A new Windows malware prototype has abandoned the traditional single command-and-control server for something far more unusual: a committee of AI models that vote on its next move. Cisco Talos researchers have identified this attack framework, named CLOSEDQUORUM, as a proof-of-concept that weaponizes a decentralized consensus mechanism among multiple large language models to direct its operations while evading security tools.
The core innovation lies in its architecture. Instead of receiving instructions from an attacker's server, CLOSEDQUORUM is designed to poll up to four independent AI services. It provides these models with stolen system context and data, then aggregates their responses to decide on malicious actions, such as harvesting Windows credentials, browser passwords, or cryptocurrency wallets. This "voting bloc" approach is a paradigm shift, moving beyond AI as a simple assistant to creating an adversarial, collaborative decision-making layer.
The primary tactical advantage for attackers is evasion. By routing its command traffic through legitimate, commercial AI APIs, the malware avoids the network signatures and known malicious domains that traditional security tools monitor. This infrastructure layering provides resilience; if one AI service blocks the request or a communication channel is severed, the malware may still receive operational directives from others in its decentralized cluster.
Cisco Talos noted that the analyzed sample is not yet functionally complete, and no full attack chain has been observed in the wild. However, its existence is a significant threat indicator. It demonstrates a clear roadmap for building adaptive, polymorphic malware that can generate unique, context-aware actions on the fly, making behavioral prediction and signature-based detection far more difficult.
This model also complicates attribution and response, as the malware's "brain" is distributed across multiple legitimate, cloud-hosted AI platforms. For defenders, this demands an evolution in security monitoring. The focus must shift from purely network-based detection to robust behavioral analytics on endpoints. Security teams will need to detect anomalous patterns of non-business software making sequential or unusual API calls to LLM services. Implementing stricter application control policies to govern access to AI APIs is becoming a critical new layer of defense.
The development signals that threat actors are actively researching ways to exploit the seam between powerful AI services and security boundaries. As these AI-native malware paradigms mature, defense strategies will increasingly depend on understanding the intent behind actions on a host, not just their known signatures, requiring greater investment in advanced endpoint detection and response (EDR) and AI-driven security operations.
一款新的 Windows 惡意軟件原型已放棄傳統的單一命令與控制伺服器,轉而採用更不尋常的方式:由一個人工智能模型組成的委員會,投票決定其下一步行動。Cisco Talos 研究人員已識別出名為 CLOSEDQUORUM 的攻擊框架,該框架將多個大型語言模型之間的去中心化共識機制武器化,用於指導其運作,同時躲避安全工具的偵測。
其核心創新在於架構設計。CLOSEDQUORUM 並非從攻擊者的伺服器接收指令,而是旨在輪詢最多四個獨立的人工智能服務。它向這些模型提供被盜取的系統上下文和數據,然後匯總它們的回應,以決定惡意操作,例如竊取 Windows 憑證、瀏覽器密碼或加密貨幣錢包。這種「投票集團」方法是一種典範轉移,將人工智能從簡單的助手,提升為構建對抗性、協作性的決策層。
對攻擊者而言,主要的戰術優勢在於規避偵測。通過將命令流量路由至合法的商業人工智能 API,該惡意軟件避開了傳統安全工具所監控的網絡特徵和已知的惡意域名。這種基礎架構分層提供了彈性;如果一個人工智能服務封鎖請求或通信渠道被切斷,該惡意軟件可能仍會從其去中心化叢集中的其他服務接收操作指令。
Cisco Talos 指出,目前分析的樣本尚未功能完整,且未在野外觀察到完整的攻擊鏈。然而,其存在本身已是一個重要的威脅指標。它清晰地展示了一條研發路線:建構能即時生成獨特、具上下文感知行為的自適應、多態惡意軟件,這將使得行為預測和基於特徵碼的偵測變得極為困難。
這種模式也增加了歸因和回應的複雜性,因為該惡意軟件的「大腦」分布於多個合法、託管在雲端的人工智能平台上。對於防禦者而言,這要求安全監控進行演進。重點必須從純粹基於網絡的偵測,轉向強大的端點行為分析。安全團隊將需要偵測非商業軟件向大型語言模型服務進行連續或異常 API 調用的異常模式。實施更嚴格的應用程式控制策略,以管理對人工智能 API 的訪問,正成為一個至關重要的新防禦層。
此發展表明,威脅行為者正積極研究如何利用強大人工智能服務與安全邊界之間的縫隙。隨著這些人工智能原生惡意軟件模式的成熟,防禦策略將越來越依賴於理解主機上行為背後的意圖,而不僅僅是其已知特徵碼,這要求在進階端點偵測與回應(EDR)及人工智能驅動的安全運營方面投入更多資源。
