{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/autonomous-malware/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["autonomous-malware","command-and-control","artificial-intelligence","windows","go"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eCLOSEDQUORUM is a 16.4MB, 64-bit Windows executable written in Go that introduces a novel 'LLM-as-C2' architecture, discovered by Cisco Talos during their CAIRN project. Unlike traditional malware that relies on a specific attacker-operated C2 server and protocol, CLOSEDQUORUM delegates its decision-making loop to a panel of up to four commercial Large Language Model (LLM) providers: DeepSeek, Qwen, Mistral, and Google Gemini.\u003c/p\u003e\n\u003cp\u003eThe implant follows a strict internal process where each model is queried, and the resulting actions are resolved via plurality voting. This architecture aims to bypass traditional network security controls by blending into legitimate traffic patterns directed toward common AI API endpoints. While current public builds contain placeholder API keys and dummy webhooks, the architectural design explicitly targets credential and cryptocurrency wallet harvesting. By offloading decision-making to external AI models, the implant achieves 'effort displacement,' allowing an operation to persist and evolve without continuous human operator interaction.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe malware executes on the host as a 64-bit Windows binary (Go and C mix, CGO_ENABLED=1).\u003c/li\u003e\n\u003cli\u003eThe 'ModelOrchestrator' component initializes API keys for DeepSeek, Qwen, Mistral, and Gemini.\u003c/li\u003e\n\u003cli\u003eThe implant triggers a four-provider query loop, invoking 'main.queryLLM' for each provider endpoint.\u003c/li\u003e\n\u003cli\u003eThe binary transmits structured prompts to these external APIs, constrained by a system prompt instructing the models to act as 'malware strategists'.\u003c/li\u003e\n\u003cli\u003eThe responses are collected and resolved via plurality voting (interModelDiscussion function) to select the next malicious task.\u003c/li\u003e\n\u003cli\u003eThe winning decision is executed locally, and the outcome is transmitted via a Discord webhook.\u003c/li\u003e\n\u003cli\u003eIf all models fail to return a valid decision, the malware enters a 'consensus' fallback state and triggers a retry loop.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eWhile no in-the-wild deployment has been confirmed, the capability of CLOSEDQUORUM demonstrates a shift toward autonomous malware that can perform credential and crypto-wallet harvesting without human-in-the-loop intervention. This increases the complexity of incident response, as detection must pivot from simple domain-based C2 blocking to identifying suspicious patterns of model interaction and API usage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy behavioral monitoring to detect persistent, low-frequency HTTPS traffic directed toward commercial AI model API endpoints from non-development/non-research endpoints. Monitor for Discord webhook traffic emanating from suspicious Windows processes. Organizations should scrutinize processes compiled with Go that exhibit CGO-based direct system call patterns for anomalous API interactions.\u003c/p\u003e\n","date_modified":"2026-09-22T14:01:30Z","date_published":"2026-09-22T14:01:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-closed-quorum/","summary":"CLOSEDQUORUM is a 64-bit Go-based Windows malware implant that uses an autonomous multi-LLM architecture to perform command and control via legitimate commercial API endpoints.","title":"CLOSEDQUORUM Autonomous AI C2 Implant Analysis","url":"https://feed.craftedsignal.io/briefs/2026-09-closed-quorum/"}],"language":"en","title":"CraftedSignal Threat Feed - Autonomous-Malware","version":"https://jsonfeed.org/version/1.1"}