A quorum of models

Cisco Talos published research on Tuesday describing CLOSEDQUORUM, a Windows implant that decides what to do next by asking commercial AI models rather than waiting for a human operator. Talos calls it the first publicly documented Windows implant to apply that model to tactical command and control.

The distinction matters. Malware that calls an AI service to write a phishing lure still takes its orders from a person. According to Talos, this one does not: the implant “does not require continued commands from a human operator or tasking from a dedicated, attacker-operated C2 server,” and the complete dynamic operation is delegated to the AI.

How the vote works

CLOSEDQUORUM queries up to four commercial model providers in sequence — DeepSeek, Alibaba’s Qwen, Mistral and Google’s Gemini — and asks each one what the implant should do next. Each provider effectively casts a vote, and the majority decides which action runs. Where the vote is split, Talos says DeepSeek holds tiebreaker priority.

The design has an obvious operational logic: no attacker-controlled server to seize, no single provider whose account suspension kills the campaign, and a decision path that changes between runs because the models do.

Ethernet cables plugged into the ports of a network switch
Detection advice points at traffic patterns rather than blocked domains. Illustrative image. Vladimir Srajber · pexels · Pexels License

What it is built to steal

The implant’s capabilities are conventional credential theft. Talos describes LSASS memory dumping, extraction of saved passwords from Chrome, Edge and Firefox, and theft from cryptocurrency wallets including MetaMask, Exodus and Ethereum wallets. The novelty is not in what it takes but in who decides when to take it.

Not seen in the wild

This is a research find rather than an incident report, and Talos is explicit about the limits of what it knows. The company says it does not have confirmation of in-the-wild deployment. It tracked development builds over seven days, and says artefacts in the samples connect the developer to criminal forum activity dating back to 2025.

CLOSEDQUORUM surfaced through CAIRN, a research toolkit Talos released on the same day and describes as a project for hunting, classifying and tracking emerging AI-integrated malware. The tooling and the first finding were published together, which tells you how new the category is.

A laptop screen showing lines of program code
The implant targets saved browser passwords and crypto wallets. Illustrative image. Daniil Komov · pexels · Pexels License

Why this is awkward to detect

Talos recommends defenders focus on behavioural characteristics rather than domain blocking — the usual response of adding the command server to a blocklist does not apply when the command server is four public APIs that ordinary software also calls.

Instead it points to correlated indicators: API traffic to multiple AI providers from one host, combined with behaviour such as accessing LSASS, injecting into suspended processes, or creating WMI persistence. Any one of those is noise. Together they are a signature.

What to watch

Two questions follow. The first is what the four named providers do about traffic of this shape, given that their abuse teams can see the pattern from their side of the API. The second is whether CLOSEDQUORUM, or something built on the same idea, turns up in an actual intrusion — at which point the industry stops arguing about whether the category is real.