Two days ago, Cisco Talos published their analysis of something they're calling CLOSEDQUORUM — and the name is more honest than most threat research headlines.
It's a Windows implant. Built in Go. 16.4MB. And once it's deployed, it doesn't need anyone to tell it what to do next.
Instead, it queries four commercial AI models — DeepSeek, Qwen, Mistral, and Google Gemini — and picks its next attack action by plurality vote. Whichever move gets the most votes, that's what runs. Harvest credentials here. Sweep for a crypto wallet there. Move laterally. Exfiltrate. The committee decides.
Talos describes this as, to their knowledge, the first Windows implant to fully delegate tactical C2 decisions to a panel of LLMs. No human operator. No dedicated command-and-control server for defenders to track and block. The attack logic lives in the AI models, and the models are queried through legitimate commercial APIs.
What they found and what they didn't
To be clear about where this is: Talos has not confirmed real-world deployments. The public build they analyzed ships with dummy API keys — it's a template, not an active campaign. But they connected the binary's artifacts to criminal forum postings going back to 2025, with ties to carding operations. This isn't theoretical research from a university lab. Someone built this to use it.
The delay between "tool built" and "tool deployed" has been shrinking all year. August's CrowdStrike threat report clocked average time-to-deployment at under 72 hours for newly discovered malware kits. The reason to pay attention now is to have a response ready before your organization is in the incident report.
Why this is different from the AI malware you've already read about
Most AI-assisted malware this year has been AI-assisted, not AI-operated. Attackers use LLMs to write the phishing email. They use code generation to create a novel variant. The human still runs the campaign — the AI is just a productivity tool for the attacker.
CLOSEDQUORUM's architecture is different. The human deploys the implant. After that, they're out of the loop. The implant reasons through its situation — what access it has, what defenses it's seeing, what moves are available — and votes on what to do next.
What this breaks:
Human-operated C2 monitoring. Security tools that look for command-and-control traffic based on timing, beacon patterns, or known C2 infrastructure have a hard time with this. The implant's "decisions" come from API calls to DeepSeek, Qwen, Mistral, and Gemini — the same APIs your developers are using. The traffic looks like legitimate AI tool usage.
Response time assumptions. Traditional attacker dwell times involve humans reviewing results, planning next steps, waiting for their operations window. When the decision-making is automated, that buffer compresses. From initial compromise to credential harvest could happen in a single overnight window while your IT person is asleep.
The "small enough to not be a target" assumption. Autonomous campaigns scale horizontally. This kind of implant can run against thousands of targets simultaneously — not because the attacker has thousands of people, but because they have API credits. A 15-person nonprofit and a mid-size logistics company face the same threat, because the attacker's cost to add you to the campaign is basically zero.
The defensive tool they shipped alongside it
This is the part most coverage missed. Talos didn't just disclose the threat — they open-sourced CAIRN at the same time. CAIRN (Cognitive Artifact Intelligence Research Network) is a detection toolkit built specifically for AI-integrated malware.
What it does: scans binaries and artifacts for the fingerprints of AI integration — prompt templates embedded in the binary, API endpoint strings, jailbreak language patterns, model-specific formatting. It does this statically, without executing the binary. The idea is to catch AI-integrated malware at the point of initial discovery, before it runs.
CAIRN is free. It's on GitHub. It runs on Windows, Linux, and Mac. If your organization has a security practice that includes scanning new software or scanning for indicators of compromise on endpoints, this is worth adding to that toolkit today.
A practical starting point: run CAIRN against any Go or Python binaries that have appeared on your systems in the last 90 days that you can't account for. Binaries in user temp directories, downloaded tools, anything that arrived outside your standard software delivery channel.
Three things to do this week
The response here doesn't require a security team or an enterprise budget.
1. Audit your API key exposure. CLOSEDQUORUM targets credential harvesting specifically. Your team's AI API keys — OpenAI, Mistral, Anthropic, whatever you're using — are high-value targets. Where are those keys stored? Are they in .env files that are committed to repos? Are they in a password manager or a shared Notion doc? The credential sweep that CLOSEDQUORUM runs will look for exactly this. Take an hour this week and map where your API keys actually live.
2. Pull CAIRN and run it on your endpoints. The GitHub repo is here. Even if you have no reason to think you're already compromised, running a baseline scan now tells you what "clean" looks like — which matters a lot when you're trying to assess an incident six months from now.
3. Check your monitoring for AI API traffic. If you have any network monitoring, add alerting on outbound traffic to DeepSeek, Qwen, Mistral, and Gemini endpoints from endpoints where you haven't deployed those tools. That's the pattern CLOSEDQUORUM uses to communicate. Most small orgs aren't running those models internally, so unexpected outbound calls to their APIs from a staff laptop or server would be a meaningful signal.
The longer arc
What's happening here is a transition from "AI helps attackers do their jobs faster" to "AI is the attacker." The human's role is increasingly limited to initial deployment and collecting results. The campaign runs itself.
That's not a 2027 concern. It's a September 2026 concern, with a functional proof-of-concept already linked to criminal infrastructure.
The practical response for a small org isn't to build a threat hunting program from scratch. It's to close the most obvious exposure points — loose credentials, unmonitored outbound API calls, software running on your systems that you can't identify — and use the free tools the research community is building, like CAIRN, to stay current.
Small teams that move in the next two weeks are ahead of this. Teams that wait for their IT vendor to send a newsletter about it aren't.
If you want to walk through what CAIRN turns up on your systems or map your credential exposure, we do that in a single sprint. Takes a day, not a quarter.
Sources: Cisco Talos blog · Help Net Security · The Hacker News · Unite.AI on CAIRN