Back Theregister Windows CLOSEDQUORUM malware uses AI models to autonomously select post ...
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past 5 hours ago
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
Z.ai says sorry for slurping up your code, open sources ZCode 6 hours ago
Z.ai says sorry for slurping up your code, open sources ZCode
Register reader hit with surprise bill after Microsoft portals disagreed 9 hours ago
Register reader hit with surprise bill after Microsoft portals disagreed
Gartner predicts 55% of enterprise VMware users will be investigating an exit by 2029 19 hours ago
Gartner predicts 55% of enterprise VMware users will be investigating an exit by 2029
Perpetual underdog AMD nips at Nvidia's heels as it joins the $1T club 1 day ago
Perpetual underdog AMD nips at Nvidia's heels as it joins the $1T club
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’ credentials and cryptocurrency wallets.
Once deployed, the malware does not require continued commands from a human operator, according to Cisco Talos, which describes it as, to its knowledge, the first publicly documented Windows implant to use this approach for command-and-control (C2).
Talos discovered the binary with its new CAIRN (Cognitive Artifact Intelligence Research Network) toolkit for hunting, classifying, and tracking emerging AI-integrated malware, which the security shop also made available as an open source repository on Tuesday.
While the threat hunters haven’t observed any in-the-wild deployment of CLOSEDQUORUM, they said that artifacts from the binary link the malware’s developer to postings that date back to 2025 on criminal forums related to carding.
After deployment, the Go-based malware delegates its action to a quorum of LLMs that vote on what it should do . If the vote is tied, DeepSeek’s vote takes precedence, followed by Qwen, Mistral, and Gemini.
“The session is closed; no humans are admitted,” Talos analyst Ryan Fetterman said on Tuesday. “Four models are queried in sequence, their independent verdicts tallied, and the binary acts, based on their judgment.”
This type of “effort displacement,” which transfers a phase of the attack from a human operator to AI systems, can compound the speed and scale advantages of an intrusion by removing the human bottleneck, Fetterman added.
“Human operators are bound by attention, working hours, and cognitive load,” he wrote in the Tuesday blog. “An AI system capable of executing a phase of the attack chain can continue when the operator is no longer watching. It does not go offline when the attacker sleeps.”
The models’ decisions are limited to the pre-defined actions, and they must choose “ONLY executable decisions,” according to a system prompt that Talos’ researchers extracted from the binary. It tells each model: “You are an advanced malware strategist.”
And then the models choose what the malware should do from these capability modules:
Steal, which simultaneously runs commands to dump LSASS memory for Windows credentials, steal saved browser passwords across Google Chrome, Microsoft Edge, and Mozilla Firefox, and extract cryptocurrency wallet data including MetaMask, Exodus, and Ethereum.
Steal, which simultaneously runs commands to dump LSASS memory for Windows credentials, steal saved browser passwords across Google Chrome, Microsoft Edge, and Mozilla Firefox, and extract cryptocurrency wallet data including MetaMask, Exodus, and Ethereum.
Inject generates shellcode and then uses process hollowing or Early Bird injection to execute malicious code.
Inject generates shellcode and then uses process hollowing or Early Bird injection to execute malicious code.
Persist establishes persistence on the infected device.
Persist establishes persistence on the infected device.
Talos believes the developer provides each operator with a customized executable containing that operator’s Discord webhook and LLM API keys, which are injected at compile time.
Stolen credentials land in the operator’s Discord channel and are AES-256-GCM encrypted with a daily rotating key that the operator derives from the message timestamp.
According to Fetterman, the “most useful detection strategy” is to look at behavioral characteristics, not domain blocking.
“Legitimate applications may DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently,” he wrote. “Far fewer should several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence.”®
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
'first' publicly documented Windows implant to use LLMs for C2
Security firm finds naming AI agents after Seinfeld characters helps bots join the team
Not that there's anything wrong with it
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
This time it's personal
Your cloud survived everything except the real world
War damage, air traffic chaos, and a storage shortage expose the cost of treating resilience as someone else's problem
ABBYY gives old-school OCR a job in the AI pipeline
FineParser runs in a CPU-powered container, preserving tables and layout before handing documents to an LLM
SAAS Salesforce staggers back to feet after global outage
Salesforce staggers back to feet after global outage
databases Oracle celebrates banner quarter with another round of layoffs
Oracle celebrates banner quarter with another round of layoffs
Anthropic decides to support OpenAI's markdown instructions spec
Anthropic decides to support OpenAI's markdown instructions spec
Microsoft agentically ports Copilot runtime to Rust for $120K
Microsoft agentically ports Copilot runtime to Rust for $120K
ai and ml Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent
Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent
software Fedora 45 beta drags the Linux console into the 21st century
Fedora 45 beta drags the Linux console into the 21st century
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions 'first' publicly documented Windows implant to use LLMs for C2
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
'first' publicly documented Windows implant to use LLMs for C2
Z.ai says sorry for slurping up your code, open sources ZCode China’s AI darling goes on the defense after engineer highlighted Grok-esque security flaws
Z.ai says sorry for slurping up your code, open sources ZCode
China’s AI darling goes on the defense after engineer highlighted Grok-esque security flaws
UPDAted Register reader hit with surprise bill after Microsoft portals disagreed Did Copilot write the synchronization code?
Register reader hit with surprise bill after Microsoft portals disagreed
Did Copilot write the synchronization code?
Perpetual underdog AMD nips at Nvidia's heels as it joins the $1T club Fueled by the AI boom, the House of Zen's rise isn't just Instinct - Lisa Su is riding high on some Epyc design chops too
Perpetual underdog AMD nips at Nvidia's heels as it joins the $1T club
Fueled by the AI boom, the House of Zen's rise isn't just Instinct - Lisa Su is riding high on some Epyc design chops too
Treasury chief says AI bosses, not their bots, will carry the can for criminal acts 'Humans are responsible, not the AI,' argues Scott Bessent as he calls out OpenAI agents' hack of Hugging Face
Treasury chief says AI bosses, not their bots, will carry the can for criminal acts
'Humans are responsible, not the AI,' argues Scott Bessent as he calls out OpenAI agents' hack of Hugging Face
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user
KDE turns 30 and someone's brought an AI-native desktop proposal
Akademy talk imagines Plasma assembling itself around a personal model of each user
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
