The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

CLOSEDQUORUM: Malware Puts AI in the C2 Loop

Sep 28, 2026, 1:25:38 PM / by The Hivemind posted in Threat Bulletin, CLOSEDQUORUM, autonomous AI malware, AI malware, AI threat actors, LLM C2

0 Comments

Executive Summary

Cisco Talos has identified CLOSEDQUORUM, a Windows malware implant that delegates tactical command-and-control (C2) decisions to a panel of commercial large language models (LLMs), allowing portions of an intrusion to operate without continued human direction or a traditional attacker-controlled C2 server. The malware can query up to four LLM providers, including DeepSeek, Qwen, Mistral, and Google Gemini, to select among predefined malicious actions including credential theft, process injection, and persistence, while reporting decisions and stolen data through Discord. Although Talos has not confirmed CLOSEDQUORUM's deployment in the wild and the publicly distributed build is nonfunctional, the malware demonstrates how threat actors can use existing AI services to automate bounded portions of the attack chain and reduce their dependence on human operators.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts