Cisco Talos CLOSEDQUORUM: Windows implant uses Gemini/DeepSeek/Qwen/Mistral quorum to pick post-compromise actions (no human C2)
Cisco Talos (22 September 2026), via its CAIRN AI-malware research toolkit, documents CLOSEDQUORUM: a Go-based Windows implant that after deployment queries up to four commercial LLMs (DeepSeek, Qwen, Mistral, Google Gemini), tallies votes, and executes the winning tactical action without a human operator or attacker-run C2 server. Constrained actions include steal (LSASS dump; Chrome/Edge/Firefox credentials; MetaMask/Exodus/Ethereum wallets), inject (shellcode via process hollowing or Early Bird APC), persist, and move (lateral-movement option present but handler absent in analysed build). Stolen material is forwarded via Discord webhook. Talos states it does not have confirmation of in-the-wild deployment; binary artifacts linked a developer to carding-forum activity from 2025. Talos frames this as effort displacement in AI-enabled offence and the first publicly documented Windows implant to delegate tactical C2 decisions to an LLM panel. Primary: Cisco Talos blog; wire: BleepingComputer 22 Sep 2026.
- Product
- CLOSEDQUORUM Windows implant (AI-quorum post-compromise); Discord webhook exfil
- Exploited in Australia?
- unknown
- Patch to
- No CVE: detect Go implant + Discord webhook C2; block/monitor unexpected calls to Gemini/DeepSeek/Qwen/Mistral APIs from endpoints; hunt LSASS/browser/wallet theft behaviours; review Talos CAIRN indicators; treat as architectural early warning until in-wild confirmation
Primary: Cisco Talos — The Closed Quorum / CLOSEDQUORUM (22 Sep 2026) · Vendor: Cisco Talos — CLOSEDQUORUM analysis · BleepingComputer — ClosedQuorum AI C2 (22 Sep 2026)
