Csoonline CLOSEDQUORUM: First Autonomous AI Malware Eliminates Human Oversight
Article Content
- •CLOSEDQUORUM is the first malware to fully automate C2 without human involvement.
- •It targets LSASS for credential dumping and extracts passwords from browsers.
- •No confirmed deployment in the wild, but it represents a significant evolution in cyber threats.
CLOSEDQUORUM is identified as the first malware utilizing a fully autonomous command and control (C2) architecture, discovered by Cisco Talos through their CAIRN project. This malware operates without human involvement, leveraging a panel of large language models (LLMs) to execute decisions aimed at stealing user credentials and crypto wallets. While there is no confirmation of its deployment in the wild, it represents a significant evolution in cyber threats, as it can continue operations independently of human oversight. The malware targets Microsoft’s Local Security Authority Subsystem Service (LSASS) for credential dumping and also extracts saved passwords from popular browsers. This shift in attack methodology allows for increased speed and scale, as human operators are no longer a limiting factor. The malware is compiled in Google’s Go programming language and supports multiple LLM integrations. The implications of this technology could reshape offensive cyber operations, necessitating new defensive strategies.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Bad Rabbit, Apt29 and Anchor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…