AI malware cuts humans out of C2 loop
Cisco Talos says it has identified CLOSEDQUORUM, a proof-of-concept implant that uses an LLM panel to drive an attack without a live operator.
A criminal campaign usually needs someone at the keyboard — an operator who reads output, picks a tool, and decides what to do next. Cisco Talos says it has found a malware sample that delegates that role to a panel of large language models, leaving a human to deploy the binary and then step aside. The research group calls the technique the first "LLM-as-C2" architecture it has seen that can fully automate the command-and-control chain.
The sample, named CLOSEDQUORUM, is described in a blog post from Cisco Talos. According to the researchers, the implant gathers verdicts from several models in sequence and acts on whichever action wins the most votes. Talos says there is not yet any confirmation that CLOSEDQUORUM has been deployed in the wild.
What the implant actually does
CLOSEDQUORUM targets credential theft on Windows systems. Its focus is Microsoft's Local Security Authority Subsystem Service (LSASS), the process that handles logins and password changes and enforces security policy. Dumping LSASS lets an attacker pull domain and local credentials out of memory.
The implant also goes after saved passwords in Chrome, Edge, and Firefox, and it hunts for crypto wallets including MetaMask, Ethereum, and Exodus. Those are the capabilities the model panel can select from as it works through a session.
Tactical knowledge is encoded directly as model-readable context, and the model's output is converted into an executable automatically. The binary is a 64-bit Windows executable compiled in Google's Go programming language, according to Talos. It supports up to four LLM integrations: DeepSeek, Qwen, Mistral, and Google Gemini.
The quorum votes, the binary obeys
After it is deployed, CLOSEDQUORUM queries the models one after another using a system prompt that reads, 'You are an advanced malware strategist. Provide ONLY executable decisions.' It then tallies the independent verdicts and acts on its goal of harvesting credentials and crypto wallets.
The model panel is not free to answer however it likes. Talos says responses are constrained to a defined JSON structure with a decision field that maps to a specific capability, and anything outside that structure is discarded.
“This design reduces the model’s output to a constrained set of executable choices,”
— Ryan Fetterman, security and threat researcher at Cisco Talos
If the votes tie, the malware follows a fixed preference order rather than asking a human to break the deadlock. Fetterman described that behavior in the same post, saying, "The tie behavior is fully deterministic and biased toward DeepSeek."
Running several models also softens the effect of any single model refusing a request, timing out, or returning a malformed answer. Talos says the arrangement "increases the likelihood of obtaining a valid decision, but does not guarantee one." A quorum can still form when one or more members are unresponsive or trip a guardrail. If every model fails, the implant treats that as consensus: the loop sleeps and retries instead of defaulting to action.
Why the operator can walk away
The central change, in Talos's telling, is that a phase of the attack no longer belongs to the operator. Fetterman framed the shift plainly in the blog post.
“This is not merely augmenting what an operator can accomplish in a session, but transferring an entire phase of the attack from the operator to the system,”
— Ryan Fetterman, security and threat researcher at Cisco Talos
Speed and scale compound once the human stops being the bottleneck, Fetterman noted. People have limits on working hours, attention span, and cognitive load; a system driving the session does not. "It does not go offline when the attacker sleeps," he said.
Talos describes the result as a credentials-as-a-service model. Someone who obtains the malware does not need to stay online to run a campaign — in Fetterman's words, "They deploy the binary, and the LLM panel runs the attack." He added that "This type of scaffolding approach could easily be translated and applied to other adversary objectives."
How Talos found it
CLOSEDQUORUM turned up through CAIRN, the Cognitive Artifact Intelligence Research Network. CAIRN is an open-source toolkit that Talos released for hunting, classifying, and tracking AI-integrated malware, and the group says it is metadata-first: it builds structured graphs of artifact relationships so human defenders can spot related families and infrastructure.
Under the hood, samples go to VirusTotal, which extracts and indexes static, dynamic, reputation, and behavioral metadata. AI-related artifacts are surfaced from content, behavior, URLs, labels, and resource metadata, and 12 targeted filters capture different classes of artifacts, covering APIs, prompts, frameworks, tooling, and runtimes. Findings are classified by artifact, behavioral context, and operational families; text is studied for semantic similarities and relationships; and VirusTotal maps infrastructure, variants, and campaign connections.
Talos says it has used CAIRN to hunt malware development since July 2025, and that the autonomous framework has changed quickly in that time. Fetterman put the pace this way: "The progression from ‘LLM as optional feature’ to ‘fully autonomous multi-model consensus orchestrator with no human operator’ filled in within a single calendar year."
Telltale signs in the logs
Talos lists specific hallmarks that defenders can look for. AI-provider API traffic that originates from unexpected Windows executables is one. Structured prompts containing context or capability language are another. Repeated execution at randomized five minute to 15 minute intervals shows up too, along with Discord webhook communication coming from the same process or host.
The researchers say intrusions are achievable with currently available models and what Fetterman called "ordinary API access" — no exotic tooling required.
The limits built into the design
Talos also points to weaknesses in the technique. Provider refusals, malformed outputs, predictable tie-breaks, constrained schemas, and a dependence on commercial APIs can each lead to attack failure. Fetterman summarized the trade-off: "Autonomy does not make the implant infallible; it exchanges some human limitations for model and infrastructure limitations."
He added that defenders are not chasing a finished capability. "The advantage for defenders is that this progression is still only beginning," Fetterman said.
Talos also notes that tradecraft is spreading. Scripts have been compiled into malware, and techniques like CLOSEDQUORUM are reaching threat actors with no connection to the original sample. "We may be in a fleeting window to observe AI transition," Fetterman wrote. "AI integration is becoming commonplace in all software."
- Four LLM integrations supported: DeepSeek, Qwen, Mistral, and Google Gemini.
- 12 targeted filters in CAIRN for classifying AI-related artifacts.
- Five to 15 minutes: the randomized interval at which the implant repeats execution.
- July 2025: the point from which Talos says it has used CAIRN to hunt malware development.
What it means for defenders
If decision-making can be pushed onto a model panel, the command-and-control server stops being the obvious place to break an intrusion. The evidence Talos lays out suggests defenders may need to watch API endpoints, prompt content, and the models themselves, not just the server an operator would normally connect back to. The sample's failure modes point the same direction: refusals, malformed outputs, fixed tie-breaks, tight schemas, and a reliance on commercial APIs are all places where the chain could be interrupted, and each of those is something a defender can observe.
The open question is timing. Talos says the progression from a model used as an optional feature to a fully autonomous multi-model orchestrator happened within a single calendar year, and that the techniques are already spreading to actors with no link to the original sample. If that pace holds, the window in which this behavior is still novel — and still worth building detections around — may not stay open long.
Sources
- CSO Online Original source
- blog post Also reporting
- Cognitive Artifact Intelligence Research Network Also reporting
- VirusTotal Also reporting
Continue Reading
Snorkel AI's $3.5B bet on training data
Snorkel AI raised $350 million at a $3.5 billion valuation, nearly tripling its worth as demand for AI training data surges.
AI Agents Expand the Identity Blast Radius
Contributed analysis from Token Security warns that agent autonomy can turn ordinary access grants into unpredictable attack paths.
US, China Weigh AI Incident Alert Channel
Treasury Secretary Scott Bessent says Washington proposed an AI incident notification mechanism ahead of Trump-Xi talks Thursday.