Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The default Early Bird APC routine creates a suspended Windows process, writes dynamically generated shellcode into its memory, queues the payload with NtQueueApcThread, and resumes execution.
When the LLM selects process_hollow, the implant locates the suspended process’s image base, overwrites its entry-point region, and resumes the thread.
A secondary payload is stored in an encrypted form to impede inspection and static recovery.
Windows Update-themed Registry, WMI filter, and consumer names help the implant blend with legitimate system activity.
The default Early Bird APC routine creates a suspended Windows process, writes dynamically generated shellcode into its memory, queues the payload with NtQueueApcThread, and resumes execution.
When the LLM selects process_hollow, the implant locates the suspended process’s image base, overwrites its entry-point region, and resumes the thread.
Discord also serves as a reporting channel through which the implant sends the LLM panel’s selected action to the operator in real time. | CLOSEDQUORUM treats commercial LLM providers as its C2 infrastructure, querying DeepSeek, Qwen, Mistral, and Google Gemini for its next action rather than receiving continued human commands or using a dedicated attacker-operated C2 server.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 64-bit Go-based Windows autonomous implant that uses DeepSeek, Qwen, Mistral, and Google Gemini APIs as a multi-provider, LLM-driven C2 decision layer. It can dump LSASS memory, steal browser credentials and crypto-wallet data, inject shellcode through Early Bird APC injection or process hollowing, establish Registry Run-key, scheduled-task, and WMI persistence, suppress ETW telemetry, and exfiltrate AES-256-GCM-encrypted, Base64-encoded data to an operator-controlled Discord webhook. The public build contained placeholder API keys and webhook values; development builds indicate per-operator customized binaries.
An AI-integrated malware family described as a fully autonomous, multi-model consensus orchestrator operating without a human operator.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.