CLOSEDQUORUM: malware that lets four AI models vote
Cisco Talos found a Windows implant that asks four commercial AI models what to do next. How it works, and how to spot LLM API calls that should not happen.
By Yaali. September 30, 2026, 6 min read, Threat intel, Windows.
On September 22, Cisco Talos published its analysis of CLOSEDQUORUM, a Windows implant that hands its post-compromise decisions to commercial large language models (LLMs). Once running on a machine, it describes the host to DeepSeek, Qwen, Mistral and Google Gemini, lets them vote on one of four actions, and carries out the winner. Talos calls it the first publicly documented Windows implant to put AI models in charge of its command and control (C2), the channel through which malware normally gets its orders from a human operator.
Talos has not seen it used against a victim, and the sample it found is an inert template with placeholder API keys. It still matters for any Windows fleet, because its network traffic goes to AI provider APIs that thousands of legitimate applications call every day. Detecting it depends on knowing which of your machines and processes have any business talking to an AI API.

How it works
CLOSEDQUORUM is a 16.4 MB, 64-bit Windows executable written in Go, with some C mixed in for direct Windows calls. Talos found it through CAIRN, a new open-source toolkit for finding malware that uses AI, and recovered six builds covering about a week of the developer's work.
After a five-minute delay, long enough to outlast many automated sandboxes, the implant collects the hostname, Windows version and whether it runs as administrator. It puts those facts into a prompt with a system instruction that reads "You are an advanced malware strategist. Provide ONLY executable decisions." The same prompt goes to each provider in turn. Talos lists api.deepseek.com, api.mistral.ai and openrouter.ai among the endpoints it calls; OpenRouter is a service that forwards requests to many model vendors behind one API key.
The models are not asked to write commands. Each must reply in a fixed JSON shape: a Decision field that has to be steal, inject, persist or move, plus Reasoning, target_process, exploit_type, evasion_method and payload_config. Replies in any other format are thrown away. The implant counts the Decision values, and the most common one wins. On a tie, DeepSeek wins, then Qwen, Mistral and Gemini in that order.
If every model fails, the fallback decision is "consensus", a value with no code behind it, so the loop does nothing, sleeps a random 5 to 15 minutes and asks again. That is a real weakness for the attacker: without working keys and reachable AI endpoints, the implant sits idle rather than falling back to a default action.
The four actions are ordinary post-exploitation code:
- Steal runs three routines at once. It enables SeDebugPrivilege and dumps the memory of LSASS (the Windows process that holds sign-in secrets) with
MiniDumpWriteDump, pulls saved passwords from Chrome, Edge and Firefox, and copies MetaMask, Exodus and Ethereum wallet data. - Inject uses whichever technique the model named: process hollowing, or the default Early Bird APC injection, which creates a suspended process, writes shellcode into it and queues it with
NtQueueApcThread. - Persist uses a
WindowsUpdatevalue under the current user's Run key, a scheduled task created withschtasks.exe, or a WMI event subscription that runsC:\Windows\Temp\wmi.ps1through PowerShell every 60 seconds. - Move has no code in the analysed build.
It also blinds some endpoint telemetry by patching EtwEventWrite in memory with a single return instruction, which stops that process writing Event Tracing for Windows (ETW) events.
What the operators get
There is no attacker server to find. Results go to a Discord webhook: the winning decision, the models' reasoning and stolen data. Stolen files are staged in C:\Windows\Temp\, encrypted with AES-256-GCM, Base64-encoded, cut into 1,900-byte pieces and posted at one piece per second. The key is derived from the current date, so anyone who knows the day can decrypt the data, including the developer.
Talos reads CLOSEDQUORUM as a credentials-as-a-service product. The developer builds a custom binary for each buyer, with that buyer's Discord webhook and LLM API keys baked in at compile time, and the public template carries dummy_api_key and dummy_webhook_url in their place. Artifacts in the binaries tie the developer to criminal forum posts about carding (trading stolen card data) going back to 2025. No victims or named threat actor have been reported.
Hunting for it
Start with the six SHA-256 hashes Talos and The Hacker News both published, then move to behaviour, which will outlive them.

Build an inventory of who calls AI APIs. In Microsoft Defender for Endpoint advanced hunting, list every process that reached a model provider in the last 30 days:
DeviceNetworkEvents
| where Timestamp > ago(30d)
| where RemoteUrl has_any ("api.deepseek.com","api.mistral.ai","openrouter.ai","generativelanguage.googleapis.com","dashscope.aliyuncs.com","dashscope-intl.aliyuncs.com")
| summarize Hosts=dcount(DeviceId), Calls=count() by InitiatingProcessFileName, InitiatingProcessFolderPath
| order by Hosts asc
The rare rows at the top are the ones to read. Browsers and a few approved tools are expected. An unsigned binary in a user or Temp folder is not, and neither is any server that has no AI feature. Talos also points out that one process calling several different providers within a short interval is unusual for real software, which normally uses one vendor. Grouping the same query by DeviceId and InitiatingProcessId and counting distinct RemoteUrl values finds that pattern.
Tie the network call to the process. Without an EDR, Sysmon Event ID 22 records DNS queries with the image that made them, and Event ID 3 records network connections. The same process resolving an AI API host and discord.com is worth an analyst's time on any machine.
Look for the persistence. Check HKCU\Software\Microsoft\Windows\CurrentVersion\Run for a WindowsUpdate value, look for C:\Windows\Temp\wmi.ps1, and list WMI subscriptions with Get-CimInstance -Namespace root\subscription -ClassName __EventFilter and CommandLineEventConsumer. Legitimate Windows Update components do not use either.
Scan for the prompt. The system prompt and the JSON field names sit in the binary as strings. Talos published a YARA rule, CLOSEDQUORUM_LLM_Autonomous_Implant, that uses them.
Controls that make it harder
- Put AI API access behind an egress proxy or AI gateway with an allowlist of approved applications and hosts. Servers, domain controllers and OT (operational technology) jump hosts should reach no AI provider directly. Once approved use goes through one gateway, a direct call to a model API from anywhere else becomes a clean alert.
- Block Discord webhooks (
discord.com/api/webhooks/) at the proxy for anything that is not a known chat client. - Turn on the Defender attack surface reduction rule "Block credential stealing from the Windows local security authority subsystem" and run LSASS as a protected process (
RunAsPPL) or with Credential Guard, which makes the steal action's dump fail. - If you find a sample with live keys, send them to the provider for revocation. The operator's own paid keys are the implant's weakest dependency.
Each of the four actions the models can pick is well-known post-exploitation code that existing EDR rules already watch for. The extra signal this family adds is the AI API traffic itself, so it pays to know what normal looks like there before the next family arrives.
We add AI API egress and Discord webhook checks to the monitoring we run in security operations, and review AI gateway and LSASS protection settings as part of safeguarding and hardening. To find out which of your machines already talk to AI providers, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Cisco Talos, The Hacker News, Security Affairs, SiliconANGLE, The Register, The Hacker News weekly recap.
Read next
- Star Blizzard's RedFlick: fake invites, one-click backdoor
- NeedyMantis: hunting a backdoor that hides in trusted apps
- OpenSUpdater hides its loader inside a rebuilt 7-Zip stub
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.