CYOPS · Cyber Operations

CLOSEDQUORUM does not remove the C2 chokepoint. It hands it to four vendors.

Cisco Talos has published an implant that puts its next action to a vote across four commercial language model providers. The architecture is new; the sample has never been seen deployed; and the defensive consequence is narrower than the framing suggests.

An implant that asks four vendors what to do next

Cisco Talos published analysis of CLOSEDQUORUM on 22 September 2026, written by Ryan Fetterman and produced through the team's new CAIRN research project [1][2]. The described artefact is a 16.4 MB, 64-bit Windows executable written in Go. It queries up to four commercial language model providers in sequence, DeepSeek, Qwen, Mistral and Google Gemini, constrains their replies to a typed JSON decision schema, and aggregates the results by plurality vote on the Decision field [1]. Ties are broken deterministically, in the order DeepSeek, Qwen, Mistral, Gemini [1][4].

Four decision values exist: steal, inject, persist and move. The lateral movement handler is absent from the distribution build [1][4]. The implemented paths cover credential theft from LSASS, saved browser passwords, and cryptocurrency wallet material; process injection; and persistence through registry run keys, scheduled tasks and WMI event subscriptions [1]. Results leave over a Discord webhook, AES-256-GCM encrypted with a key derived from the current date [1].

The caveat belongs at the top, not the bottom. Talos writes: “While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025” [1]. The public build “contains placeholder API keys and a dummy webhook, so we did not observe a complete end-to-end execution of the architecture” [1]. Talos published a YARA rule and six development-build hashes, and no Snort or endpoint product coverage, which is consistent with an artefact nobody has seen deployed [1].

What is actually new

Talos's own wording is narrower than the headline. The body of the report claims CLOSEDQUORUM is, to the team's knowledge, the first publicly documented Windows implant to apply this model to tactical command and control [1]. Three qualifications sit in that sentence: platform, public documentation, and tactical scope.

Malware taking executable commands from a remote model is fourteen months old. LAMEHUG, also tracked as PROMPTSTEAL, was reported by Ukraine's CERT in July 2025 and assessed by researchers as APT28 tooling used against Ukrainian government targets. It called Qwen2.5-Coder-32B-Instruct through the Hugging Face API and ran the Windows command chains the model returned [10]. Help Net Security notes that CAIRN's initial retrospective hunts reach back to that sample as the earliest known case [5]. PromptLock, published by ESET in August 2025, generated and executed Lua at runtime from a locally hosted model, was assessed a proof of concept, and was later traced to an academic research prototype that had reached VirusTotal [11]. Akamai documented in November 2025 a remote access trojan whose command channel was deliberately shaped to look like an OpenAI-compatible chat completions endpoint, with no model behind it at all [12].

What appears genuinely undocumented before this is the quorum: delegating action selection to a vote across several commercial providers, against a constrained decision schema, with a deterministic tie-break. Nothing in Google's threat intelligence reporting, Unit 42's sample study or Anthropic's most recent report describes an implant doing that [7][9][16].

The chokepoint moves; it does not vanish

Talos frames the architectural change plainly: “Instead of a singular, unique C2 server, CLOSEDQUORUM calls up to four commercial LLM provider endpoints used by thousands of legitimate applications daily” [1]. The volume argument is real and measurable. Zscaler recorded 989.3 billion AI and machine learning transactions from around 9,000 organisations across 2025, an 83 per cent year-on-year increase spread over more than 3,400 applications [14]. Netskope found the median organisation's weekly AI usage rising from 34 to 59 per cent of users, with median weekly prompt volume tripling from 1,498 to 4,731 [15]. Blocking model provider domains is no longer available as a control in most enterprises.

But the stronger claim, that the command channel has become unblockable, does not survive contact with the design. Four providers and one chat platform are five third parties the operator does not control and cannot repair. RuntimeWire records the resulting failure modes: provider refusals, rate limits, service outages, invalid JSON and a predictable tie-break can each stall or distort the decision process, and cites Expel's assessment that end-to-end autonomous attacks still depend on pipelines and direction built by people [6]. The honest formulation is that the chokepoint has been transferred rather than destroyed. The defender loses domain blocking. The providers gain a revocation point the operator does not hold.

The technique class is not new either. MITRE ATT&CK T1102, Web Service, already describes adversaries relaying command traffic through legitimate external services precisely because hosts are already communicating with them before a compromise, and lists proxy-enforced restriction of unauthorised external services as mitigation [13]. What has changed is that the service class in question is one most enterprises finished allow-listing this year.

The base rate, and the counterweight

Unit 42 analysed 405 unique AI-integrated malware samples in research published on 25 August 2026. Roughly 97 per cent, 393 of them, existed only in sandboxes and on VirusTotal; twelve reached protected endpoints and all were caught [7]. The conclusion: “None of the AI-linked samples required a new detection method to be identified and blocked”, and “The AI component does not evade detection. It changes how the code is authored, not how it executes” [7][8].

