Posted in

CLOSEDQUORUM Malware Uses AI Models to Control Windows Attacks

A newly analyzed Windows malware called CLOSEDQUORUM is experimenting with an unusual approach to command and control: instead of relying entirely on an attacker-operated server, it asks multiple AI models to vote on what the malware should do.

Cisco Talos disclosed the malware on September 22, 2026, describing it as an early and limited example of malware that delegates parts of its decision-making process to commercial AI services.

The models can select actions designed to steal Windows credentials, browser passwords, and cryptocurrency wallet information. However, Talos said it has not observed the complete attack chain operating successfully, and the publicly available version of CLOSEDQUORUM does not work without additional configuration.

Talos discovered the malware while using CAIRN, an open-source tool released the same day to help identify malware that interacts with AI services.

The malware is at least several months old. Talos’s code analysis is dated June 17, 2026.

Researchers did not identify how CLOSEDQUORUM would initially reach a victim’s computer. However, code clues reportedly linked its developer to criminal forum activity involving carding—the trade in stolen payment-card data—dating back to 2025.

How CLOSEDQUORUM’s AI Voting System Works

Traditional malware commonly receives instructions from a command-and-control (C2) server operated by the attacker.

CLOSEDQUORUM takes a different approach.

The malware can query up to four commercial AI services:

  • DeepSeek
  • Qwen
  • Mistral
  • Google Gemini

For each request, CLOSEDQUORUM sends basic information about the infected computer, including its computer name, Windows version, and whether it has administrator privileges.

It also provides the AI models with a predefined list of actions.

The available actions are:

  • Steal — collect sensitive information from the computer.
  • Inject — inject code into another process.
  • Persist — establish ways to automatically restart the malware.
  • Move — intended for another action, although the public sample contains no implementation for it.

Each AI model has to return its answer in a specific format. Invalid responses are discarded.

The malware then counts the valid responses and executes whichever action receives the most votes.

If none of the models provides a usable response, CLOSEDQUORUM does not simply choose an action. Instead, it waits and attempts the process again.

This design means an attacker would not necessarily need to send commands to every infected machine after deployment. The AI services can make the operational decision themselves.

Attackers Can Still Monitor the Decisions

Although the AI models make the decisions, the attacker can reportedly monitor what happens.

Before executing an action, CLOSEDQUORUM sends the models’ responses and their stated reasoning to an attacker-controlled Discord channel through a Discord webhook.

A webhook is a URL that allows a program to automatically send messages to a specific channel.

The same Discord channel is also used to receive stolen information.

However, the malware requires several pieces of configuration before this system can operate.

Each build needs:

  • API keys for the AI services
  • A valid Discord webhook
  • The appropriate configuration embedded during compilation

The publicly available sample contains placeholder values instead. As a result, the public version cannot actually communicate with the AI services or send stolen information without being configured.

Talos said that, to its knowledge, CLOSEDQUORUM is the first publicly documented Windows implant to delegate C2 decisions to AI models.

AI-Powered Malware Is Not Entirely New

Attackers have previously experimented with AI-assisted malware.

For example, Ukraine’s CERT-UA reported LAMEHUG in July 2025. That malware used an AI model to generate commands for tasks that had already been defined by the malware.

CLOSEDQUORUM takes a somewhat different approach.

Rather than asking an AI model to generate commands, it asks several models to choose which predefined operation should happen next.

Talos characterized the malware as an early and relatively limited experiment in handing part of an attack’s decision-making process to AI.

There are also obvious limitations to this approach.

AI services can refuse requests, impose usage limits, return malformed responses, or behave differently from one request to another. The malware also depends on infrastructure operated by companies that the attacker does not control.

What CLOSEDQUORUM Can Do

Stealing Credentials and Cryptocurrency Data

When the AI vote selects steal, CLOSEDQUORUM can collect several categories of sensitive information.

Talos found functionality for:

  • Dumping the memory of LSASS, the Windows process that stores authentication-related information.
  • Extracting saved passwords from Chrome, Edge, and Firefox.
  • Collecting information associated with MetaMask, Exodus, and Ethereum cryptocurrency wallets.

