First Autonomous AI C2 System Uses Ensemble Models for Task Voting

www.news4hackers.com-first-autonomous-ai-c2-system-uses-ensemble-models-for-task-voting-first-autonomous-ai-c2-system-uses-ensemble-models-for-task-voting

Cisco Talos researchers identified the first documented instance of an “autonomous AI C2 implant” leveraging a four-model ensemble to determine malicious activities.

Discovery of CLOSEDQUORUM

Cisco Talos researchers identified the initial documented instance of an “autonomous AI C2 implant” leveraging a four-model ensemble comprising DeepSeek, Alibaba’s Qwen, Mistral, and Google’s Gemini to determine subsequent malicious activities. The malware, named CLOSEDQUORUM, was disclosed in a report released Tuesday. Its discovery was facilitated by the Cisco Talos open-source Cognitive Artifact Intelligence Research Network (CAIRN) tool, also launched on the same day.

Malware Functionality

CLOSEDQUORUM functions as a Windows-based implant targeting credential and cryptocurrency theft. Unlike conventional command-and-control (C2) frameworks, which rely on direct communication with attacker-controlled domains, this malware interacts with four commercial large language model (LLM) application programming interfaces (APIs). It generates prompts instructing the models to act as “advanced malware strategists” and provide only executable decisions in structured JSON format. These responses are interpreted as votes for actions such as “steal,” “inject,” or “persist.”

Execution Mechanism

Each action triggers specific malware modules: for example, the “steal” function executes lsassDump(), dumpBrowserCredentials(), and extractCryptoWallets() routines. The implant executes the action with the highest vote count, defaulting to a predefined hierarchy in case of ties—DeepSeek first, followed by Qwen, Mistral, and Gemini if prior models fail to respond or return invalid JSON.

Telemetry and Exfiltration

Attack telemetry, including model reasoning outputs, is transmitted to an adversary’s Discord server via webhook. Stolen data is similarly exfiltrated after encryption using AES-256-GCM and base64 encoding. Cisco Talos confirmed the discovered binary contained placeholder API keys for model providers and a sample Discord webhook URL, indicating the implant was not yet deployed in active campaigns.

LLM-as-C2 Architecture

Researchers posited that the “LLM-as-C2 architecture” could be offered as a service to cybercriminals, with individual operators integrating their own API keys and webhook URLs during compilation. The reliance on legitimate platforms like commercial AI services and Discord complicates traditional domain-based defenses.

Human Intervention Reduction

The report highlighted that this approach introduces a novel layer to AI-driven attacks by minimizing human intervention. “Effort displacement compounds the effects of speed and scale because the human-in-the-loop is no longer the bottleneck,” noted Ryan Fetterman, a Cisco Talos Security Researcher. “An AI system can operate continuously without interruption,不受限于 human attention spans or work schedules.”

“Autonomy does not render the implant infallible; it shifts limitations from human constraints to model and infrastructure dependencies,” the report concluded.

Vulnerabilities and Risks

The design also introduces vulnerabilities. Dependency on third-party APIs exposes attackers to risks such as model rejections, rate limits, or account takedowns, which could disrupt operations.


Blog Image

About Author

en_USEnglish