliance frameworks.
Computer Software/Engineering
CLOSEDQUORUM represents paradigm shift in malware autonomy, requiring enhanced detection capabilities for AI-integrated threats and security architecture updates.
Computer/Network Security
Novel AI-voting C2 mechanism challenges traditional detection methods, demanding new threat hunting tools like CAIRN for autonomous malware identification.
Information Technology/IT
Windows-based AI malware targeting LSASS credentials and browser data requires immediate policy updates for multicloud visibility and egress controls.
Sources
- This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Movehttps://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.htmlVerified
- The Closed Quorum: Inside the First Reported Autonomous AI C2 Implanthttps://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/Verified
- Introducing CAIRN: Frontier Tracking for AI-Integrated Malwarehttps://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/Verified
- Snort Rule 1:66984 for CLOSEDQUORUM Detectionhttps://www.snort.org/rule_docs/1-66984Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain CLOSEDQUORUM's autonomous AI-driven operations through workload segmentation and controlled network paths. The malware's lateral movement, credential harvesting, and data exfiltration activities would face reduced blast radius within segmented cloud environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial malware deployment would likely face constrained network reachability and limited access to cloud resources through workload isolation boundaries
Control: Zero Trust Segmentation
Mitigation: Stolen credentials would likely provide reduced access scope within segmented environments, constraining privilege escalation across workload boundaries
Control: East-West Traffic Security
Mitigation: Process injection techniques would likely encounter restricted east-west communication paths, reducing the malware's ability to spread across workloads
Control: Multicloud Visibility & Control
Mitigation: AI model API communications would likely be detected and potentially constrained through multicloud traffic analysis and anomalous behavior identification
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration via Discord webhooks would likely be constrained through controlled egress policies and outbound traffic restrictions
Persistent mechanisms would likely achieve reduced operational scope within segmented environments, limiting access to sensitive workloads and data repositories
Impact at a Glance
Affected Business Functions
- Information Security Operations
- Credential Management Systems
- Financial Services (Crypto Wallets)
- Web Browser Data Protection
Estimated downtime: 3 days
Estimated loss: $75,000
Windows login credentials via LSASS memory dumps, saved browser passwords from Chrome, Edge, and Firefox, cryptocurrency wallet data from MetaMask, Exodus, and Ethereum wallets. The malware establishes persistent access through Registry modifications, scheduled tasks, and WMI event subscriptions.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to AI services and Discord webhooks from non-authorized applications
- • Deploy Zero Trust Segmentation with least privilege access controls to prevent LSASS memory dumping and limit process injection capabilities
- • Enable Multicloud Visibility & Control to detect anomalous patterns of AI service queries combined with credential access behaviors
- • Configure Threat Detection & Anomaly Response to identify suspicious combinations of AI service traffic, process injection, and persistence mechanisms
- • Establish Cloud Native Security Fabric (CNSF) controls to monitor and restrict AI model interactions and autonomous system behaviors in real-time



