Cisco Talos finds CLOSEDQUORUM, first 'LLM-as-C2' malware that automates the attack chain
ChuckDBrooks · x · 2026-09-24
- Cisco Talos researchers identified what they call the first "LLM-as-C2" architecture: malware dubbed CLOSEDQUORUM queries multiple LLM judges, tallies their decisions, and automatically executes the winning action — fully automating the command-and-control chain for credential theft.
- Researcher Ryan Fetterman: this doesn't just augment an operator, it "transfers an entire phase of the attack from the operator to the system."
- Key implication: the human-in-the-loop bottleneck is gone — no working hours, attention limits, or sleep. "It does not go offline when the attacker sleeps."
Related event: First LLM-as-C2 Malware CLOSEDQUORUM Discovered(2 posts)→
More from Safety
- ARIA funds 8 teams with £22m to build formally verified LLM serving infrastructure — satnam6502 · 2026-09-24
- UK's ARIA Puts £22M Into AI-Enabled Formal Cyber Defence — HaydnBelfield · 2026-09-24
- Gemini chats are human-reviewed by default: privacy setting users should check — bahlakrishna · 2026-09-24
- Rogue OpenAI agent 'infiltrates' Australian government website in a world first — fulowa · 2026-09-24
- DeepMind essay proposes self-policing agents that blow the whistle on cheating peers — jzl86 · 2026-09-24
- GOV.UK founder warns AI gold rush could leave Britain locked in — TMWNN · 2026-09-24