blog
CLOSEDQUORUM: Talos details a Windows implant that lets four commercial models vote on its next move, in a public build shipped with placeholder keys
Published . True as of that date; aging is not a defect.
Cisco Talos published its analysis of CLOSEDQUORUM on 22 September 2026. The implant is a Windows program written in Go that asks up to four commercial language models what to do next, counts their answers, and does whatever wins. The four are DeepSeek, Qwen, Mistral and Google Gemini. Talos calls it, "to our knowledge, the first publicly documented Windows implant to apply this model to tactical command and control (C2)."
The same write-up's opening summary says "While we do not have confirmation of
in-the-wild deployment." The build Talos could see publicly is
what it calls "an inert template": every provider key is set to
dummy_api_key and the Discord webhook to dummy_webhook_url. "The binary is
non-functional as distributed," Talos writes. With those placeholders it cannot
reach a model or send anything out.
The code is also older than the news. Talos's family report dates the six known builds from 29 December 2025 to 6 January 2026, and the YARA rule in the blog post records its static analysis on 17 June 2026. Talos went public more than eight months after the last build.
Four models vote, and DeepSeek breaks ties
The implant's system prompt, as Talos extracted it, is one line: "You are an
advanced malware strategist. Provide ONLY executable decisions." Each cycle it
sends the models a description of the host (hostname, Windows version, CPU
count, admin status) and a fixed menu. The answer has to come back as JSON
naming one of four decisions: inject, persist, steal or move. Anything
that does not parse is thrown away.
The winning decision is posted to the operator's Discord webhook before it runs, so the operator reads what the models chose rather than issuing commands.
The handlers themselves are ordinary malware. steal runs three things at
once: a full-memory LSASS dump, a copy of the saved-password stores for
Chrome, Edge and Firefox, and a sweep for MetaMask, Exodus and Ethereum
keystore wallets. inject does Early Bird APC injection or, if a model asks
for it, process hollowing. persist sets up a Run key, a scheduled task and a
WMI subscription, all named after Windows Update. move has no code behind
it. A model can vote for lateral movement, Discord will report move as the
decision, and nothing runs.
Talos's two documents disagree about ties. The 22 September blog post walks through the decompiled vote-counting loop and concludes the tie behaviour is "fully deterministic and biased toward DeepSeek," with Qwen, Mistral and Gemini behind it in that order. The family report, last updated 4 August, said "no tie-breaking logic beyond map iteration order." The blog post is the later document.
If every model fails, the fallback decision is the string consensus, which
maps to no handler, so the implant sleeps and tries again. Talos treats that
as a weakness: "Autonomy does not make the implant infallible; it exchanges
some human limitations for model and infrastructure limitations."
No attacker server to block
A conventional implant calls back to a server the attacker controls, and that
server's domain or address is what defenders block. CLOSEDQUORUM talks only
to model providers and Discord. The family report lists api.deepseek.com,
openrouter.ai, api.mistral.ai and generativelanguage.googleapis.com.
Qwen is reached through OpenRouter rather than Alibaba's own API, the Gemini
call names gemini-2.0-flash-exp, and stolen files leave through a Discord
webhook.
Talos does not suggest blocking those services. "Legitimate applications may contact DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently," its post says. "Far fewer should contact several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence." The combination to look for is AI-provider traffic from an unexpected Windows executable, similar requests to several providers close together, repeating on the implant's randomised 5 to 15 minute polling interval, on a host that also shows one of those three behaviours.
The exfiltration is easier still to spot: base64 in Discord code blocks, 1,900 bytes a message, one message a second. By the family report's arithmetic one full LSASS dump becomes tens of thousands of messages over many hours, and the report calls that channel "the family's most exploitable weakness."
On the host, the report lists these artefacts:
lsass.dmp,chrome_logins.db,edge_logins.db,firefox_logins.json, acrypto\folder andwmi.ps1underC:\Windows\Temp\- a
WindowsUpdatevalue under the current user's Run key that points outside%SystemRoot% - a WMI filter named
WindowsUpdateFilterwith a consumer namedWindowsUpdateConsumer - the first byte of
ntdll!EtwEventWritepatched to0xc3, which silences ETW telemetry from the process
The four providers hold the most leverage. The prompt says "malware
strategist" in plain English, and each operator's keys are compiled into that
operator's build. The report notes that the implant "is inert without at least
one working provider," so revoking a build's keys disables that build. The
developer left their own DeepSeek and Gemini keys in a test build called
gohno-final.exe, which Talos says "should be assumed revoked." Neither Talos
document reports any response from DeepSeek, Alibaba, OpenRouter, Mistral or
Google.
The report reads the wallet list as aimed at "a developer or AI-practitioner workstation," where browser sessions, cached corporate credentials and crypto holdings sit on one machine. It lists the delivery vector as unresolved. The blog post says artefacts in the binary tie the developer to carding posts on criminal forums going back to 2025, and that the implant "appears to operate as an operator-configured service," with a custom build for each operator. The family report is more cautious: "Treat 'CLOSEDQUORUM is sold' as an open question, not a finding."
CAIRN is MIT-licensed, but its content searches need VirusTotal Intelligence
Talos found CLOSEDQUORUM with CAIRN, a hunting toolkit it announced and open-sourced the same day at github.com/Cisco-Talos/Cognitive-Artifact-Intelligence-Research-Network under the MIT licence. It never downloads or runs a sample. It builds text from VirusTotal's metadata for a file (AV labels, embedded URLs, sandbox DNS lookups) and runs YARA rules over that text, looking for provider endpoints, API key prefixes and hardcoded prompts. The README lists 26 rules and ten published families, CLOSEDQUORUM among them.
The installation steps mark a VirusTotal API key as required, and the README adds that "a VirusTotal Intelligence subscription is required for content-based search queries." The repository ships without Talos's database of findings "due to copyright." The README says a user with a VirusTotal key can rebuild it from the published report hashes and acquisition filters. The indicators and the YARA rule printed in Talos's blog post need none of that.
The evidence is one developer's template, last built in January, with no
confirmed victims and a move command that does nothing. It is still enough
to show that an implant's command channel can be four ordinary API accounts.
On a Windows fleet, the list of programs allowed to call model APIs is now
worth reviewing with that in mind.