The Malware That Puts Its Next Move to a Four-Model Vote

Cisco Talos disclosed a Windows implant on September 22, 2026 that does something researchers had been predicting and had not yet seen documented in the wild. Instead of pulling instructions from a server the attacker controls, it asks four commercial language models what to do next and then executes whichever answer wins.
The sample is called CLOSEDQUORUM. Talos describes the design as LLM-as-C2, and the label is accurate. The command-and-control infrastructure is a set of public APIs and a Discord webhook.
How the loop runs
CLOSEDQUORUM is a 16.4-megabyte, 64-bit Go binary. On a randomized interval between five and fifteen minutes, it collects basic host state, meaning the hostname, the Windows version, and whether the process is running with administrator rights. It sends that reconnaissance data to DeepSeek, Qwen, Mistral, and Google Gemini in turn.

Each model receives a system prompt that frames it as an advanced malware strategist and instructs it to return one action from a fixed set, in strict JSON. The four options are steal, inject, persist, and move. Responses that do not conform to the required schema are discarded rather than repaired. Whichever action collects the most votes across the four models is the one that runs.
Ties resolve through a fixed priority order. DeepSeek has the casting vote, followed by Qwen, then Mistral, then Gemini. If a provider is unavailable, the cascade moves down the list. If every model fails to return a usable answer, the implant sleeps and retries.
What the actions actually do
The three functional modules are conventional on their own, which is part of why the architecture matters.
Steal fires several things at once: LSASS memory dumping for credentials, browser credential theft across Chrome, Edge, and Firefox, and cryptocurrency wallet extraction targeting MetaMask, Exodus, and Ethereum wallets. Inject generates shellcode and deploys it through process hollowing or Early Bird APC injection. Persist installs redundant survival mechanisms through registry Run keys, scheduled tasks, and permanent WMI event subscriptions, and it suppresses ETW telemetry to reduce what defenders can see in their logs.
The fourth option, move, covers lateral movement, but the handler for it is absent in the build Talos examined. The implant can vote for lateral movement and then have nothing to execute, which is the kind of detail that suggests an unfinished tool rather than a mature one.
Everything collected gets encrypted, segmented, and exfiltrated through an operator-controlled Discord webhook. Each decision and the model's stated rationale are also logged to a Discord channel, which gives a human operator a running commentary without giving them control.
Why the architecture is the interesting part
Security researchers have spent two years documenting large language models migrating from developer tooling into the malware supply chain. Google's Threat Intelligence Group reported LLM-assisted self-obfuscation in the PROMPTFLUX family in November 2025. Later disclosures showed criminal and state-linked actors wiring live model APIs into malicious code so payloads could rewrite themselves or generate commands at runtime rather than shipping fixed logic. Microsoft has tracked JadePuffer, also known as Storm-3168, which Sysdig described in July 2026 as the first documented LLM-driven ransomware operation, and which Microsoft's later reporting showed had extended its activity into Azure, including a June 2026 attack on a tenant that used two compromised service principals.
CLOSEDQUORUM pushes that trajectory somewhere specific. Rather than using one model to obscure or generate a piece of code, it treats a panel of models as a standing authority for the whole intrusion lifecycle. Talos researcher Ryan Fetterman found the sample through CAIRN, an open-source toolkit the company released to hunt for AI-integrated malware by scanning metadata for prompt templates, provider endpoints, and orchestration logic rather than executing suspicious binaries. Using CAIRN, Fetterman identified roughly twenty additional examples of AI-integrated malware, which makes CLOSEDQUORUM look less like an anomaly and more like an early documented instance of a pattern.
The reason this weakens a real constraint is worth spelling out. Traditional malware has an infrastructure problem. An operator has to stand up command servers, protect them, and periodically task them, and investigators can seize them, sinkhole them, or subpoena their records. CLOSEDQUORUM's infrastructure is a handful of commercial AI APIs and a Discord webhook. Both are cheap, fast to replace, and trivial to abandon. There is no server to subpoena in a jurisdiction the attacker chose for its permissiveness. The model providers function as fourth parties who did not know they were participating, not as infrastructure the attacker owns or protects.
Talos used the phrase effort displacement to describe what the design buys. The goal is to remove the human operator as the bottleneck in the attack chain, so the loop can run at machine speed without anyone available to issue the next command, rather than to make that operator more efficient.
The limits, which are real
Talos is careful to state what it does not know, and the caveats matter more than the headline.
The publicly circulating sample is what the researchers call a lazy template. It ships with placeholder API credentials and a dummy Discord webhook, which means it cannot function as distributed. Talos did not observe a complete decision loop in operation and has no confirmation of in-the-wild deployment. The six SHA256 hashes the company catalogued span roughly a week of iterative development. Forensic artifacts in the binary connect its author to forum postings about carding and stolen payment card data going back to 2025, which points to a financially motivated individual rather than a nation-state program.
The reliance on commercial APIs is also a structural weakness. Rate limits, malformed model output, and temporary API unavailability can each break the chain at a critical moment, and an attacker who builds on someone else's endpoint has outsourced control over whether the attack continues.
Talos does not describe the implant as technically sophisticated. That assessment is probably right. The modules are ordinary, the injection techniques are well known, and the lateral movement handler is missing.
What defenders should take from it
The useful conclusion has little to do with LLM-directed malware being widespread in production right now. The blueprint is documented, a toolkit exists to find more of it, and roughly twenty similar samples turned up within the first pass.
For enterprise defenders, that suggests two practical adjustments. The first is egress monitoring aimed specifically at outbound calls from production hosts to commercial model provider endpoints, because a server that has no business reasoning about its own hostname should not be reaching one. The second is treating the decision log as a detection surface. CLOSEDQUORUM's use of a Discord webhook for both commentary and exfiltration is a convenience that also leaves a network signature, and the researchers found it by reading metadata rather than running the binary.
The uncomfortable part of the story is what it demonstrates rather than what it did. Even as a half-finished experiment with placeholder keys, CLOSEDQUORUM shows that the decision layer of an attack can now be assembled from services nobody controls, and that capability is documented and circulating regardless of whether this particular sample ever runs.
Related articles
Claude Sonnet 5.5 Is 30 Percent Cheaper. That Is a Procurement Story, Not a Model Story.
Vendor discount claims are usually measured against a representative workload, and yours is not representative.
HPE Just Sold $1.2 Billion of Hardware Because the Network Became the Point
A $1.2 billion order with an undisclosed split across five categories is not the same as $1.2 billion of margin.
Shopify Let AI Agents Press Buy. The Merchant Still Eats the Dispute.
The agent platform brokers the intent. The merchant carries the risk.
Does Copying Someone Else's AI Prompt Count as Infringement? A Ruling Keeps Prompts Outside Copyright
A recipe is not protected, but that does not mean the dish made from it is not protected.