Cisco Talos reported CLOSEDQUORUM, a 64-bit Go-based Windows implant that delegates tactical command-and-control decisions to a plurality vote among commercial LLMs including DeepSeek, Qwen, Mistral, and Google Gemini. Rather than depending on a conventional attacker-controlled C2 server or continuous operator input, the malware can use the models' structured responses to select actions such as credential theft, persistence, and process injection—including techniques that can execute malicious code within legitimate processes and evade process-based defenses.
The observed sample was an inert template containing placeholder API keys and a dummy Discord webhook, so Talos could not validate end-to-end execution or deployment in the wild. Build artifacts suggest customized variants may embed provider credentials and Discord endpoints for exfiltration; the implant targets LSASS memory, browser-stored credentials, and cryptocurrency wallets, encrypting and Base64-encoding data before segmented Discord delivery. Defenders should correlate anomalous traffic to multiple AI-provider APIs with LSASS access, process-injection behavior, persistence changes, and Discord communications.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos shared an open-source framework designed to identify, classify, and analyze malware and hacking tools that use AI chatbots or agentic AI components. Talos said applying the framework identified an unusual AI-guided malware instance, though the excerpt did not name the malware, operators, or targets.
The malware previously referred to as BALZAK was renamed CLOSEDQUORUM.
Development-build artifacts associated with CLOSEDQUORUM reportedly link its developer to criminal-forum carding posts dating to 2025.
Cisco Talos discovered the Go-based 64-bit Windows CLOSEDQUORUM binary through its CAIRN project and described it as the first publicly documented Windows implant using commercial LLMs for tactical command-and-control decisions. The observed distribution sample was an inert template with dummy API keys and a Discord webhook, so Talos did not confirm in-the-wild deployment or end-to-end execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceblog.talosintelligence.com
Open sourcewired.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.