AI malware just removed the human from the attack loop
Cisco Talos uncovers CLOSEDQUORUM, first 'LLM-as-C2' malware using multi-model judge panel to autonomously steal credentials and crypto wallets.
Cisco Talos's CAIRN research toolkit identified CLOSEDQUORUM, a 64-bit Go Windows binary described as the first 'LLM-as-C2' architecture that automates an entire attack phase without a human operator. A panel of LLMs (DeepSeek, Qwen, Mistral, Google Gemini) votes on next actions via constrained JSON decisions, with deterministic tie-breaking biased toward DeepSeek. It performs LSASS credential dumping, steals saved browser passwords from Chrome, Edge, and Firefox, and targets crypto wallets including MetaMask, Ethereum, and Exodus. Talos states there is no confirmation of CLOSEDQUORUM deployment in the wild, and simultaneously released CAIRN as an open-source toolkit for hunting AI-integrated malware via VirusTotal metadata.