← All posts / Research

No Humans Admitted: Inside CLOSEDQUORUM, the First Fully Autonomous AI Command-and-Control Malware

Cisco Talos open-sources CAIRN, a toolkit for hunting AI-integrated malware, and uses it to document CLOSEDQUORUM — a Windows implant that delegates its next move to a voting panel of four commercial LLMs, marking the first reported fully autonomous AI command-and-control architecture.

No Humans Admitted: Inside CLOSEDQUORUM, the First Fully Autonomous AI Command-and-Control Malware

For years, the reassuring line about AI-assisted cyberattacks was that a human operator always remained in the loop — directing the tooling, selecting targets, approving each step. On September 22, Cisco Talos published research that retires that assumption. A Windows implant the team calls CLOSEDQUORUM delegates the selection of its next action to a panel of commercial large language models and executes the resulting decision on its own. No operator commands. No dedicated attacker-controlled C2 server. Talos describes it as the first publicly documented Windows implant with fully autonomous command and control.

The disclosure arrived alongside the public release of CAIRN — the Cognitive Artifact Intelligence Research Network — an open-source toolkit Talos built to hunt exactly this class of threat. Together, they offer the clearest picture yet of what “effort displacement,” Talos’s term for transferring an entire phase of an attack from the human to the machine, actually looks like in shipping criminal tooling.

A voting panel where no human has a seat

CLOSEDQUORUM is a 16.4 MB, 64-bit Windows executable compiled in Go with C interop enabled for direct system calls. Its offensive feature set — credential dumping, process injection, persistence — is unremarkable by modern malware standards. The architectural choice that makes it unique is the treatment of LLM providers as the C2 infrastructure.

Traditional command and control requires the attacker to operate attributable, blockable infrastructure: a domain, an IP, a listener. Certificate transparency logs and threat intelligence feeds expose that infrastructure before it is ever used. CLOSEDQUORUM instead calls up to four commercial LLM endpoints — DeepSeek, Qwen, Mistral, and Google Gemini — the same APIs used by thousands of legitimate applications every day.

A component Talos calls the ModelOrchestrator queries each provider in sequence with a structured prompt containing host context: hostname, OS architecture, CPU count, Windows version, admin status, and the currently targeted process. The responses are deserialized into a typed decision structure and resolved through plurality voting — each model’s verdict increments a counter, and the highest count wins. The name is deliberate: a quorum is a decision-making body requiring a minimum number of participants, and this session is closed. Four models vote. Zero humans are admitted.

The system prompt extracted from the binary is blunt: “You are an advanced malware strategist. Provide ONLY executable decisions.” The LLM panel cannot answer in free-form text — it must emit a JSON object whose Decision field maps to a concrete capability, or the response is discarded entirely. The constrained vocabulary collapses an open-ended decision space into four executable verbs:

  • steal — simultaneously runs LSASS memory dumping, browser credential theft (Chrome, Edge, Firefox), and crypto wallet extraction (MetaMask, Exodus, Ethereum wallets)
  • inject — generates shellcode and either performs process hollowing via PEB traversal or Early Bird APC injection, with the exploit variant chosen from the model’s structured output
  • persist — establishes Registry Run keys, scheduled tasks, and a WMI event subscription that fires every 60 seconds
  • move — lateral movement, unimplemented in the distribution build

Ties are resolved by a deterministic priority order — DeepSeek first, then Qwen, Mistral, and Gemini — an artifact of the max-finding loop’s strict comparison. If every provider fails or refuses, the fallback decision is the literal string consensus, which has no capability handler; the implant sleeps and retries rather than acting recklessly. Each winning decision, along with the models’ reasoning, is relayed to the operator’s Discord webhook as real-time attack telemetry — a one-way feed, not a control channel.

Credentials-as-a-service, with autonomy as the upsell

Talos’s static analysis found that the publicly distributed binary is an inert template: API keys initialize to dummy_api_key and the webhook to dummy_webhook_url. Development builds, however, demonstrate compile-time injection of real provider credentials. The inferred business model is a customized executable per operator, with stolen data arriving in the operator’s Discord channel AES-256-GCM encrypted — though Talos notes the symmetric key is merely derived from the current date, meaning the developer can decrypt any operator’s exfiltrated loot. Artifacts from the binary link the developer to carding forum posts dating back to 2025. There is no confirmation yet of in-the-wild deployment.

The significance is the service’s differentiator: an operator who acquires CLOSEDQUORUM does not need to be online to run a campaign. As Talos puts it, the implant “does not go offline when the attacker sleeps.”

CAIRN: fingerprinting AI’s vestiges in malware

CLOSEDQUORUM was discovered through CAIRN, released September 21 as an open-source research toolkit. CAIRN is metadata-first: it extracts prompt templates, API keys, and jailbreak strings from binaries without executing them, then classifies and clusters samples by these AI fingerprints. The name borrows from the stacked stones hikers leave on trails — markers of a path.

The backstory is instructive. When CERT-UA documented the LAMEHUG implant polling a Qwen coder model via Hugging Face in July 2025, Talos researcher Ryan Fetterman expected “this big boom of AI-enabled malware.” A retrospective a year later turned up only about nine named families, several of them research proofs-of-concept. Building CAIRN to dig deeper, Fetterman found roughly twenty additional examples in a few months of use — the landscape, he told WIRED, is “a lot more complex and diverse than has been publicly reported.”

Why behavioral detection now beats domain blocklists

Autonomy cuts both ways. Provider refusals, rate limits, malformed output, a deterministic tie-breaking order, and dependence on commercial APIs all create failure modes defenders can exploit. And because the C2 is a set of legitimate API endpoints, domain blocking is nearly useless. Talos’s detection guidance is correspondingly behavioral: flag AI-provider API traffic originating from an unexpected Windows executable; watch for similar requests to several model providers within a short interval; treat combinations — one process touching LSASS and contacting multiple LLM providers and posting to a Discord webhook and re-executing on randomized 5–15 minute intervals — as the signal, since no single indicator identifies the architecture.

Talos frames CLOSEDQUORUM not as sophistication but as precedent: proof that removing the operator from a bounded phase of an intrusion is achievable today with ordinary API access and current commercial models. AI’s offensive impact has so far been measured in speed and scale. The third dimension — effort that displaces the human entirely — is now demonstrated, documented, and defensible against, and the window to build those defenses before autonomous operations mature is, for now, still open.