Cisco Talos Reports CLOSEDQUORUM Malware Using AI to Choose Attack Commands
Moyen · The Hacker News ·
En bref
- CLOSEDQUORUM uses up to four AI models to vote on which malicious actions to execute.
- The malware steals Windows credentials, saved browser passwords, and cryptocurrency wallet data.
- Cisco Talos disclosed the threat on September 22; no CVE identifiers are associated.
- Microsoft Windows users are the primary targets, and AI-driven decision-making complicates detection.
Cisco Talos published research on September 22 about a malware strain called CLOSEDQUORUM. This threat employs multiple artificial intelligence models—as many as four—to make decisions, such as voting on which commands to run. That is a shift from static or preprogrammed attack logic.
The malware's primary goals are stealing data. It harvests credentials from Windows systems, extracts saved passwords from browser storage, and grabs cryptocurrency wallet information. These targets are common but high-value for cybercriminals.
Who is affected? Windows users, especially those who save login details in their browsers or hold digital assets in crypto wallets. Organizations running Windows endpoints are at risk. The involvement of AI models adds a layer of adaptability, making signature-based detection harder.
Why it matters: This isn't a vulnerability with a CVE; it's a malware capability. The lack of a CVE means patching alone won't stop it. Defenders need behavioral detection and credential hygiene. Microsoft, as the maker of Windows, may need to enhance built-in protections.
Context: Cisco Talos has been tracking this. The use of AI vote control suggests malware authors are experimenting with ensemble decision-making. Up to four models could vote on command selection, reducing predictability. This is an emerging trend.
What to watch: Monitor for CLOSEDQUORUM indicators. Watch for updates from Cisco Talos and Microsoft. Expect more AI-driven malware. Review browser password management policies. Consider hardware wallets for crypto.
À faire maintenant
- Hunt for CLOSEDQUORUM indicators published by Cisco Talos and block any known IOCs at the perimeter and endpoints.
- Enforce Group Policy to prevent browsers from saving passwords; require a password manager with MFA for all staff.
- Deploy EDR rules that flag unusual command execution sequences or processes making network calls to AI model APIs.
- Isolate cryptocurrency wallet access on hardened, dedicated machines or migrate to hardware wallets.
- Maintain Windows and Microsoft Defender updates even though no CVE applies; ensure behavioral monitoring is active.
- Train users to recognize phishing that could deliver CLOSEDQUORUM and restrict local admin rights to reduce impact.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.