Author: James Knight, Senior Principal and Lead Threat Intelligence Analyst, Digital Warfare
Introduction
Most malware today needs a human operator sending commands. Ransomware groups maintain dedicated command and control infrastructure precisely because their payloads need real-time instruction on what to do next, where to move, and when to trigger. That infrastructure is also where defenders catch them. Disrupt the C2 channel and the attack stalls.
CLOSEDQUORUM was built to sidestep that dependency entirely. Rather than calling back to an attacker-controlled server and waiting for instructions, the implant queries publicly available AI models and lets them vote on the next move. The attacker configures the malware once, deploys a customized copy, and then the software makes its own tactical decisions using commercial AI services that any developer or researcher legitimately accesses every day.
Cisco Talos researchers working on the CAIRN project, their initiative for tracking software that uses AI during attacks, identified and analyzed the implant. Their report was shared with CyberSecurityNews on September 23, 2026. The significance of CLOSEDQUORUM is not the scale of damage it has caused. No confirmed victims have been identified. Its significance is the design principle it demonstrates and the detection gap that principle creates for every enterprise running conventional signature-based or C2-blocking defenses.
This builds directly on the pattern we documented in the Digital Warfare 2026 Mid-Year Threat Pattern Report, which classified AI-augmented attacks as the fourth dominant threat pattern in 2026, accounting for 14 percent of confirmed incidents in our dataset between January and August.
How CLOSEDQUORUM Uses AI Models to Make Attack Decisions
When CLOSEDQUORUM runs on an infected Windows machine it begins by collecting basic information about the host: the operating system version, the processor count, and whether the process is running with administrator rights. This context is sent as a structured prompt to up to four AI models simultaneously.
The four models queried are DeepSeek, Qwen, Mistral, and Gemini. Each model receives a limited menu of action choices rather than an open invitation to generate any attack it can devise. This is a deliberate design decision. The author constrained the AI to selecting from a predefined list, which keeps the output predictable enough to parse and act on automatically while still outsourcing the tactical decision to an external reasoner.
Each model responds with a structured choice and the malware tallies the votes. The most popular choice wins. When two or more models return the same action, that action executes. When no clear winner emerges, a tie-breaking priority order applies starting with DeepSeek as the first preference. If no usable response arrives at all, the malware pauses and retries rather than acting on its own. The retry loop runs at irregular intervals of five to fifteen minutes following an initial delay, a timing pattern Cisco Talos noted specifically because it mimics legitimate background application behavior.
The actions available to the vote are: steal credentials from Windows login stores, saved browser passwords, and cryptocurrency wallet files; inject executable code into another running process to gain cover under a legitimate program; or establish a persistence mechanism that causes the malware to restart after a reboot.
A fourth listed action, lateral movement across a network, has no working handler in the distributed build Cisco Talos analyzed. That is an important qualification. The current public build cannot spread autonomously to other machines. The operator still chooses where to place a customized copy and still supplies the API keys needed to reach the AI models. The autonomous element is the tactical decision loop once the implant is running, not the initial compromise or the deployment.
Stolen material is transmitted through a Discord webhook. The implant uses a date-derived encryption key for its communications, a design choice Cisco Talos noted creates an additional complication: a developer with knowledge of the derivation method could decode any operator's collected data, effectively giving the author visibility into what operators steal.
Why CLOSEDQUORUM Represents a Genuine Shift in How Malware Can Evade Detection
Traditional malware detection relies on two overlapping approaches. The first is signature detection, matching known malicious code patterns, file hashes, or behavioral sequences against a database of confirmed threats. The second is C2 blocking, identifying and disrupting the network connections malware uses to receive commands from attackers. Both approaches share an assumption: that malicious traffic is identifiable either by what it looks like or by where it goes.
CLOSEDQUORUM challenges both assumptions in a specific and practical way. The code itself may not match any known signature because each customized copy the operator deploys is configured differently and the publicly available build contains placeholder values that will change before operational deployment. The network traffic the implant generates looks like legitimate API calls to commercial AI services because it is legitimate API calls to commercial AI services. A firewall rule blocking traffic to DeepSeek or Mistral would break a significant number of legitimate developer and business workflows for every organization using those tools.
Cisco Talos describes the detection approach that works: correlate the sequence of behaviors rather than looking for any single indicator. A Windows process making rapid successive connections to multiple AI provider APIs, then accessing Windows credential memory locations such as LSASS or the Windows Credential Manager, then injecting into a second process, then creating a registry run key for persistence, is a behavioral chain that does not describe any legitimate application. The IOCs Cisco Talos published confirm the specific file paths and registry locations: credential collection targets include logins.json for Firefox, the Login Data database used by Chrome and Edge, and exodus.wallet for the Exodus cryptocurrency wallet. Persistence is established via a registry value named WindowsUpdate under the current user's Run key, and staging occurs in C:\Windows\Temp\ before transmission via Discord webhook.
