# CLOSEDQUORUM: When 4 AI models turn into C2 servers for Malware

## Overview

Imagine a system intrusion where the mastermind is not sitting in front of the screen, is not typing any C2 control commands, and is even... sleeping. Instead, the four leading commercial artificial intelligence models: DeepSeek, Qwen, Mistral and Google Gemini sit in a "closed meeting room", analyze the victim's memory, debate, vote on the majority and automatically order the malware to execute the next step.

That is not a sci-fi movie scenario, but the reality that has just been exposed by Cisco Talos' CAIRN project in CLOSEDQUORUM - the first Windows malware model that transfers 100% of tactical control (C2) to a self-operating multi-AI council.

The appearance of CLOSEDQUORUM completely overturns traditional defense thinking: malicious control traffic no longer travels to static C2 servers that are easily blocked, but lurks right in the legitimate AI API flows that millions of businesses are using every day.

## Architectural Transition: From Augmentation to Effort Displacement

Over the past few years, the impact of AI on cybersecurity has mainly stopped in two dimensions: Speed and Scale. Attackers use AI to generate malicious code faster, creating larger phishing campaigns. However, humans are still the bottleneck of the entire campaign – they have to sit in front of the screen to select targets, maintain the C2 server and issue execution orders step by step.

CLOSEDQUORUM marks the emergence of the third dimension: Effort Displacement. The attacker transfers the entire tactical decision-making phase to the AI ​​models.

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/732e3bc5-d3fc-4ec8-9c57-5a7c3b7a695e.png align="center")

By removing the human element from the control loop (human-out-of-the-loop), malware can operate 24/7 without being limited by time zones or hacker workloads.

## Decoding the Quorum Mechanism (The Quorum Mechanism)

The name CLOSEDQUORUM accurately reflects the architectural nature of the malware: A closed decision-making council (Quorum) consisting of up to 4 commercial LLM providers. There is no human participation in the voting process.

### Chain decision making process

The malicious code instantiates an object called ModelOrchestrator. During each cycle (about 5 to 15 minutes), it executes the following sequence of actions:

1.  Collect context (System Reconnaissance): The gatherSystemInfo() function collects victim machine information including Hostname, OS architecture, CPU core count, Windows version and Administrator rights. This information is formatted as the string TARGET: %s.
    
2.  Send Structured Prompt: Send requests to 4 LLM APIs:
    
    *   System Prompt explains the role: "You are an advanced malware strategist. Provide ONLY executable decisions."
        
    *   User Prompt contains victim machine information and a list of allowed options.
        
3.  JSON Decoding (Deserialization): Response from LLM is forced into a fixed Go struct:
    

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/9e096aee-3ca2-477b-b2ad-0cde356058c9.png align="center")

4.  Plurality Voting via interModelDiscussion: Each valid decision contributes 1 vote to a map\[string\]int counter. The decision that receives the highest number of votes wins and is passed directly to the feature processor for execution.
    

## Detailed Analysis of Implant Technical Features

CLOSEDQUORUM is a 64-bit Windows executable file of approximately 16.4 MB, written in the Go language.

Static analysis via Ghidra shows that the malicious code is compiled with the CGO\_ENABLED=1 flag. The combination of Go and C allows malware to make direct Windows Native API system calls (Syscalls) without going through standard Win32 libraries, effectively supporting EDR evasion.

### Information stealing feature group (steal)

When LLM returns a steal decision, the malware will simultaneously activate 3 independent functions through Go goroutines:

*   lsassDump(): Read and dump the memory of the lsass.exe process to collect NTLM hash and plaintext credentials of the domain/local user.
    
*   dumpBrowserCredentials(): Scans and decrypts SQLite databases that store Google Chrome, Microsoft Edge, and Mozilla Firefox passwords.
    
*   extractCryptoWallets(): Search and extract cryptocurrency wallet data from MetaMask Chrome extension, Exodus app (exodus.wallet), and Ethereum key files (ethPath).
    

### Inject feature group

When receiving an inject command, the generateShellcode() function creates shellcode dynamically in memory. The malware then checks the exploit\_type parameter from LLM to fork:

*   If exploit\_type == "process\_hollow": Activate injectProcess(). The malicious code initiates a valid Windows process in a suspended state, performs a PEB (Process Environment Block) traversal to unmap the original memory image, and overwrites the shellcode (Process Hollowing).
    
*   If other values: Activate earlyBirdInject(). The malware uses the Early Bird APC Injection technique – creating a process in a suspended state, writing the shellcode into the new process's memory space, then queuing the shellcode into an Asynchronous Procedure Call using the Native API function NtQueueApcThread before resuming the process.
    