This combination potentially gives the malware access to both Windows credentials and valuable browser and cryptocurrency data.

Process Injection

The inject option allows CLOSEDQUORUM to place code inside another process.

Talos observed support for techniques including Early Bird APC injection and, depending on the model’s response, process hollowing.

Process injection can allow malware to execute code under the context of another process and potentially make malicious activity more difficult to identify.

Establishing Persistence

The persist option gives CLOSEDQUORUM several ways to automatically start again after execution.

Talos identified three persistence mechanisms:

  • A value under the current user’s Windows Registry Run key.
  • A scheduled task.
  • A WMI event subscription.

The Registry and WMI components use Windows Update-themed names intended to resemble legitimate system activity.

The WMI mechanism is configured to start the malware every 60 seconds.

How Stolen Data Is Sent

Before sending stolen files, CLOSEDQUORUM copies them into:

C:\Windows\Temp\

The files are then encrypted and divided into 1,900-byte chunks.

The malware sends approximately one chunk per second to the attacker’s Discord channel.

Using small chunks rather than sending an entire file at once can make the traffic resemble a series of ordinary webhook messages rather than a conventional file-transfer operation.

What Security Teams Should Look For

Talos recommends focusing on behavior and combinations of activity rather than simply blocking access to the AI providers used by the malware.

Legitimate applications can communicate with services such as DeepSeek, Mistral, Gemini, Discord, and OpenRouter. Blocking those domains outright could therefore disrupt legitimate activity.

Instead, defenders can look for unusual combinations of behaviors.

Potential indicators include:

  • A Windows application that unexpectedly communicates with AI services.
  • Similar requests being sent to multiple AI providers within a short period.
  • AI prompts containing information about the local computer or attack-related terminology.
  • Access to LSASS.
  • Process injection or execution involving suspended processes.
  • Creation of new persistence mechanisms.
  • Discord webhook activity originating from the same computer or process.
  • Repeated activity at irregular intervals of roughly five to 15 minutes.

Some of the AI-related prompts may only be visible through TLS inspection, because HTTPS encryption prevents ordinary network monitoring from seeing their contents.

Snort and YARA Detection

Talos published a Snort rule, 1:66984, designed to detect CLOSEDQUORUM’s prompts sent to AI services.

Because the prompts are generally protected by TLS, the rule may require TLS inspection to identify them on the network.

Talos also published a YARA rule. The researchers noted that the rule is primarily designed to search VirusTotal’s file data. Some of the strings it detects—including text sent by the malware to AI models—are only available when the malware file itself is scanned.

When The Hacker News checked CAIRN’s rule collection on September 23, it did not contain a CLOSEDQUORUM rule. Organizations using CAIRN would therefore need to add Talos’s rule separately.

CLOSEDQUORUM Hashes

Talos published SHA-256 hashes for six development builds associated with CLOSEDQUORUM:

250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c
5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5

Other Indicators of Compromise

Security teams investigating potentially affected Windows systems can also look for the following artifacts:

  • Registry: A value named WindowsUpdate under the current user’s Run key.
  • File: A PowerShell script at a path consistent with C:\Windows\Temp\wmi.ps1.
  • WMI: A permanent event subscription using Windows Update-themed names that launches the malware every 60 seconds.

What CLOSEDQUORUM Means for Malware Detection

CLOSEDQUORUM does not represent a fully autonomous AI-powered attack. The publicly available sample has significant limitations, requires attacker-supplied API keys and a Discord webhook, and Talos has not observed the entire workflow operating from beginning to end.

Nevertheless, its design highlights a developing security concern: malware can use commercial AI services as part of its decision-making process rather than relying solely on traditional attacker-controlled infrastructure.

For defenders, that makes context increasingly important. An unexpected connection to an AI service is not necessarily malicious on its own. But when that activity occurs alongside credential theft, process injection, persistence mechanisms, LSASS access, and Discord webhook communication, the combination can provide a much stronger signal.

CLOSEDQUORUM therefore offers a glimpse into how attackers could experiment with AI-assisted decision-making inside malware—and why security monitoring may need to consider not just where a program connects, but what it does before, during, and after those connections.

Leave a Reply

Your email address will not be published. Required fields are marked *