Where CLOSEDQUORUM Sits in the Digital Warfare AI Attack Classification
The Digital Warfare AI Augmentation Classification, developed from confirmed incidents in our 2026 dataset, identifies three maturity levels of AI-assisted attacks.
Level One is AI-assisted tool generation, where human attackers use large language models to create custom scripts or generate malware code. The vibe-coded Active Directory enumeration PowerShell script documented in July 2026 is a Level One example. The attacker wrote the prompt. The AI wrote the tool. A human still directed the attack in real time.
Level Two is AI-accelerated decision support, where AI helps human attackers analyze reconnaissance data, compress attack timelines, or prioritize targets faster than manual review allows. TeamPCP members confirmed to Forbes that they used AI in this capacity to accelerate their lateral movement scripting.
CLOSEDQUORUM is designed for something between Level Two and Level Three. It uses AI for real-time tactical decision-making during the attack itself, not in the planning phase before deployment. The attacker sets the menu of choices and deploys the implant, but from that point forward the AI models determine moment-to-moment behavior. JADEPUFFER, which we classified as the only confirmed Level Three example in our 2026 dataset as of the mid-year report, demonstrated fully autonomous multi-step attack execution including self-correction. CLOSEDQUORUM does not yet reach that threshold because the action menu is constrained, the lateral movement handler is not implemented, and the operator still chooses the initial deployment target. It is best understood as an early Level Three prototype that demonstrates the design architecture of fully autonomous AI malware without yet achieving it.
For the full framework see the DigitalWarfare AI Augmentation Classification and the JADEPUFFER analysis in our threat intelligence archive.
What Security Teams Should Do About CLOSEDQUORUM Today
The absence of confirmed victims does not make CLOSEDQUORUM a future problem. The design is documented, the code exists, and the operator model the author intended is clear. Security teams have a time-limited window to tune detection before a weaponized variant circulates or another actor implements the same architecture with working lateral movement.
Tune behavioral detection rules for the AI decision loop pattern. Work with your EDR and SIEM vendors to create detection logic that correlates rapid outbound connections to multiple AI provider APIs with subsequent credential access activity, process injection, or persistence creation within the same process context. No single indicator from that chain is malicious. The sequence is.
Update credential store monitoring. CLOSEDQUORUM specifically targets logins.json for Firefox, the Login Data database used by Chrome and Edge, and exodus.wallet files. Any process that is not a browser or a known credential manager accessing these files should generate an immediate alert.
Flag the specific registry persistence value. A registry value named WindowsUpdate created under HKCU\Software\Microsoft\Windows\CurrentVersion\Run by any process other than a Windows system component should be treated as suspicious. This is a known technique but the naming convention used by CLOSEDQUORUM specifically mimics legitimate Windows update behavior to avoid casual review.
Review Discord webhook egress in your environment. Discord webhook traffic from processes that are not the Discord desktop client warrants investigation. Staging files in C:\Windows\Temp\ before transmission is a secondary indicator. Neither is conclusive alone but both combined with the AI provider API connection pattern constitute a high-confidence detection signal.
Do not block AI provider domains at the network perimeter. Blocking DeepSeek, Mistral, Gemini, or OpenRouter at the firewall will create significant operational disruption for legitimate development and business workflows without meaningfully stopping an attacker who can route through a proxy or use a different model provider. Detection through behavioral correlation is the correct approach, not provider-level blocking.
For organizations that want expert assessment of their current detection capability against AI-augmented attack techniques, Digital Warfare red teaming services now incorporate scenario modules built from confirmed 2026 AI attack TTPs including agentic malware decision loops.
See our AI penetration testing services for organizations that want to assess whether their AI infrastructure could be abused in a similar architecture.
Key Takeaways
CLOSEDQUORUM is a Windows malware sample identified by Cisco Talos on September 23, 2026 that queries DeepSeek, Qwen, Mistral, and Gemini simultaneously, tallies their votes, and uses the winning response to decide whether to steal credentials, inject into a process, or establish persistence. No attacker command is required after deployment. No confirmed victims have been identified in the publicly available build, which contains placeholder credentials and a dummy reporting address. The detection challenge is real because the malware's outbound traffic consists of legitimate API calls to commercial AI providers that cannot be blocked without disrupting legitimate workflows. Detection requires correlating the behavioral sequence of AI API calls followed by credential access, process injection, or persistence creation rather than matching any single indicator. The Digital Warfare AI Augmentation Classification places CLOSEDQUORUM between Level Two and Level Three, representing an early architectural prototype of fully autonomous AI-directed malware that has not yet reached the operational autonomy of the JADEPUFFER case from July 2026. Security teams should tune behavioral detection rules today before a weaponized variant with working lateral movement appears.