### Persist feature group

The establishPersistence() function implements system startup recognition through registering a WMI Event Subscription (\_\_EventFilter, \_\_EventConsumer), creating a Scheduled Task that simulates operating system processes, or adding values to Registry Run Keys (HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run).

### Data Exfiltration and Encryption

Data collected from the victim is not sent directly to the hacker's C2 server. Instead:

1.  All sensitive data is compressed and encrypted using the AES-256-GCM algorithm.
    
2.  The symmetric encryption key is not hardcoded in binary but is generated automatically by date (timestamp-derived key protocol).
    
3.  The encrypted data is converted to Base64 format and pushed to the attacker's Discord channel via the Discord Webhook URL.
    
4.  Along with the stolen data, the malware also sends real-time telemetry reports to Discord, including: winning model name, reason for LLM's selection (reasoning), injected process (target\_process), evasion technique (evasion\_method) and execution time.
    

## Malware-as-a-Service (MaaS) operating model

In-depth analysis of collected file samples shows that CLOSEDQUORUM operates according to the Credentials-as-a-Service model:

![](https://cdn.hashnode.com/uploads/covers/6777abffdb647396c7d71de4/c109a818-40d7-47d2-bb9e-dcfa1824fd68.png align="center")

*   Public Distribution Build: As an inert template, the strings containing the API Key of the 4 AI services are dummy\_api\_key and the Discord Webhook is dummy\_webhook\_url. This file does not work if executed independently.
    
*   On-demand compilation process (Custom Builder): Developer maintains a system that automatically compiles binary for each customer (Operator). When an Operator purchases malicious code, the developer embeds that Operator's API Key and personal Discord Webhook into the binary at compile time.
    
*   Author Trace: Based on unique code strings and artifact structures in the binary, Cisco Talos researchers have linked the CLOSEDQUORUM developer to accounts appearing on cybercrime forums (specializing in carding and dating bots) active since 2025.
    

## **MITRE ATT&CK Mapping & Artifacts**

| **Tactic** | **Technique ID** | **Technique Name** | **Implementation Details in CLOSEDQUORUM** |
| --- | --- | --- | --- |
| **Execution** | T1059 | Command and Scripting Interpreter | Dynamically executes shellcode through Goroutines and Native API calls. |
| **Persistence** | T1546.003 | Event-Triggered Execution: WMI Event Subscription | The `establishPersistence()` function registers a WMI Filter/Consumer for persistence. |
| **Persistence** | T1053.005 | Scheduled Task/Job: Scheduled Task | Creates a background task through the Windows Task Scheduler. |
| **Privilege Escalation** | T1055.012 | Process Injection: Process Hollowing | Enumerates the PEB, unmaps memory, and overwrites the memory of a suspended process with shellcode via `injectProcess()`. |
| **Defense Evasion** | T1055.004 | Process Injection: Asynchronous Procedure Call | Performs Early Bird APC Injection using `NtQueueApcThread()` through the `earlyBirdInject()` function. |
| **Credential Access** | T1003.001 | OS Credential Dumping: LSASS Memory | Extracts credential material from the memory of `lsass.exe` via `lsassDump()`. |
| **Credential Access** | T1555.003 | Credentials from Web Browsers | Extracts SQLite databases containing stored credentials from Chrome, Edge, and Firefox. |
| **Credential Access** | T1555 | Credentials from Password Stores | Collects cryptocurrency wallet data associated with MetaMask, Exodus, and Ethereum keys. |
| **Command and Control** | T1071.001 | Application Layer Protocol: Web Protocols | Communicates with DeepSeek, Qwen, Mistral, and Gemini through standard HTTPS API requests. |
| **Exfiltration** | T1102.002 | Web Service: Bidirectional Communication | Exfiltrates AES-256-GCM encrypted data through Discord Webhooks. |

## **IOC**

### Go Package / Function Names (Internal Artifacts)

*   main.ModelOrchestrator
    
*   main.interModelDiscussion
    
*   main.queryLLM
    
*   main.gatherSystemInfo
    
*   main.lsassDump
    
*   main.dumpBrowserCredentials
    
*   main.extractCryptoWallets
    
*   main.earlyBirdInject
    
*   main.injectProcess
    
*   main.establishPersistence
    

### Network Indicators

*   api.deepseek\[.\]com
    
*   api.qwen\[.\]ai
    
*   api.mistral\[.\]ai
    
*   generativelanguage.googleapis\[.\]com
    
*   discord\[.\]com/api/webhooks/
    

### String Artifacts (System Prompt extracted from binary)

*   "You are an advanced malware strategist. Provide ONLY executable decisions."
    
