ClosedQuorum: Delegated Control and the Boundaries of AI Malware Autonomy
Abstract
ClosedQuorum presents an instructive case for AI virology: language models participate in choosing malware actions during execution. The analytical question is where that participation sits in the malicious system. Decision-making, capability execution, persistence, and reproduction are different functions, and evidence for one does not establish the others. This article places ClosedQuorum within a proposed category of AI-orchestrated malware, develops a compact model of delegated control, and examines what would be required to support stronger claims about autonomy or propagation. Its contribution is a taxonomic and defensive interpretation of public reporting, not an independent reverse-engineering report or a new experimental result.
1. Start with the evidence boundary
On September 22, 2026, Cisco Talos published Ryan Fetterman’s analysis of ClosedQuorum, a Go-based Windows implant with a model-mediated tactical decision loop. Talos qualifies its priority claim as the first such publicly documented Windows implant to its knowledge. It does not confirm deployment in the wild. Static analysis establishes the described architecture; the public distribution binary contains placeholder API credentials and a dummy webhook, and Talos did not observe complete end-to-end operation. These limits belong beside the headline, not in a footnote. Talos analysis.
The case should therefore be read at three separate evidence levels:
| Evidence level | Question it answers |
|---|---|
| Structural evidence | Does the program contain a reachable path from model output to action selection? |
| Runtime evidence | Does that path operate successfully under stated conditions? |
| Deployment evidence | Has the system been observed performing those actions in an actual intrusion? |
Evidence does not automatically move upward through this table. A model API string alone establishes little; a recovered decision loop establishes more; a successful laboratory run still does not establish an active campaign. Conversely, incomplete deployment evidence does not make an architectural finding irrelevant.
2. A bounded action repertoire
The reported panel comprises DeepSeek, Qwen, Mistral, and Google Gemini. Its action vocabulary includes credential and wallet theft (steal), process injection (inject), persistence (persist), and an unimplemented lateral-movement option (move). Discord serves as a reporting and exfiltration destination. Selection uses plurality voting, with ties resolved by provider order: DeepSeek, Qwen, Mistral, then Gemini. This is deterministic arbitration, not an additional deliberation by a tie-breaking model. Technical source.
For classification, the important distinction is between naming a capability, implementing it, and successfully exercising it. A declared action is an interface element. An implementation is program behavior. Success depends on the environment and must be observed separately.
The same discipline applies to code-generation claims. A function named as a shellcode generator does not, by its name alone, prove that a language model authored executable bytes. An analyst must trace the actual source of those bytes before assigning a generative-payload label. Selecting an existing capability and synthesizing a new capability are different forms of AI integration.
3. Placement within VXHEAVEN’s AI-virology taxonomy
For VXHEAVEN, AI-orchestrated malware can be defined as malicious software in which model output contributes to selecting or parameterizing actions during execution. This is a proposed analytical category, not an industry standard or a claim about model consciousness.
The conceptual placement is:
AI Virology
├── AI-Assisted Malware
│ └── AI used during development or preparation
├── AI-Mediated Attacks
│ └── AI-Orchestrated Malware
│ └── Model-mediated tactical control
└── AI-Native Propagation
├── Prompt Worms
├── RAG Worms
└── Memory Worms
These branches describe roles and can overlap. A program may be developed with AI assistance and later use a model at runtime. A propagation mechanism could also incorporate model-mediated control. Classification should record the demonstrated combination rather than force every specimen into one exclusive box.
| Classification axis | Required evidence |
|---|---|
| AI-assisted construction | Evidence that AI contributed to producing the software or attack material. Runtime API access does not establish this. |
| AI-mediated control | A causal path from a model response to an action decision. |
| Generative capability | Evidence that model output supplies new executable or behavioral content, beyond choosing a label. |
| Adaptive behavior | Observable changes in behavior caused by relevant changes in available information. |
| Self-propagation | Production and establishment of a viable descendant through the affected system’s behavior. |
| Operational autonomy | Successful progression through a specified phase without new operator tasking. |
Under this framework, the defensible placement of the reported design is model-mediated tactical control. Assigning it to a worm class would require a different evidentiary claim: a reproductive transition. Assigning it to autonomous capability synthesis would require tracing generated functionality. Neither label follows simply from the presence of several models.
