CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)

CLOSEDQUORUM (TL-2026-2753), also tracked as CLOSEDQUORUM, is a medium-severity malware campaign, first published 2026-09-22. It has no confirmed attribution, affects Microsoft Windows, maps to 22 MITRE ATT&CK techniques (T1003.001, T1005, T1027), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-2753

Threat ID
TL-2026-2753
Also known as
CLOSEDQUORUM, Closed Quorum, The Closed Quorum, BALZAK, win.closedquorum
Severity
MEDIUM
Status
MONITORING
Category
MALWARE
First published
2026-09-22
Last reviewed
2026-09-22
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, finance, cryptocurrency
Target regions
Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in CLOSEDQUORUM

Malware and tooling: BALZAK, CLOSEDQUORUM

Cisco Talos documents CLOSEDQUORUM (formerly BALZAK), a 16.4MB Go-based Windows implant that delegates tactical decisions (steal, inject, persist, move) to a panel of up to four commercial LLM providers (DeepSeek, Qwen, Mistral, Google Gemini) via plurality voting, acting without operator commands. It steals LSASS credentials, browser passwords and cryptocurrency wallets and exfiltrates AES-256-GCM encrypted data through Discord webhooks. No in-the-wild deployment has been confirmed; the public sample carries dummy API keys and webhook placeholders.

How CLOSEDQUORUM works

CLOSEDQUORUM (renamed from BALZAK on 2026-07-03) is a Windows implant written in Go with embedded C components for direct Windows system calls (CGO_ENABLED=1), 16.4MB, 64-bit. It replaces a conventional operator-controlled C2 channel with commercial LLM provider APIs. On each cycle it builds a TARGET context string (hostname, OS architecture, CPU count, Windows version, administrator status and the current process list) and sends the same prompt to up to four providers: DeepSeek, Qwen (reached via OpenRouter per secondary reporting), Mistral and Google Gemini. The embedded system prompt is "You are an advanced malware strategist. Provide ONLY executable decisions." Each model must answer with a JSON struct containing Decision (one of steal, inject, persist, move), Reasoning, target_process, exploit_type, evasion_method and payload_config. Providers are polled sequentially and aggregated in an interModelDiscussion() routine that tallies the Decision fields by plurality; ties are broken by a fixed provider priority (DeepSeek, then Qwen, then Mistral, then Gemini). If no consensus is reached (a "consensus" fallback string) the implant performs a no-op, sleeps and retries. Malformed, refused or rate-limited responses are discarded with no fallback execution.

Decision handlers: 'steal' runs lsassDump() (MiniDumpWriteDump with SeDebugPrivilege), dumpBrowserCredentials() (Chrome and Edge Login Data, Firefox logins.json) and extractCryptoWallets() (MetaMask extension storage, Exodus, Ethereum wallet paths), staging artifacts under C:\Windows\Temp\. 'inject' calls generateShellcode() and injects via Early Bird APC (default: create suspended process, write shellcode, NtQueueApcThread, resume) or process hollowing (PEB-walk, when the LLM returns process_hollow). 'persist' calls establishPersistence(), deploying an HKCU Run key value named WindowsUpdate, a scheduled task created with schtasks.exe, and a permanent WMI event subscription that fires every 60 seconds off a system performance query and executes a PowerShell script written to C:\Windows\Temp\wmi.ps1. 'move' has no handler in the distributed build.

Evasion: EtwEventWrite is overwritten with a RET to suppress ETW telemetry, a secondary payload is encrypted and keyed from system time (environmental keying), the implant waits 5 minutes before first activity and then polls at randomized 5-15 minute intervals, and persistence artifacts use Windows Update themed names.

Exfiltration: stolen data is encrypted with AES-256-GCM using a key derived from the current date (not hardcoded), base64-encoded, split into 1,900-byte chunks and posted to a compile-time configured Discord webhook at 1-second intervals. Each message also reports the winning decision, the LLM reasoning, target_process, exploit_type, evasion_method, payload_config, model name and timestamp to the operator. The developer builds customized binaries with the operator's credentials injected at compile time.

