🔒CLOSEDQUORUM Malware Uses LLMs to Decide Next Moves
Malware now uses AI to decide its next move
TL;DR
CLOSEDQUORUM malware leverages LLMs to autonomously decide its next actions, marking a new era in malware sophistication. It steals credentials and cryptocurrency wallets, operates without human control, and uses a quorum of LLMs to vote on actions.
CLOSEDQUORUM is the first malware to use LLMs for autonomous command-and-control (C2). It steals credentials and cryptocurrency wallets, operates without human control, and uses a quorum of LLMs to decide its next actions. This malware is a game-changer for security teams as it bypasses traditional detection methods by mimicking legitimate behavior. The quorum includes DeepSeek, Qwen, Mistral, and Gemini, with DeepSeek having the final say in case of a tie. If you're in security, this is a wake-up call.

Key Points
CLOSEDQUORUM malware steals credentials and cryptocurrency wallets, including MetaMask, Exodus, and Ethereum wallets.
The malware uses a quorum of LLMs to decide its next actions, with DeepSeek having the final say in case of a tie.
Operators receive AES-256-GCM encrypted stolen credentials via Discord, with daily rotating keys.
The malware can generate shellcode and use process hollowing or Early Bird injection to execute malicious code.
Detection focuses on behavioral characteristics, not domain blocking, as legitimate apps may contact DeepSeek, Mistral, Gemini, and Discord.
Why It Matters
Security teams must update their detection strategies to account for malware like CLOSEDQUORUM, which uses LLMs for autonomous decision-making. Traditional domain blocking is ineffective; behavioral analysis is key. This affects anyone using Discord, LLMs, or cryptocurrency wallets.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,488 builders reading daily.