The word virology here names the research domain. It does not imply that every specimen examined is a computer virus in the strict reproductive sense.
4. Separate control, execution, and reproduction
An AI-virology description becomes clearer when it distinguishes three functions:
| Function | Central question | Relevant object |
|---|---|---|
| Control | What action should happen next? | Observations, model responses, selection policy. |
| Execution | What can the program actually do? | Implemented capabilities and available permissions. |
| Reproduction | What creates the next viable instance or carrier? | A descendant and a demonstrated establishment path. |
A conceptual control cycle is:
Available observations
|
v
Model-mediated assessment
|
v
Decision selection and interpretation
|
v
Implemented action
|
v
Resulting environment
This diagram does not imply that every result is sensed accurately or fed back into the next decision. A scheduled loop is not sufficient evidence of effective adaptation. Analysts should identify which observations are refreshed, which outcomes are checked, and which errors remain invisible to the controller.
Let \(o_t\) denote the information available to a controller at time \(t\), \(\mathcal{D}_t\) its received model responses, and \(\Gamma\) the application’s decision-selection rule. A descriptive abstraction is
$$ \mathcal{D}_t=\operatorname{Responses}(o_t), \qquad a_t=\Gamma(\mathcal{D}_t). $$
Let \(\mathcal{A}_{\mathrm{declared}}\) be the action vocabulary and \(\mathcal{A}_{\mathrm{implemented}}\) the set backed by program behavior. Selecting a recognized word does not guarantee that it belongs to the second set. Even an implemented action may fail under the current privileges or host state.
For an executable selection, write
$$ s_{t+1}\sim P(\cdot\mid s_t,a_t), $$
where \(s_t\) is the actual environment state and \(P\) represents execution outcomes. The controller sees \(o_t\), not necessarily all of \(s_t\). This distinction matters when evaluating whether apparently reasoned choices were informed by current, sufficient evidence.
These equations describe a class of systems. They are not a reconstruction of every implementation detail, a runnable controller, or a measured performance model.
5. What a model panel does—and does not—prove
A panel introduces an aggregation policy. That policy deserves analysis independently of the participating models.
Plurality is not a majority requirement. A selection can win by receiving more votes than its alternatives without receiving more than half of all votes. A tie rule is part of the effective policy, not incidental presentation logic.
Several providers do not imply independent errors. Models may respond similarly because they receive the same incomplete observations, follow similar conventions, or share blind spots. Provider diversity is not itself a measurement of decision diversity.
Agreement is not correctness. All participants may agree on an action that is inappropriate, unsupported, or impossible in the current environment. A successful parser proves that a response was interpretable; it does not prove that the underlying decision was sound.
Redundancy and decision quality are different outcomes. A panel may produce usable responses more often while making no better choices. Conversely, stricter rejection of uncertain responses may improve quality while reducing availability. Those tradeoffs must be measured separately.
For a benign evaluation of this architectural pattern, compare a panel with a fixed policy and a single-model controller under the same workload. Record valid-response frequency, task success, disagreement, latency, and cost. Without a baseline, a more elaborate orchestration layer can be mistaken for a more capable system.
6. Autonomy should be indexed by phase
Calling a system autonomous leaves the most useful question unanswered: autonomous over which decisions, and under which dependencies?
