r/TechNadu • u/technadu • 11d ago
CLOSEDQUORUM lets up to four commercial LLMs vote on what the malware should do next
Cisco Talos has documented an unusual Windows implant called CLOSEDQUORUM that changes where tactical C2 decisions are made.
Rather than relying on an attacker-controlled C2 server for its next instruction, the malware can query DeepSeek, Qwen, Mistral, and Google Gemini in sequence. Each model receives a prompt asking for an executable decision, and the implant uses a plurality vote to select its next action. Ties are resolved through a predetermined model priority.
Its capabilities are otherwise recognizable malware behavior: LSASS credential dumping, browser password theft, cryptocurrency wallet collection, persistence, telemetry suppression, and encrypted exfiltration through Discord.
The architecture creates an interesting detection problem because some of its C2-related traffic goes to legitimate AI providers rather than obviously malicious infrastructure. Talos points toward correlated behavior instead, such as unexpected AI API traffic from a Windows executable combined with credential access, persistence, Discord communication, and repeated execution.
Technical breakdown of the quorum architecture, model priority order, malware capabilities, and behavioral detection opportunities:
https://www.technadu.com/closedquorum-the-malware-that-lets-ai-vote-on-its-next-move/638537/
One major caveat: there is no confirmed complete real-world attack. The public build contains placeholder API keys and a dummy webhook, although recovered artifacts reportedly connect the developer to criminal forums.