The counterweight is about tempo, not efficacy. Google's Threat Intelligence Group reported on 8 September 2026 that in the second quarter of 2026 it observed actors compromise a cloud resource and then plan, build and execute an agent-enabled mass credential harvesting campaign in under six hours [9]. Anthropic's September 2026 report documents operations in which agents autonomously modified and rebuilt malware to evade existing detections, and one case in which stolen provider API keys were automatically substituted for the operator's own [16].

That last detail matters here more than any other. CLOSEDQUORUM's analysed build is inert because it has no credentials. Stolen model provider keys are already a traded commodity. The gap between a capability demonstration and a working tool is an API key.

Detection

The usable signal is correlation, not destination. Fetterman's formulation, reported by The Register, is the operative one: far fewer legitimate applications should contact several model providers while also accessing LSASS, injecting into suspended processes, or creating WMI persistence [3]. Talos recommends behavioural detection rather than blocking model providers outright [1][6].

CAIRN itself is the more durable output of the week. It is a metadata-first toolkit with a three-tier YARA taxonomy: primitive AI artefacts, behavioural context, and family attribution from confirmed operational fingerprints [2]. Unite.AI counts 26 rules in the published repository, nine at each of the first and third tiers and eight at the second [17]. A reproducible method outlives any single sample.

What to do

  • Inventory which model provider endpoints your estate legitimately reaches, and from which processes. A category-level allow rule is not an inventory [14][15].
  • Alert on co-occurrence: model provider egress from a process that also touches LSASS, performs injection, or writes WMI subscriptions [3].
  • Treat Discord webhook traffic from servers and non-user endpoints as an exfiltration signal in its own right [1][13].
  • Protect model provider API keys as credentials of record. Their theft is what makes this design work [16].
  • Do not re-tool for AI malware. On the published evidence, existing behavioural controls caught every AI-integrated sample that reached an endpoint [7][8].

Domain close

One gap is worth stating as a gap. Across national CERT and vendor guidance reviewed for this article, we could not identify published guidance addressing outbound enterprise traffic to model provider APIs as a malware detection control. The nearest available instruments are Talos's behavioural correlation advice and a ten-year-old ATT&CK mitigation [1][13]. That is a thin shelf for a traffic class that is now measured in the hundreds of billions of transactions a year. The test for CLOSEDQUORUM is simple and not yet met: whether any incident response team recovers a working, credentialed variant from a live intrusion. Until then it is a design, published in full, in a field where designs have historically taken about a year to reach someone's network.

Sources

Every R3KONX article cites its primary material. 17 sources, in order of first citation. Links open the original publication.

  1. The Closed Quorum: Inside the first reported autonomous AI C2 implant Cisco Talos · 2026-09-22
  2. Introducing CAIRN: Frontier tracking for AI-integrated malware Cisco Talos · 2026-09-22
  3. Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions The Register · 2026-09-22
  4. New ClosedQuorum Windows malware uses AI for attack decisions BleepingComputer · 2026-09-22
  5. Researchers uncover malware that uses AI to choose its next move Help Net Security · 2026-09-22
  6. Cisco Talos finds malware taking orders from a four-model committee RuntimeWire · 2026-09-22
  7. The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution Unit 42, Palo Alto Networks · 2026-08-25
  8. AI Speeds Up Malware Development, Not Its Success Rate: Analysis SecurityWeek · 2026-08-26
  9. GTIG AI Threat Tracker: From Prompting to Autonomy - The Evolution of Adversarial AI Google Threat Intelligence Group · 2026-09-08
  10. LameHug: The First Publicly Documented Case of a Malware Integrating a LLM Picus Security · 2025-08-11
  11. First known AI-powered ransomware uncovered by ESET Research ESET WeLiveSecurity · 2025-08-26
  12. What We Do In The Shadow (AI): New Malware Strain Vamps Up Akamai · 2025-11-18
  13. Web Service, Technique T1102 MITRE ATT&CK · 2025-04-15
  14. Zscaler 2026 AI Security Report: 83% year-over-year surge in AI activity Zscaler · 2026-01-27
  15. Netskope AI Report: 2026 Netskope Threat Labs · 2026-08-04
  16. Countering misuse of AI: September 2026 threat intelligence report Anthropic · 2026-09-01
  17. Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware Unite.AI · 2026-09-22

This article was researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveat: CLOSEDQUORUM has not been observed in a live intrusion. Cisco Talos analysed a distribution build carrying placeholder credentials and did not observe end-to-end execution, so every description of the implant's behaviour here is static analysis rather than incident observation, and is attributed to Talos throughout. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.