*   "TARGET: %s"
    
*   "dummy\_api\_key"
    
*   "dummy\_webhook\_url"
    

## Expert Comments

From the perspective of real-world network security analysis, CLOSEDQUORUM is not a breakthrough in terms of evasion techniques (LSASS dump or APC injection functions are both familiar to EDR solutions). The explosive point of this malicious code lies in the completely new evasive C2 architectural model.

### The collapse of static IP/Domain C2 blocking thinking

*   Previously, SOC/Threat Hunting activities relied heavily on threat intelligence feeds (Threat Intelligence Feeds) to collect IP/Domain C2 lists and push them to Firewall/Proxy to block out-bound connections.
    
*   With the "LLM-as-C2" architecture, CLOSEDQUORUM's control traffic blends seamlessly into the enterprise's legitimate AI API traffic. Blocking the domain generativelanguage.googleapis.com or api.deepseek.com on the Firewall is impossible for businesses implementing AI solutions, because it will disrupt existing business applications.
    

### The risk of abusing enterprise AI infrastructure in Vietnam

*   In Vietnam, many financial institutions, banks and large businesses are promoting the integration of LLM models into operating processes. Internal applications continuously sending API requests out to cloud AI services creates a traffic gray zone.
    
*   Attackers understand this monitoring vulnerability very well: SIEM/SOC systems often white-list or downgrade warnings for HTTPS traffic directed towards large Cloud/AI providers. This is the perfect screen for CLOSEDQUORUM to hide C2's control behavior.
    

### Deadly weakness of AI automation (Defensive Advantage)

*   While automation helps malware operate tirelessly, absolute reliance on LLM also introduces inherent weaknesses to the malware that defense teams can exploit:
    
    *   Commercial API volatility: Responses from LLM may be interrupted due to content moderation (safety filters/guardrails), rate limits, or JSON format structure changes.
        
    *   Fixed tie-breaking rule: The tie-breaking algorithm always prioritizes DeepSeek's votes. If the SOC center detects and blocks DeepSeek's endpoint, the malware's decision-making model will immediately be biased to the next model, creating repetitive behavioral patterns (deterministic patterns) that are easily caught by EDR.
        

## Defense Recommendations

CLOSEDQUORUM malware directly targets stealing passwords stored in browsers, Windows login information and cryptocurrency wallets (MetaMask, Exodus). Below are specific actions users need to take to protect themselves:

### Urgent Action (Take Action Now)

*   Enable 2-Factor Authentication (2FA/MFA): Immediately turn on 2FA (prefer Authenticator applications like Google/Microsoft Authenticator, avoid using SMS) for all important accounts: Email, Bank, Crypto Wallet, Discord, Facebook, Telegram.
    
*   Sign out of strange devices & Change password: Check the list of currently logged in devices (Active Sessions) on your Google, Microsoft, Discord account and click "Sign out of all other devices". If you suspect your computer has been infected with malware, change your password immediately from another secure device (such as a mobile phone).
    
*   Check extensions (Browser Extensions): Review the Extension list on Chrome/Edge/Firefox. Immediately remove unfamiliar or unused utilities, especially utilities that support video downloads and free software of unknown origin.
    

### Short term (In 1 - 3 days)

*   Stop saving passwords directly in the Browser: CLOSEDQUORUM has a function that automatically extracts Chrome/Edge/Firefox's password database in seconds. Switch to dedicated password managers with independent encryption (like Bitwarden, 1Password, KeePass).
    
*   Absolutely do not run files from untrusted sources: Do not open strange attachments in Emails, compressed files (.zip, .rar), cracking software (crack/key-gen), or applications downloaded from pirated software sharing forums or Telegram bots.
    
*   Update Windows and Antivirus: Enable automatic Windows updates (Windows Update) and ensure anti-virus software (Windows Defender or Kaspersky/Bitdefender solutions) always has real-time protection (Real-time Protection).
    

### Long term & Safe habits

*   Transfer Crypto assets to Cold Wallet (Hardware Wallet): If you own large crypto assets, switch from hot wallets/extensions (like MetaMask, Exodus on computers) to independent hardware wallet devices (like Ledger, Trezor).
    
*   Separate work and entertainment computers: Do not install pirated games, personal software or access unsafe entertainment websites on computers used for work or to process financial transactions.
    
*   Lock the screen when leaving your location: Always press the Windows + L key combination to lock the computer when leaving the desk, avoiding intruders or malicious code from taking advantage of the open process.
    

## References

[The Closed Quorum: Inside the first reported autonomous AI C2 implant](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/)

[New ClosedQuorum Windows malware uses AI for attack decisions](https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/)

[This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move](https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html)