A practical description should identify the scope of delegation:
| Phase | Evidence needed to claim autonomy |
|---|---|
| Preparation | Selection or production of the required configuration without case-by-case operator input. |
| Delivery | Independent establishment on a destination, under an explicit threat model. |
| Tactical selection | Choice of the next permitted program action without a fresh human command. |
| Execution monitoring | Verification of outcomes and appropriate handling of failure. |
| Adaptation | Relevant behavioral changes based on new observations. |
| Propagation | Creation and establishment of descendants without external reseeding. |
This table is an assessment framework, not a claim that ClosedQuorum implements every phase. An analyst should mark unsupported entries as unknown rather than infer them from an autonomous selection loop.
Autonomy also differs from independence. A controller can operate without ongoing human tasking while depending on remote inference, credentials, network availability, and preexisting code. Removing one human decision point does not remove the surrounding infrastructure or the human responsibility for the malicious operation.
The useful unit is therefore a bounded delegation claim: a named phase, a declared information set, a defined repertoire, and a stated intervention requirement. This makes comparisons possible without reducing every system to a misleading single autonomy score.
7. The reproductive boundary: comparison with RAG and Memory Worms
The distinction from the worm mechanisms explored in VXHEAVEN’s taxonomy is causal.
In a RAG-worm model, retrieved content changes an application’s behavior so that it creates a viable descendant carrier. A memory-mediated variant additionally uses persistent agent state to preserve or regenerate that capability. The defining observation is a lineage, not repeated execution on one host.
Morris II provides a published experimental reference for adversarial self-replicating prompts in connected GenAI applications, including a RAG-based setting. Its relevance is evidence of reproduction under evaluated conditions, not a general claim that all model-integrated malware is reproductive. Morris II paper.
For a proposed descendant transition, ask:
- What was the parent instance or carrier?
- Which observed action produced the candidate descendant?
- Where did the descendant become established?
- Could that descendant continue the relevant behavior without the original parent or a fresh researcher-supplied seed?
Persistence alone answers none of these questions. Repeated access to the same model service is not replication. Shared use of one provider does not show infection between clients, and the model service itself need not be compromised for its output to be misused.
A generic reproduction measure would be
$$ R_{\mathrm{AI}}= \mathbb{E}[\text{new viable descendants per parent within a declared horizon}]. $$
The parent unit, descendant test, attribution rule, and observation horizon must all be specified. This article assigns no value to ClosedQuorum: the evidence discussed does not supply a measured reproductive lineage. Unknown reproduction is not a numerical zero, and tactical autonomy is not a substitute for offspring data.
8. Defensive analysis: identify the conversion into authority
The central defensive question for model-mediated control is where external text acquires the authority to cause an action. The model response is only one event. The consequential transition occurs when an application interprets it and exercises permissions on its behalf.
That suggests a process-centered investigation rather than a verdict based on an AI-related domain:
| Investigative layer | Question |
|---|---|
| Origin | Which executable or process lineage initiated the request? |
| Business context | Is inference access expected for that workload and identity? |
| Temporal relationship | What endpoint activity preceded and followed the request? |
| Authority | Which permissions allowed the subsequent action? |
| Destination | Where did outputs, reports, or collected material go? |
| Causality | Is the action demonstrably linked to the response, or merely nearby in time? |
Encrypted transport may prevent inspection of prompts and responses. In that case, a defender can still correlate process identity, connection metadata, and endpoint events, while stating the resulting uncertainty. A contact with a legitimate AI service is a lead; its significance comes from the surrounding behavior.
For authorized agent systems, enforce action authorization independently of model agreement. Requiring several models to approve an action is not a replacement for checking whether the authenticated user may request it. A typed output schema constrains representation; a permission boundary constrains authority.
In incident response, interrupt the affected process and its execution paths according to established containment procedures. Preserve the provenance needed to explain the sequence. Blocking a provider alone should not be described as proof that the host is clean or that already-created persistence has been removed.
These are architectural recommendations from the framework developed here. They are not detection rules validated against a ClosedQuorum corpus, and no detection performance is claimed.
