blog

CLOSEDQUORUM: Talos details a Windows implant that lets four commercial models vote on its next move, in a public build shipped with placeholder keys

Cisco Talos published its analysis of CLOSEDQUORUM on 22 September 2026. The implant is a Windows program written in Go that asks up to four commercial language models what to do next, counts their answers, and does whatever wins. The four are DeepSeek, Qwen, Mistral and Google Gemini. Talos calls it, "to our knowledge, the first publicly documented Windows implant to apply this model to tactical command and control (C2)."

The same write-up's opening summary says "While we do not have confirmation of in-the-wild deployment." The build Talos could see publicly is what it calls "an inert template": every provider key is set to dummy_api_key and the Discord webhook to dummy_webhook_url. "The binary is non-functional as distributed," Talos writes. With those placeholders it cannot reach a model or send anything out.

The code is also older than the news. Talos's family report dates the six known builds from 29 December 2025 to 6 January 2026, and the YARA rule in the blog post records its static analysis on 17 June 2026. Talos went public more than eight months after the last build.

Four models vote, and DeepSeek breaks ties

The implant's system prompt, as Talos extracted it, is one line: "You are an advanced malware strategist. Provide ONLY executable decisions." Each cycle it sends the models a description of the host (hostname, Windows version, CPU count, admin status) and a fixed menu. The answer has to come back as JSON naming one of four decisions: inject, persist, steal or move. Anything that does not parse is thrown away.

The winning decision is posted to the operator's Discord webhook before it runs, so the operator reads what the models chose rather than issuing commands.

The handlers themselves are ordinary malware. steal runs three things at once: a full-memory LSASS dump, a copy of the saved-password stores for Chrome, Edge and Firefox, and a sweep for MetaMask, Exodus and Ethereum keystore wallets. inject does Early Bird APC injection or, if a model asks for it, process hollowing. persist sets up a Run key, a scheduled task and a WMI subscription, all named after Windows Update. move has no code behind it. A model can vote for lateral movement, Discord will report move as the decision, and nothing runs.

Talos's two documents disagree about ties. The 22 September blog post walks through the decompiled vote-counting loop and concludes the tie behaviour is "fully deterministic and biased toward DeepSeek," with Qwen, Mistral and Gemini behind it in that order. The family report, last updated 4 August, said "no tie-breaking logic beyond map iteration order." The blog post is the later document.

If every model fails, the fallback decision is the string consensus, which maps to no handler, so the implant sleeps and tries again. Talos treats that as a weakness: "Autonomy does not make the implant infallible; it exchanges some human limitations for model and infrastructure limitations."

No attacker server to block

A conventional implant calls back to a server the attacker controls, and that server's domain or address is what defenders block. CLOSEDQUORUM talks only to model providers and Discord. The family report lists api.deepseek.com, openrouter.ai, api.mistral.ai and generativelanguage.googleapis.com. Qwen is reached through OpenRouter rather than Alibaba's own API, the Gemini call names gemini-2.0-flash-exp, and stolen files leave through a Discord webhook.

Talos does not suggest blocking those services. "Legitimate applications may contact DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently," its post says. "Far fewer should contact several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence." The combination to look for is AI-provider traffic from an unexpected Windows executable, similar requests to several providers close together, repeating on the implant's randomised 5 to 15 minute polling interval, on a host that also shows one of those three behaviours.

The exfiltration is easier still to spot: base64 in Discord code blocks, 1,900 bytes a message, one message a second. By the family report's arithmetic one full LSASS dump becomes tens of thousands of messages over many hours, and the report calls that channel "the family's most exploitable weakness."

On the host, the report lists these artefacts:

  • lsass.dmp, chrome_logins.db, edge_logins.db, firefox_logins.json, a crypto\ folder and wmi.ps1 under C:\Windows\Temp\
  • a WindowsUpdate value under the current user's Run key that points outside %SystemRoot%
  • a WMI filter named WindowsUpdateFilter with a consumer named WindowsUpdateConsumer
  • the first byte of ntdll!EtwEventWrite patched to 0xc3, which silences ETW telemetry from the process

The four providers hold the most leverage. The prompt says "malware strategist" in plain English, and each operator's keys are compiled into that operator's build. The report notes that the implant "is inert without at least one working provider," so revoking a build's keys disables that build. The developer left their own DeepSeek and Gemini keys in a test build called gohno-final.exe, which Talos says "should be assumed revoked." Neither Talos document reports any response from DeepSeek, Alibaba, OpenRouter, Mistral or Google.

The report reads the wallet list as aimed at "a developer or AI-practitioner workstation," where browser sessions, cached corporate credentials and crypto holdings sit on one machine. It lists the delivery vector as unresolved. The blog post says artefacts in the binary tie the developer to carding posts on criminal forums going back to 2025, and that the implant "appears to operate as an operator-configured service," with a custom build for each operator. The family report is more cautious: "Treat 'CLOSEDQUORUM is sold' as an open question, not a finding."

CAIRN is MIT-licensed, but its content searches need VirusTotal Intelligence

Talos found CLOSEDQUORUM with CAIRN, a hunting toolkit it announced and open-sourced the same day at github.com/Cisco-Talos/Cognitive-Artifact-Intelligence-Research-Network under the MIT licence. It never downloads or runs a sample. It builds text from VirusTotal's metadata for a file (AV labels, embedded URLs, sandbox DNS lookups) and runs YARA rules over that text, looking for provider endpoints, API key prefixes and hardcoded prompts. The README lists 26 rules and ten published families, CLOSEDQUORUM among them.

The installation steps mark a VirusTotal API key as required, and the README adds that "a VirusTotal Intelligence subscription is required for content-based search queries." The repository ships without Talos's database of findings "due to copyright." The README says a user with a VirusTotal key can rebuild it from the published report hashes and acquisition filters. The indicators and the YARA rule printed in Talos's blog post need none of that.

The evidence is one developer's template, last built in January, with no confirmed victims and a move command that does nothing. It is still enough to show that an implant's command channel can be four ordinary API accounts. On a Windows fleet, the list of programs allowed to call model APIs is now worth reviewing with that in mind.

Primary evidence