Skip to content
CLOSEDQUORUM: First Autonomous AI Malware Eliminates Human Oversight

CLOSEDQUORUM: First Autonomous AI Malware Eliminates Human Oversight

First seen 23 Sep 2026, 00:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 01:59 UTC
  • CLOSEDQUORUM is the first malware to fully automate C2 without human involvement.
  • It targets LSASS for credential dumping and extracts passwords from browsers.
  • No confirmed deployment in the wild, but it represents a significant evolution in cyber threats.

CLOSEDQUORUM is identified as the first malware utilizing a fully autonomous command and control (C2) architecture, discovered by Cisco Talos through their CAIRN project. This malware operates without human involvement, leveraging a panel of large language models (LLMs) to execute decisions aimed at stealing user credentials and crypto wallets. While there is no confirmation of its deployment in the wild, it represents a significant evolution in cyber threats, as it can continue operations independently of human oversight. The malware targets Microsoft’s Local Security Authority Subsystem Service (LSASS) for credential dumping and also extracts saved passwords from popular browsers. This shift in attack methodology allows for increased speed and scale, as human operators are no longer a limiting factor. The malware is compiled in Google’s Go programming language and supports multiple LLM integrations. The implications of this technology could reshape offensive cyber operations, necessitating new defensive strategies.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-01-01
CLOSEDQUORUM development begins
Development of CLOSEDQUORUM was linked to postings on criminal forums related to carding.
Blog.Talosintelligence
2026-09-22
CLOSEDQUORUM disclosed
Cisco Talos published findings on CLOSEDQUORUM, detailing its autonomous C2 capabilities.
Blog.Talosintelligence
2026-09-23
CSO Online reports on CLOSEDQUORUM
CSO Online highlighted the implications of CLOSEDQUORUM's autonomous capabilities and its potential impact.
Csoonline

More articles in this cluster (4)

Following this threat?

Track Bad Rabbit, Apt29 and Anchor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed