{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/discord-webhook/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["malware","ai-agent","command-and-control","windows","discord-webhook"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCLOSEDQUORUM is a novel Windows implant that replaces traditional hardcoded C2 infrastructure with a voting mechanism utilizing commercial AI services, including DeepSeek, Qwen, Mistral, and Google Gemini. Discovered by Cisco Talos, the malware transmits system telemetry and a predefined list of actions to these models, proceeding with the action that receives the highest consensus. The malware supports actions such as credential theft, code injection, and establishing persistence.\u003c/p\u003e\n\u003cp\u003eAlthough the publicly analyzed samples include placeholder values for API keys and Discord webhooks, the design represents a shift toward delegating attack logic to external AI services. The malware maintains operational visibility by posting decisions and stolen data to a configured Discord channel via webhooks. Persistence is achieved through Windows Update-themed Registry keys, scheduled tasks, and WMI event subscriptions. Defenders should monitor for anomalous outbound traffic to AI API providers originating from unauthorized endpoints, particularly when coupled with indicators of LSASS access or suspicious process injection.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eExecution of the CLOSEDQUORUM binary on the host system.\u003c/li\u003e\n\u003cli\u003eCollection of system metadata, including hostname, OS version, and administrator status.\u003c/li\u003e\n\u003cli\u003eInitiation of HTTPS requests to multiple AI API providers (e.g., DeepSeek, Qwen) to request tasking based on the gathered metadata.\u003c/li\u003e\n\u003cli\u003eAggregation of AI model responses to determine the majority-voted action (steal, inject, or persist).\u003c/li\u003e\n\u003cli\u003eIf 'steal' is selected, the malware performs LSASS memory dumping and exfiltration of browser and crypto wallet credentials.\u003c/li\u003e\n\u003cli\u003eIf 'persist' is selected, the malware creates Registry Run keys, scheduled tasks, and WMI event subscriptions disguised as Windows Update processes.\u003c/li\u003e\n\u003cli\u003eExfiltration of stolen data, split into encrypted 1,900-byte chunks, to the attacker via a Discord webhook.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe malware is designed to facilitate credential theft, persistence, and potential code injection on compromised Windows hosts. While Cisco Talos noted that the publicly available samples are currently non-functional due to missing API credentials, the underlying capability demonstrates a sophisticated approach to autonomous C2 and command orchestration. Potential impact includes mass credential harvesting, persistent backdoor installation, and the risk of automated lateral movement or payload deployment based on model-driven decision-making.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize detection and response based on the behavioral patterns associated with CLOSEDQUORUM.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable monitoring for anomalous outbound HTTPS traffic to identified AI API providers (DeepSeek, Qwen, Mistral, Gemini, OpenRouter) from processes not authorized to interact with AI services.\u003c/li\u003e\n\u003cli\u003eImplement Sysmon or EDR rules to detect LSASS memory access (Event ID 10) by non-security processes.\u003c/li\u003e\n\u003cli\u003eMonitor for the creation of persistence mechanisms themed as 'WindowsUpdate' or similar system updates, specifically targeting the Run registry key and WMI event subscriptions.\u003c/li\u003e\n\u003cli\u003eInspect process creation logs for the execution of PowerShell scripts from paths within C:\\Windows\\Temp.\u003c/li\u003e\n\u003cli\u003eUtilize the provided SHA-256 hashes to hunt for dormant or staged samples across the enterprise environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T15:56:04Z","date_published":"2026-09-23T15:56:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-closedquorum-ai-malware/","summary":"CLOSEDQUORUM is a Windows malware that offloads C2 decision-making to a quorum of AI models, enabling automated execution of credential theft, process injection, and persistence mechanisms.","title":"CLOSEDQUORUM Windows Malware Leverages AI Voting for Command Execution","url":"https://feed.craftedsignal.io/briefs/2026-09-closedquorum-ai-malware/"}],"language":"en","title":"CraftedSignal Threat Feed - Discord-Webhook","version":"https://jsonfeed.org/version/1.1"}