Separate reports detail CLOSEDQUORUM and SectopRAT
Talos and FortiGuard separately documented CLOSEDQUORUM's AI majority-vote theft and SectopRAT's browser and crypto-wallet stealer.
Security Affairs reported on 24 September 2026 that Cisco Talos documented CLOSEDQUORUM, a Windows implant that sends host context to DeepSeek, Qwen, Mistral, and Google Gemini and acts on a majority vote among steal, inject, persist, or move, breaking ties toward DeepSeek. Its steal path collects LSASS credentials, saved passwords from Chrome, Edge, and Firefox, and wallets such as MetaMask and Exodus, then sends AES-256-GCM data through a Discord webhook; Talos said the public sample is inert with placeholder API keys while development builds embed real credentials, and linked artifacts found with the CAIRN toolkit to 2025 carding-forum posts. Separately, GBHackers reported on 30 September 2026 that FortiGuard analyzed SectopRAT, also known as ArechClient2, hidden after installation of tampered legitimate digital-audio software from an Italian vendor, with no evidence of a vendor supply-chain compromise and the malicious folder under C:\ProgramData. A scheduled ReportDump.exe loads a tampered FrameworkBase.dll that pulls in sdkcra.dll to decrypt the .NET RAT in memory; it contacts 98.142.252.140 on TCP 15847 with AES-encrypted JSON, supports 29 functions including screen capture and shell execution, and its DeployBrowserKey module steals browser credentials, cookies, payment data, and wallets including MetaMask, Exodus, and Electrum, with Binance-related fallback domains. The sources do not disagree: they describe two distinct campaigns that both target browser secrets and crypto wallets but use different loaders, command channels, and decision logic.
- On 2026-09-24, Security Affairs reported that Cisco Talos documented CLOSEDQUORUM, a Windows implant that sends host context to DeepSeek, Qwen, Mistral, and Google Gemini and executes a majority vote among steal, inject, persist, or move,…
- CLOSEDQUORUM's steal path dumps LSASS credentials, saved passwords from Chrome, Edge, and Firefox, and wallets such as MetaMask and Exodus, then exfiltrates AES-256-GCM data through a Discord webhook.
- Talos said the public CLOSEDQUORUM sample is inert with placeholder API keys, while development builds embed real credentials; it was found with the CAIRN toolkit and artifacts were linked to 2025 carding-forum posts.
- On 2026-09-30, GBHackers reported FortiGuard's analysis of SectopRAT, also known as ArechClient2, placed under C:\ProgramData after a tampered install of legitimate digital-audio software from an Italian vendor, with no evidence of a…
- A scheduled ReportDump.exe loads FrameworkBase.dll altered to pull in sdkcra.dll, which decrypts the .NET RAT in memory; the malware supports 29 functions, including screen capture, shell execution, and DeployBrowserKey theft of browser…
- SectopRAT's primary command server is 98.142.252.140 on TCP port 15847 using AES-encrypted JSON commands, with Binance-related fallback domains.
- The reports describe different malware families, researchers, and infrastructure and do not contradict each other.
Coverage timelineoldest first · each row is one article
- · 6d agoCLOSEDQUORUM, the malware that asks four AI models what to do next
Security Affairs· 74
Cisco Talos says CLOSEDQUORUM lets four commercial AI models vote on credential and wallet theft.
- · 17h agoSectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets
GBHackers· 60
SectopRAT hides in tampered legitimate software and steals browser credentials and crypto wallets.