Cisco Talos researchers have unveiled the first known instance of an autonomous AI Command and Control (C2) implant called CLOSEDQUORUM. This malicious software uses a sophisticated ensemble of four AI models—DeepSeek, Alibaba's Qwen, Mistral, and Google's Gemini—to determine its next steps. The discovery was made possible by Cisco Talos's Cognitive Artifact Intelligence Research Network tool, which was launched alongside the report.
CLOSEDQUORUM is designed to operate on Windows systems, targeting credentials and cryptocurrency wallets. Unlike traditional C2 frameworks that communicate directly with attacker-controlled domains, this malware uses commercial large language model APIs to generate decisions in JSON format. These decisions act as votes for actions like stealing data, injecting malware, or maintaining persistence. The action with the most votes is executed, and in cases of a tie, a predefined order of models is used to decide.
The malware communicates with its operators via a Discord server, sending attack telemetry and encrypting stolen data using AES-256-GCM before exfiltration. Although Cisco Talos found placeholder API keys and a sample Discord webhook URL in the code, indicating the malware has not yet been deployed, the potential for future exploitation remains significant.
The report suggests that this AI-driven C2 system could be marketed as a service to cybercriminals, allowing them to integrate their own API keys and webhook URLs. The use of legitimate platforms like AI services and Discord presents unique challenges for traditional security measures that rely on domain-based defenses.
Ryan Fetterman, a Cisco Talos Security Researcher, noted that the autonomous nature of this system shifts bottlenecks from human limitations to model and infrastructure dependencies. However, reliance on third-party APIs also introduces vulnerabilities, such as the risk of model rejections or account suspensions, which could disrupt the malware's operations.

