talos · Crawled Sep 22, 2026

The Closed Quorum: Inside the first reported autonomous AI C2 implant

10 IoCs
Read original article ↗

AI Summary

CLOSEDQUORUM is a Windows-based malware implant that uses commercial large language models (LLMs) from DeepSeek, Qwen, Mistral, and Google Gemini as an autonomous command and control (C2) infrastructure. It delegates tactical decisions such as credential theft, process injection, and persistence to a panel of LLMs, which vote on the next action via a structured JSON schema. The malware targets user credentials and cryptocurrency wallets, exfiltrating stolen data via an operator-controlled Discord webhook using AES-256-GCM encryption and Base64 encoding. While the distributed version contains placeholder keys and is non-functional, development builds suggest a 'credentials-as-a-service' model where customized binaries are provided to operators.

AI-extracted · verify before operational use

Indicators of Compromise 10 extracted

Type Value Detail
SHA-256 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7 Details →
SHA-256 c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7 Details →
SHA-256 c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f Details →
SHA-256 f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c Details →
SHA-256 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb Details →
SHA-256 eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5 Details →
Domain api[.]deepseek[.]com Details →
Domain openrouter[.]ai Details →
Domain api[.]mistral[.]ai Details →
Domain cdn[.]discordapp[.]com Details →