$ techbeacon▋
Darkweb

AI‑Powered Malware Shifts Command Decisions from Humans to Large Language Models

AI‑Powered Malware Shifts Command Decisions from Humans to Large Language Models

Security researchers have identified a Windows‑based malware implant dubbed CLOSEDQUORUM that replaces the traditional human operator with a commercial large language model to direct its malicious activities. By delegating tactical choices to an AI‑driven voting system, the code creates an autonomous command‑and‑control (C2) channel that can issue instructions without direct human input.

The implant initiates contact with an external language‑model service, transmitting encoded data about its host environment. The model then processes a series of prompts that simulate a consensus‑building process among virtual “voters,” each representing a potential action such as data exfiltration, lateral movement, or persistence. The chosen outcome is returned to the malware, which executes the command on the compromised machine.

Talos, the threat‑research arm of Cisco, disclosed the findings after analyzing a sample obtained from the open‑source community. While the researchers have not observed CLOSEDQUORUM in the wild, they caution that its architecture could lower the barrier for less‑skilled actors to launch sophisticated campaigns, as the AI service handles decision‑making that would normally require expert knowledge.

The emergence of AI‑enabled threats follows a broader trend of cybercriminals repurposing publicly available artificial‑intelligence tools for illicit purposes. Earlier this year, ransomware groups began using AI‑generated phishing content to increase success rates, and deep‑learning models have been employed to evade detection by security products. CLOSEDQUORUM represents a shift from using AI as a helper for content creation to embedding it directly into the operational core of malware.

Experts warn that the use of off‑the‑shelf language models for C2 could complicate detection efforts, as network traffic may appear to be legitimate queries to popular AI platforms. Defenders are urged to monitor anomalous outbound requests to AI service endpoints and to incorporate behavioral analytics that can spot the characteristic voting‑loop pattern. As the line between automated tools and malicious actors blurs, the security community will need to adapt its threat‑intel pipelines to account for AI‑mediated command structures before such techniques appear in active campaigns.

Source: GBHackers
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related