CLOSEDQUORUM is a pioneering Windows implant identified by Cisco Talos that implements a fully autonomous command-and-control (C2) architecture. By utilizing a panel of commercial Large Language Models (LLMs)—including DeepSeek, Mistral, and Gemini—the malware delegates tactical decision-making to AI. This shift represents a significant move toward effort displacement, where the attack chain continues to progress without the need for constant human operator involvement.
Technically, the malware is a 64-bit Go executable that performs credential harvesting from LSASS, web browsers, and cryptocurrency wallets. It employs sophisticated techniques such as direct system calls, process hollowing, and APC injection, while utilizing Discord webhooks for data exfiltration. The 'LLM-as-C2' design allows the threat to bypass traditional domain-based blocking by communicating with legitimate AI provider endpoints.
Top comments (0)