CLOSEDQUORUM: The Latest Sneaky Malware to Watch
Automated Deception with LLM Providers
Oi, take a look at this! The sly malware known as CLOSEDQUORUM queries up to four LLM providers – Google Gemini, DeepSeek, Qwen, and Mistral – to independently select from pre-defined dubious actions, such as stealing users’ credentials and cryptocurrency wallets. Cisco Talos believes this is the initial recorded Windows implant that employs this stealthy technique for command-and-control (C2). Once deployed, it no longer requires further commands from its human operator. Clever, right?
Uncovering the Cunning Intruder
Talos discovered this binary menace using their new CAIRN (Cognitive Artifact Intelligence Research Network) toolkit for hunting, categorizing, and tracking novel AI malware. They’ve even released this as an open source repository for anyone interested. However, they haven’t encountered CLOSEDQUORUM unleashed in the wild yet, but they estimate the developer has been discussing it on criminal forums since 2025.
LLMs Call the Shots
Once this Go-based malware is initiated, it allows a quorum of LLMs to determine its next sneaky action. If they can’t reach a consensus, DeepSeek takes the lead, followed by Qwen, Mistral, and then Gemini. “The session is closed; no humans are permitted,” Talos analyst Ryan Fetterman stated. This “effort displacement” accelerates their nefarious activities, eliminating the human bottleneck. AI doesn’t need any rest, after all!
Voting on Shady Choices
These LLMs are informed they’re “advanced malware strategists” and must select from the following shady options:
- Steal: Captures LSASS memory for Windows credentials, collects saved browser passwords, and extracts cryptocurrency wallet data including MetaMask, Exodus, and Ethereum.
- Inject: Creates shellcode and employs process hollowing or Early Bird injection to execute malicious code.
- Persist: Remains on the infected device like an unwelcome odor.
Identifying the Intruder
The developer provides each operator with a customized executable containing their Discord webhook and LLM API keys, integrated at compile time. Stolen credentials are sent to the operator’s Discord channel, encrypted with a daily rotating key. Fetterman notes the “most effective detection strategy” isn’t domain blocking but rather observing behavioral patterns. Legit apps might communicate with DeepSeek, OpenRouter, Mistral, Gemini, or Discord, but few will engage in all those activities while exploring LSASS or executing dubious injections.
Overview of the Cunning Intruder
Folks in Bytes: When AI Goes Off the Rails – Who would have imagined AI would be in control without a human nudge? This CLOSEDQUORUM is no fool; it’s a truly cunning intruder orchestrating actions with its LLM companions. We ought to stay alert for this crafty malware making its next play.
