A newly discovered Windows malware, ClosedQuorum, is leveraging commercial AI models to autonomously orchestrate the critical post-compromise phase of an attack. Instead of relying on human operators for strategic decisions, the malware queries systems from Google, DeepSeek, Qwen, and Mistral to plan its next steps, representing a significant shift in how adversaries approach complex network intrusions.
Analysis by BleepingComputer identifies ClosedQuorum as a payload activated after initial access. Its core innovation lies in its command mechanism. As it executes on a compromised host, it gathers contextual intelligence on the environment—network configuration, installed software, and user activity. This data is fed as prompts to APIs of multiple commercial LLMs, which the malware uses as an on-demand advisory panel. The AI models suggest tactical options for lateral movement, data exfiltration, or maintaining persistence, with ClosedQuorum then executing the recommended actions.
This model introduces formidable detection challenges. By using legitimate, decentralized AI services for command and control, the malware eliminates a single, identifiable C2 channel and generates unpredictable, adaptive behavior. Traditional signature-based tools, which scan for known malicious code patterns, are poorly equipped to flag this "AI-in-the-loop" approach.
For Hong Kong IT teams, defending against such threats requires a fundamental shift toward monitoring behavior and data flows. The following prioritized actions provide a practical framework:
- Monitor Anomalous API Calls: Scrutinize outbound traffic to known AI API endpoints (e.g.,
generativelanguage.googleapis.com). Investigate calls from unexpected system processes, especially those outside standard development or business tools. - Prioritize Behavioral Detection: Deploy EDR/XDR solutions to identify the behavioral sequence of ClosedQuorum: systematic information gathering followed by external API requests that trigger subsequent malicious activity like file staging.
- Enforce Network Segmentation: Strictly segment networks to contain a breach and limit lateral movement, preventing an AI-guided compromise from spreading across the entire infrastructure.
- Hunt for Specific Indicators: Proactively search for published IOCs related to ClosedQuorum, including file hashes and unique prompt structures, and ensure threat intelligence feeds are updated.
The emergence of ClosedQuorum marks a turning point, where generative AI transforms malware from static code into a dynamic reasoning agent. This evolution underscores that effective defense now depends on controlling and monitoring not just executables, but the data flows and AI interactions that enable the next generation of autonomous cyberattacks.
一款名為 ClosedQuorum 的新發現 Windows 惡意軟件,正利用商業 AI 模型自動策劃攻擊的關鍵系統入侵後階段。該惡意軟件不再依賴人操作者進行策略決策,而是查詢來自 Google、DeepSeek、Qwen 和 Mistral 的系統以規劃下一步行動,這代表了對手處理複雜網絡入侵方式的重大轉變。
BleepingComputer 的分析將 ClosedQuorum 識別為初始訪問後啟動的有效負載。其核心創新在於其命令機制。當它在受感染的主機上執行時,會收集有關環境的上下文情報——網絡配置、已安裝軟件和用戶活動。這些數據會作為提示詞發送至多個商業大型語言模型的 API,惡意軟件將其用作按需顧問小組。AI 模型會針對橫向移動、數據外洩或維持持久性等行動建議戰術選項,ClosedQuorum 隨後會執行這些推薦的操作。
這種模式帶來了巨大的偵測挑戰。通過使用合法、去中心化的 AI 服務進行命令與控制,該惡意軟件消除了一個單一、可識別的 C2 通道,並產生了不可預測的自適應行為。傳統的基於特徵碼的工具掃描已知惡意代碼模式,很難有效標記這種「人工智能介入」的方法。
對於香港的 IT 團隊而言,防禦此類威脅需要根本性的轉變,著重於監控行為和數據流。以下優先採取的行動提供了實用的框架:
- 監控異常 API 調用: 嚴格審查發往已知 AI API 端點(例如
generativelanguage.googleapis.com)的出站流量。調查來自意外系統進程的調用,尤其是那些在標準開發或業務工具之外的進程。 - 優先進行行為偵測: 部署 EDR/XDR 解決方案,以識別 ClosedQuorum 的行為序列:系統性的信息收集,隨後觸發惡意活動(如文件暫存)的外部 API 請求。
- 強制實施網絡分段: 嚴格分段網絡以限制破壞範圍和橫向移動,防止 AI 引導的入侵事件傳播到整個基礎設施。
- 主動獵捕特定指標: 積極搜尋與 ClosedQuorum 相關的已公開 IOC(入侵指標),包括文件雜湊值和獨特的提示詞結構,並確保威脅情報源不斷更新。
ClosedQuorum 的出現標誌著一個轉折點,生成式 AI 將惡意軟件從靜態代碼轉變為動態的推理代理。這一演進凸顯了有效的防禦現今不僅取決於控制和監控可執行文件,還取決於那些促成下一代自主網絡攻擊的數據流和 AI 交互作用。