9. CAIRN and cognitive artifacts
CAIRN—Cognitive Artifact Intelligence Research Network—adds a useful research perspective: prompts, model-service references, and orchestration traces can become investigative artifacts. Talos describes a metadata-first workflow with tiered classification, semantic clustering, and relationship analysis. It also warns that AI-related strings and cluster membership produce leads that require validation; bundled dependencies and unrelated software features can create false positives. CAIRN introduction.
The public repository documents analysis of VirusTotal metadata rather than downloading or executing binaries. Its provenance-oriented scan representation allows an analyst to inspect which metadata supported a match. This is a discovery and triage layer, not a substitute for establishing program behavior. CAIRN repository.
For VXHEAVEN, the resulting archival opportunity is to record the role of the AI component, not just its presence. A useful case record would include:
- The observed artifact and where it came from.
- The claimed control or propagation function.
- Evidence connecting that artifact to reachable behavior.
- Runtime observations, if available.
- Deployment status and unresolved alternatives.
- The date and conditions under which the classification was made.
This creates a record that can be revised when stronger evidence appears. It also prevents an appealing taxonomy label from becoming more certain than the underlying analysis.
10. Research questions that can be studied safely
Several important questions do not require a functioning malicious implant. A disposable simulation can use benign tasks and inert action records to evaluate the properties of model-mediated control:
| Question | Harmless measurement |
|---|---|
| Does aggregation improve reliability? | Compare completed benign tasks across fixed, single-model, and panel policies. |
| Do choices depend on relevant observations? | Change one simulated environmental condition and measure the resulting decisions. |
| Are failures visible to the controller? | Supply simulated unsuccessful outcomes and observe whether later decisions account for them. |
| Does the action vocabulary match the implementation? | Compare accepted labels with registered inert handlers. |
| How influential is arbitration? | Replay the same recorded responses under declared selection rules and compare outcomes. |
| Can the run be reconstructed? | Rebuild each decision from retained inputs, response records, policy version, and action logs. |
The experimental system should have no credential access, injection routines, persistence mechanisms, live exfiltration destination, or path to external targets. Model responses should resolve only to inert records or ordinary sandboxed tasks. Such experiments evaluate controller properties; they do not establish malicious deployment or reproduce the source specimen’s complete behavior.
For a comparative study, preregister the workload and success criteria, include failed and refused responses, and report variability across runs. Preserve model and policy versions where available. Label hypothetical scenarios as hypothetical, and keep results from simulations separate from reverse-engineering findings.
11. What this case contributes to AI virology
ClosedQuorum is useful to the taxonomy because it directs attention to delegated control: the part of a malicious system where observations become decisions. That layer deserves its own description alongside payload capability, persistence, and propagation.
This separation makes the broader field more precise. A specimen may have a conventional carrier and a model-mediated controller. Another may use semantic carriers to reproduce across applications. A future specimen could combine both, but the combination must be demonstrated rather than inferred from an autonomy label.
The research task is to identify each causal transition, preserve its evidence, and measure its limits. For VXHEAVEN, the lasting contribution of this case is a sharper classification question: what authority has been delegated to the model, and what observable behavior does that delegation enable?
References and editorial scope
- Ryan Fetterman. The Closed Quorum: Inside the first reported autonomous AI C2 implant. Cisco Talos, September 22, 2026. Primary analysis.
- Ryan Fetterman. Introducing CAIRN: Frontier tracking for AI-integrated malware. Cisco Talos, September 22, 2026. Project introduction.
- Cisco Talos. Cognitive Artifact Intelligence Research Network. Public research-tool repository.
- Stav Cohen, Ron Bitton, and Ben Nassi. Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications. First submitted 2024; revised 2025. arXiv:2403.02817.
Prepared September 28, 2026. Specimen-specific reporting is attributed to its original investigators. The VXHEAVEN classification, analytical model, and proposed evaluation questions are editorial synthesis. No malware sample was executed or independently reverse-engineered for this article. No operational exploit instructions or deployment materials are included.