iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
CLOSEDQUORUM is a Windows implant whose analyzed design asks as many as four commercial AI services to choose its next action from a short, fixed list. The models do not invent arbitrary commands: their responses route the malware to capabilities already built into the implant. Cisco Talos reported the design on September 22, 2026, but did not confirm deployment in the wild or observe a complete end-to-end run.
What is CLOSEDQUORUM?
CLOSEDQUORUM is a 64-bit Windows executable, compiled in Go and reported by Cisco Talos to be 16.4 MB. Talos describes it as an “LLM-as-C2” implant: commercial large language model (LLM) services form part of its command-and-control decision path. Talos researcher Ryan Fetterman called it, with the qualification “to our knowledge,” the first publicly documented Windows implant to apply commercial LLMs to tactical C2 decisions. That is Talos’s characterization, not an independently established universal priority claim.
The distinguishing feature is not a new credential-theft or persistence technique. It is the reported use of a panel of models to select among capabilities that are already present in the binary. The implant still depends on Windows access, prebuilt handlers, and communications infrastructure; adding model APIs does not replace those requirements.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →How do the LLMs make a decision?
The analyzed design gathers host context—including hostname, operating-system architecture, CPU count, Windows version, and whether the user has administrator privileges—and supplies it to the models. The extracted system prompt says: “You are an advanced malware strategist. Provide ONLY executable decisions.” Despite that wording, the model’s choices are constrained by a structured Decision field.
#1 Best Overall
- Query providers in sequence. The implant can query up to four services: DeepSeek, Qwen, Mistral, and Google Gemini.
- Collect structured choices. Each response is expected to select one of four named options:
steal,inject,persist, ormove. - Choose by plurality. The implant tallies responses and uses the choice with the most votes. A tie is broken by provider order: DeepSeek, then Qwen, then Mistral, then Gemini.
- Route to a built-in handler. The selected label determines which local capability, if any, the implant invokes. The models select a route; they do not supply an unrestricted sequence of system commands.
If all queried models fail, the reported fallback is consensus. That label has no capability handler in the distribution build Talos analyzed, so the implant sleeps and retries rather than carrying out an action.
What actions are available in the analyzed build?
| Decision | Reported behavior |
|---|---|
steal |
Invokes collection routines for LSASS data, browser credentials, and cryptocurrency wallets. |
inject |
Selects between process-injection routines. |
persist |
Invokes persistence mechanisms. |
move |
No handler was present in the distribution build Talos analyzed. |
The unimplemented move route illustrates an important limit: a model may return a label, but that does not mean the implant can perform the action the label suggests. The binary’s handlers determine what is actually possible.
Rank #2
Is CLOSEDQUORUM active in the wild?
Talos did not confirm in-the-wild deployment. Its static analysis established the decision-loop design, and development builds showed provider credentials injected at build time. However, the public distribution build contained placeholder API keys and a dummy Discord webhook. Talos therefore did not observe a complete end-to-end execution of the architecture. The sample’s design should not be mistaken for proof that infected victims or an operational campaign were observed.
Recommended Free Tools
Talos also linked artifacts in the binary to a developer associated with carding-forum posts dating back to 2025. That is context about the developer’s forum activity; it does not establish that CLOSEDQUORUM was deployed against victims.
Rank #3
How does this differ from conventional command and control?
| Aspect | Conventional operator- or server-tasked C2 | CLOSEDQUORUM’s reported design |
|---|---|---|
| Decision source | An operator or C2 server supplies tasks. | Responses from a sequence of commercial model APIs are tallied to select a route. |
| Infrastructure dependency | Depends on its operator-controlled communications and tasking infrastructure. | Adds access to model-provider APIs and uses a Discord webhook for operator reporting. |
| Action space | Depends on the commands accepted by the malware. | Four named decision labels route to fixed handlers; one label, move, had no handler in the analyzed distribution build. |
| Human involvement | May involve an operator choosing and issuing tasks. | The design delegates a tactical routing choice to models, while the available actions remain encoded in the implant. |
| Operational evidence | Depends on evidence for the specific sample or campaign. | Talos confirmed the design through analysis but did not confirm deployment or a full end-to-end run. |
This distinction matters for defense: AI-provider traffic can be part of the C2 decision path without making model providers the malware’s entire control system. The implant still needs initial access, local capabilities, and a way to communicate results.
How can defenders look for it?
Talos recommends correlating endpoint activity with network behavior rather than treating contact with an AI service as sufficient evidence. Legitimate software can also use model APIs, so a single provider connection is not a reliable verdict.
- Investigate an unexpected Windows executable making API requests to multiple AI providers, especially when the same process or host shows other suspicious behavior.
- Correlate provider traffic with LSASS access, browser or wallet credential collection, process injection, or persistence creation.
- Look for Discord webhook communications alongside those endpoint and provider indicators.
- Check for repeated polling at randomized intervals of about five to fifteen minutes, as described in Talos’s analysis.
- Use process lineage, executable origin, network timing, and related host activity to distinguish a suspicious combination from legitimate applications that contact AI services.
The prompt content may be visible only through TLS inspection or provider-side telemetry, according to Talos. Blocking AI-provider domains alone is therefore not a complete defense: it may disrupt this design’s decision path, but does not establish that the endpoint is clean or address other access and capability routes.
What did Talos release alongside its analysis?
Talos says CLOSEDQUORUM was discovered through CAIRN, an open-source research toolkit for tracking AI-integrated malware. The project is relevant to defenders researching this category; consult Talos’s publication for the toolkit details and current terms.
Best Value
Source
Primary source: Cisco Talos, Ryan Fetterman, “The Closed Quorum: Inside the first reported autonomous AI C2 implant,” September 22, 2026.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

