Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
A new Windows malware, CLOSEDQUORUM, is utilizing AI models – specifically Large Language Models (LLMs) – to autonomously choose actions after a system is compromised. This represents the first publicly documented Windows implant leveraging AI for Command and Control (C2) communication, highlighting a significant evolution in malware tactics. The Register reported on a Microsoft portal disagreement and a related surprise bill, alongside other security news including a zero-day attack on on-prem SharePoint and a Russian phishing campaign.
The Register reported on a new Windows malware, CLOSEDQUORUM, that is utilizing AI models to autonomously select post-compromise actions. This represents the first publicly documented Windows implant leveraging AI for Command and Control (C2) communication. The malware is described as a significant evolution in malware tactics, moving beyond traditional scripting and relying on AI to dynamically adapt to its environment and evade detection. The Register also reported on a Microsoft portal disagreement and a related surprise bill, alongside other security news including a zero-day attack on on-prem SharePoint and a Russian phishing campaign targeting users posing as Signal support. The article also mentioned a broader trend of security companies being acquired, such as EQT buying a majority stake in Swiss cybersecurity firm Acronis.