Status and attribution: the publicly distributed binary contains dummy_api_key and dummy_webhook_url placeholders and is an inert template that does not work out of the box; Talos also saw a build chain spanning about 7 days of iterative development. Talos performed static analysis only. Artifacts link the developer to criminal-forum postings related to carding dating to 2025. Malpedia's page lists UAT-11795, UAT-7810 and UAT-8302 only as related-reading entries from the same library, not as attributed actors, so no actor is assigned. The sample was classified with Talos's open-source CAIRN (Cognitive Artifact Intelligence Research Network) toolkit (RAT / LLM-tasked C2, tier T3, high confidence, archetype A4), released alongside the report. Talos frames CLOSEDQUORUM as evidence that attack-chain automation is arriving, with expanding portions of the chain executable without operator involvement. Defensive weaknesses in the design include provider refusals, rate limits, malformed output handling and the predictable tie-break order. Detection guidance favors correlating multi-provider LLM API calls from non-standard executables with LSASS access, process injection, WMI persistence and Discord webhook traffic, rather than blocking AI provider domains wholesale.

MITRE ATT&CK techniques used in TL-2026-2753

Credential Access

T1003.001 LSASS Memory; T1555.003 Credentials from Web Browsers

Collection

T1005 Data from Local System; T1074.001 Local Data Staging

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.004 Asynchronous Procedure Call; T1055.012 Process Hollowing; T1480.001 Environmental Keying; T1497.003 Time Based Checks

Exfiltration

T1030 Data Transfer Size Limits; T1567.004 Exfiltration Over Webhook

Persistence

T1053.005 Scheduled Task; T1546.003 Windows Management Instrumentation Event Subscription; T1547.001 Registry Run Keys / Startup Folder

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.001 PowerShell; T1106 Native API

Command and Control

T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CLOSEDQUORUM

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints (implant targets Windows version reported at runtime)

Remediation for CLOSEDQUORUM

Immediate actions

  • Hunt for the six published SHA256 hashes across EDR and file telemetry
  • Alert on non-browser, non-sanctioned processes contacting multiple LLM provider APIs (api.deepseek.com, api.mistral.ai, openrouter.ai, generativelanguage.googleapis.com) within short intervals
  • Alert on unsigned or unexpected processes posting to Discord webhooks
  • Hunt for HKCU Run value 'WindowsUpdate', unexpected schtasks.exe task creation and WMI permanent event subscriptions that launch C:\Windows\Temp\wmi.ps1

Workarounds

  • Do not block AI provider domains wholesale; legitimate enterprise applications depend on them. Scope controls to process and user context.

Longer-term hardening

  • Enable LSASS protection (RunAsPPL / Credential Guard) and alert on non-system processes opening LSASS with dump access
  • Monitor for EtwEventWrite tampering and process injection (Early Bird APC, process hollowing) in EDR
  • Restrict outbound access to LLM APIs and Discord to sanctioned applications and users via egress allowlists rather than blanket domain blocks
  • Use the CAIRN toolkit and the Talos-provided YARA rule to hunt AI-integrated malware

Timeline of CLOSEDQUORUM

  • Artifacts in the binary link the developer to criminal-forum postings related to carding dating to 2025 (exact date not published; year-level placeholder)
  • Secondary reporting (Tech Times) dates initial AI-integrated malware development by the developer to July 2025 (month-level, secondary source)
  • Talos static analysis of the binary confirms the embedded system prompt and the four-value Decision schema (steal, inject, persist, move)
  • The family is renamed from BALZAK to CLOSEDQUORUM in Talos tracking; the build chain shows roughly 7 days of iterative development
  • Malpedia adds the Talos report to its library under family win.closedquorum
  • Talos releases the open-source CAIRN toolkit (MIT, 26 tiered YARA rules), which classified the sample as LLM-tasked C2, tier T3, high confidence
  • Cisco Talos (Ryan Fetterman) publishes 'The Closed Quorum', describing CLOSEDQUORUM as the first reported autonomous AI C2 implant, with SHA256 hashes and a YARA rule
  • BleepingComputer, SC Media, Tech Times and others report on the implant; Talos notes no confirmed in-the-wild deployment and that the public build uses dummy API keys and webhook placeholders

Sources cited for CLOSEDQUORUM

More in malware

Detection coverage for TL-2026-2753

As of 2026-09-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2753 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats