CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)
CLOSEDQUORUM (TL-2026-2753), also tracked as CLOSEDQUORUM, is a medium-severity malware campaign, first published 2026-09-22. It has no confirmed attribution, affects Microsoft Windows, maps to 22 MITRE ATT&CK techniques (T1003.001, T1005, T1027), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-2753
- Threat ID
- TL-2026-2753
- Also known as
- CLOSEDQUORUM, Closed Quorum, The Closed Quorum, BALZAK, win.closedquorum
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- MALWARE
- First published
- 2026-09-22
- Last reviewed
- 2026-09-22
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, cryptocurrency
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in CLOSEDQUORUM
Malware and tooling: BALZAK, CLOSEDQUORUM
Cisco Talos documents CLOSEDQUORUM (formerly BALZAK), a 16.4MB Go-based Windows implant that delegates tactical decisions (steal, inject, persist, move) to a panel of up to four commercial LLM providers (DeepSeek, Qwen, Mistral, Google Gemini) via plurality voting, acting without operator commands. It steals LSASS credentials, browser passwords and cryptocurrency wallets and exfiltrates AES-256-GCM encrypted data through Discord webhooks. No in-the-wild deployment has been confirmed; the public sample carries dummy API keys and webhook placeholders.
How CLOSEDQUORUM works
CLOSEDQUORUM (renamed from BALZAK on 2026-07-03) is a Windows implant written in Go with embedded C components for direct Windows system calls (CGO_ENABLED=1), 16.4MB, 64-bit. It replaces a conventional operator-controlled C2 channel with commercial LLM provider APIs. On each cycle it builds a TARGET context string (hostname, OS architecture, CPU count, Windows version, administrator status and the current process list) and sends the same prompt to up to four providers: DeepSeek, Qwen (reached via OpenRouter per secondary reporting), Mistral and Google Gemini. The embedded system prompt is "You are an advanced malware strategist. Provide ONLY executable decisions." Each model must answer with a JSON struct containing Decision (one of steal, inject, persist, move), Reasoning, target_process, exploit_type, evasion_method and payload_config. Providers are polled sequentially and aggregated in an interModelDiscussion() routine that tallies the Decision fields by plurality; ties are broken by a fixed provider priority (DeepSeek, then Qwen, then Mistral, then Gemini). If no consensus is reached (a "consensus" fallback string) the implant performs a no-op, sleeps and retries. Malformed, refused or rate-limited responses are discarded with no fallback execution.
Decision handlers: 'steal' runs lsassDump() (MiniDumpWriteDump with SeDebugPrivilege), dumpBrowserCredentials() (Chrome and Edge Login Data, Firefox logins.json) and extractCryptoWallets() (MetaMask extension storage, Exodus, Ethereum wallet paths), staging artifacts under C:\Windows\Temp\. 'inject' calls generateShellcode() and injects via Early Bird APC (default: create suspended process, write shellcode, NtQueueApcThread, resume) or process hollowing (PEB-walk, when the LLM returns process_hollow). 'persist' calls establishPersistence(), deploying an HKCU Run key value named WindowsUpdate, a scheduled task created with schtasks.exe, and a permanent WMI event subscription that fires every 60 seconds off a system performance query and executes a PowerShell script written to C:\Windows\Temp\wmi.ps1. 'move' has no handler in the distributed build.
Evasion: EtwEventWrite is overwritten with a RET to suppress ETW telemetry, a secondary payload is encrypted and keyed from system time (environmental keying), the implant waits 5 minutes before first activity and then polls at randomized 5-15 minute intervals, and persistence artifacts use Windows Update themed names.
Exfiltration: stolen data is encrypted with AES-256-GCM using a key derived from the current date (not hardcoded), base64-encoded, split into 1,900-byte chunks and posted to a compile-time configured Discord webhook at 1-second intervals. Each message also reports the winning decision, the LLM reasoning, target_process, exploit_type, evasion_method, payload_config, model name and timestamp to the operator. The developer builds customized binaries with the operator's credentials injected at compile time.
Status and attribution: the publicly distributed binary contains dummy_api_key and dummy_webhook_url placeholders and is an inert template that does not work out of the box; Talos also saw a build chain spanning about 7 days of iterative development. Talos performed static analysis only. Artifacts link the developer to criminal-forum postings related to carding dating to 2025. Malpedia's page lists UAT-11795, UAT-7810 and UAT-8302 only as related-reading entries from the same library, not as attributed actors, so no actor is assigned. The sample was classified with Talos's open-source CAIRN (Cognitive Artifact Intelligence Research Network) toolkit (RAT / LLM-tasked C2, tier T3, high confidence, archetype A4), released alongside the report. Talos frames CLOSEDQUORUM as evidence that attack-chain automation is arriving, with expanding portions of the chain executable without operator involvement. Defensive weaknesses in the design include provider refusals, rate limits, malformed output handling and the predictable tie-break order. Detection guidance favors correlating multi-provider LLM API calls from non-standard executables with LSASS access, process injection, WMI persistence and Discord webhook traffic, rather than blocking AI provider domains wholesale.
MITRE ATT&CK techniques used in TL-2026-2753
Credential Access
T1003.001 LSASS Memory; T1555.003 Credentials from Web Browsers
Collection
T1005 Data from Local System; T1074.001 Local Data Staging
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.004 Asynchronous Procedure Call; T1055.012 Process Hollowing; T1480.001 Environmental Keying; T1497.003 Time Based Checks
Exfiltration
T1030 Data Transfer Size Limits; T1567.004 Exfiltration Over Webhook
Persistence
T1053.005 Scheduled Task; T1546.003 Windows Management Instrumentation Event Subscription; T1547.001 Registry Run Keys / Startup Folder
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.001 PowerShell; T1106 Native API
Command and Control
T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography
defense-impairment
Affected products and versions in CLOSEDQUORUM
- Microsoft — Windows
Vulnerable versions: Windows endpoints (implant targets Windows version reported at runtime)
Remediation for CLOSEDQUORUM
Immediate actions
- Hunt for the six published SHA256 hashes across EDR and file telemetry
- Alert on non-browser, non-sanctioned processes contacting multiple LLM provider APIs (api.deepseek.com, api.mistral.ai, openrouter.ai, generativelanguage.googleapis.com) within short intervals
- Alert on unsigned or unexpected processes posting to Discord webhooks
- Hunt for HKCU Run value 'WindowsUpdate', unexpected schtasks.exe task creation and WMI permanent event subscriptions that launch C:\Windows\Temp\wmi.ps1
Workarounds
- Do not block AI provider domains wholesale; legitimate enterprise applications depend on them. Scope controls to process and user context.
Longer-term hardening
- Enable LSASS protection (RunAsPPL / Credential Guard) and alert on non-system processes opening LSASS with dump access
- Monitor for EtwEventWrite tampering and process injection (Early Bird APC, process hollowing) in EDR
- Restrict outbound access to LLM APIs and Discord to sanctioned applications and users via egress allowlists rather than blanket domain blocks
- Use the CAIRN toolkit and the Talos-provided YARA rule to hunt AI-integrated malware
Timeline of CLOSEDQUORUM
- Artifacts in the binary link the developer to criminal-forum postings related to carding dating to 2025 (exact date not published; year-level placeholder)
- Secondary reporting (Tech Times) dates initial AI-integrated malware development by the developer to July 2025 (month-level, secondary source)
- Talos static analysis of the binary confirms the embedded system prompt and the four-value Decision schema (steal, inject, persist, move)
- The family is renamed from BALZAK to CLOSEDQUORUM in Talos tracking; the build chain shows roughly 7 days of iterative development
- Malpedia adds the Talos report to its library under family win.closedquorum
- Talos releases the open-source CAIRN toolkit (MIT, 26 tiered YARA rules), which classified the sample as LLM-tasked C2, tier T3, high confidence
- Cisco Talos (Ryan Fetterman) publishes 'The Closed Quorum', describing CLOSEDQUORUM as the first reported autonomous AI C2 implant, with SHA256 hashes and a YARA rule
- BleepingComputer, SC Media, Tech Times and others report on the implant; Talos notes no confirmed in-the-wild deployment and that the public build uses dummy API keys and webhook placeholders
Sources cited for CLOSEDQUORUM
- The Closed Quorum: Inside the first reported autonomous AI C2 implant (Cisco Talos, Ryan Fetterman)
- Malpedia library entry (family win.closedquorum)
- Cisco Talos CAIRN: Cognitive Artifact Intelligence Research Network
- New ClosedQuorum Windows malware uses AI for attack decisions (BleepingComputer)
- Researchers uncover malware that uses AI to choose its next move (Help Net Security)
- First 'autonomous AI C2 implant' uses panel of models to vote on next task (SC Media)
- Cisco Talos Discloses Autonomous Windows Malware: Four AI Models Direct Each Attack (Tech Times)
- CLOSEDQUORUM: An Autonomous Windows Implant Using Multiple LLMs for Attack Decisions (DEV Community)
- Talos releases CAIRN, uncovers LLM-voting malware CLOSEDQUORUM (AI Weekly)
More in malware
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
Detection coverage for TL-2026-2753
As of 2026-09-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2753 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.