By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ClosedQuorum Malware Uses AI for Attack Decisions
A novel Windows malware, identified as ClosedQuorum, has emerged, employing multiple artificial intelligence models to autonomously make decisions during the post-compromise phases of cyberattacks. This sophisticated malware utilizes large language models (LLMs) to analyze the compromised environment and determine the most effective actions, significantly increasing its adaptability and potential for evasion. The specific AI models integrated into ClosedQuorum include Google's Gemini, DeepSeek, Qwen, and Mistral AI. By incorporating these advanced AI capabilities, ClosedQuorum can move beyond pre-programmed attack sequences, enabling it to react dynamically to security measures and system configurations encountered after initial infiltration.
Researchers at Mandiant, a Google Cloud company, discovered ClosedQuorum. The malware's architecture allows it to download and execute these AI models locally, facilitating offline decision-making and reducing its reliance on external command-and-control servers. This local execution capability makes it more challenging to detect and disrupt. The AI models are used to process information gathered from the infected system, such as running processes, network configurations, and user privileges. Based on this analysis, the AI then selects subsequent actions, which could include escalating privileges, exfiltrating data, or deploying additional malicious payloads. This autonomous decision-making process represents a significant advancement in malware sophistication, moving away from static, script-driven attacks towards more intelligent and adaptive threats.
The integration of multiple LLMs provides ClosedQuorum with a diverse set of reasoning and decision-making capabilities. Each model may offer different strengths in analyzing specific types of data or generating strategic responses. This multi-model approach could also serve as a redundancy mechanism, ensuring that the malware can continue to operate effectively even if one model is compromised or its capabilities are limited in a particular scenario. The ability of ClosedQuorum to independently strategize and execute attacks without direct human intervention or constant external guidance marks a concerning development in the cybersecurity landscape, potentially leading to more persistent and damaging breaches. The threat actors behind ClosedQuorum are leveraging cutting-edge AI technology to enhance the efficacy and stealth of their malicious operations, posing a new challenge for cybersecurity defenses.
Mandiant's analysis indicates that ClosedQuorum's sophisticated use of AI for autonomous decision-making during post-compromise operations is a notable evolution in malware design. The malware's ability to download and run these models locally on the victim's machine is a key feature that enhances its resilience against detection and takedown efforts. This development underscores the growing trend of threat actors incorporating AI into their tools and techniques to create more potent and evasive cyber weapons. The specific LLMs identified—Gemini, DeepSeek, Qwen, and Mistral AI—are all powerful models capable of complex reasoning, which ClosedQuorum exploits to optimize its attack pathways and achieve its objectives with greater efficiency.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.