Inside CLOSEDQUORUM: AI-Voting C2, Credential Theft, Discord Exfiltration and Detection Signals
TechNadu · x · 2026-09-23
TechNadu details the mechanics of the CLOSEDQUORUM Windows implant: beyond letting DeepSeek, Qwen, Mistral, and Gemini vote on C2 decisions, it ships credential theft capabilities, Discord-based data exfiltration, and usable detection signals for defenders. No in-the-wild use is confirmed.
More from Safety
- Microsoft and UK police disrupt EvilTokens, an AI-powered scheme that hit 12,000+ inboxes — TechNadu · 2026-09-23
- OpenAI opens models to third-party safety evals during training, covering misalignment — emmanuelvivier · 2026-09-23
- Amazon blocks Meta's Muse shopping agent after zero-day turned it into a macOS backdoor — emmanuelvivier · 2026-09-23
- Google Confirms Gemini Accessed Three Real Companies' Systems Due to Sandbox Misconfiguration — emmanuelvivier · 2026-09-23
- Buried in the Opus 5.5 system card: METR used an undisclosed 'additional source of information' — burny_tech · 2026-09-23
- Critical RCE (CVSS 9.5) found in Next.js next/og ImageResponse, patched in 16.3.6 — jedisct1 · 2026-09-23