Thursday Sep 24

Malware Takes Orders From Four AI Models

24SEP
NO OPERATOR4 VOTERSIMPLANT

Cisco Talos pulled apart a Windows implant with no operator behind it. Each step is decided by a majority of DeepSeek, Qwen, Mistral and Gemini. It has not been seen attacking anyone yet.

The sample is called CLOSEDQUORUM. Sixteen megabytes of Go. Its system prompt reads: you are an advanced malware strategist, provide only executable decisions. The models vote. DeepSeek breaks ties.

Choices on the ballot: steal, inject, persist, move sideways. Targets include LSASS credentials, browser passwords, and MetaMask, Exodus and Ethereum wallets. Loot leaves through a Discord webhook under AES-256-GCM.

Talos found dummy API keys in the public build, so this is a prototype, not a campaign. The author's handle traces back to carding forum posts. Talos shipped CAIRN, an open-source tracker for AI-driven malware, the same day.

full brief & sources

⚡ Why this matters

  • Command and control used to need a human and a server. This design removes both. The attacker rents judgment from four public model APIs.
  • Ryan Fetterman at Talos calls it effort displacement. The hard part of running an intrusion moves from the criminal to the model vendor's inference bill.
  • For anyone shipping an AI product, your API is now potentially someone's C2. Abuse detection just became a product requirement.

🔍 What happened

  • Cisco Talos published its analysis on September 22. CLOSEDQUORUM is a 16.4 MB Windows implant written in Go.
  • At each decision point the implant sends state to DeepSeek, Qwen, Mistral and Gemini. It executes whichever action wins a plurality. DeepSeek is the tiebreaker.
  • Actions include credential theft from LSASS, harvesting Chrome, Edge and Firefox passwords, and draining MetaMask, Exodus and Ethereum wallets. Data exfiltrates to a Discord webhook, encrypted with AES-256-GCM.
  • There is no attacker-controlled server. The malware behaves like a credentials-as-a-service pipeline that pays for its own brain by the token.
  • Talos has not observed the implant in the wild. The public build contains placeholder API keys. The developer's identity links to 2025 posts on a carding forum.
  • Talos also released CAIRN, an open-source framework for identifying and tracking malware that embeds LLM calls.

💬 Smart takes

  • Ryan Fetterman, Cisco Talos: the point is effort displacement. No operator, no C2 server, and the intrusion still adapts. The attacker's cost drops to API spend.
  • Help Net Security, on CAIRN: defenders now need to fingerprint LLM traffic patterns inside binaries the way they once fingerprinted beaconing.
  • Skeptic: four models voting on a plan is slower, louder and more expensive than a hardcoded playbook. Real crews optimize for quiet. This may be a proof of concept that never scales.

🧭 Where this goes

  1. Likelymodel providers add abuse signatures for malware-style prompts and start rate-limiting suspicious keys within weeks.
  2. Possiblea working variant appears in a real intrusion, using stolen API keys so the bill lands on a victim.
  3. Wild Carda court asks whether the model vendor whose output chose the action carries any liability.

🥄 The Spoon Take

The scary part is not the malware. It is the architecture. Four consumer APIs replaced the operator and the server, the two things defenders have spent twenty years learning to find. If your company sells inference, you are now part of someone's kill chain. Build the abuse team before the incident report forces you to.

🤔 Pushback

No victims, dummy keys, one sample. Treat this as a design sketch until CAIRN finds it running somewhere real.