{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Autonomous AI-driven malware (CLOSEDQUORUM) represents a tier-shift in adversary tradecraft, allowing real-time decision making without human intervention; identifying this early prevents large-scale ransomware impact."
      },
      "name": "Autonomous AI Command-and-Control and Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1071",
        "attack.t1486"
      ],
      "series": {
        "slug": "trust-and-the-enticing-consultancy-offer",
        "index": 2,
        "title": "Trust and the enticing consultancy offer",
        "total": 2
      },
      "related": [
        {
          "hunt": "social-engineering-elicitation-on-saas",
          "reason": "The social engineering phase on social media platforms is out of scope and requires identity/browser-based telemetry.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "socially-engineered-endpoint-infection-evasion",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule could flag the malware hash, but this hunt pivots between process injection states, rare AI API DNS resolutions, and high-volume file modifications to identify an active, autonomous infection chain that simple static rules would miss.",
      "coverage": [
        {
          "stage": "command-and-control-autonomous-ai",
          "steps": [
            "suspicious-process-lead",
            "rare-ai-infrastructure-dns"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-ransomware-encryption",
          "steps": [
            "high-volume-encryption-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "social-engineering-elicitation",
          "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "trojanised-software-execution",
          "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-edr-killer",
          "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-infostealer",
          "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Consultancy and Job Lure",
            "slug": "social-engineering-elicitation",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Social media messages offering $300/hour for consultancy",
              "Sparse consultant profiles with no employer footprint",
              "Fake job offers requiring candidate software installation"
            ]
          },
          {
            "name": "Execution of Trojanised Installer",
            "slug": "trojanised-software-execution",
            "tactic": "execution",
            "techniques": [
              "T1204",
              "T1566"
            ],
            "observables": [
              "Fake LastPass Authenticator installers",
              "SECOH-QAD.exe",
              "KMSAuto.exe",
              "sample.exe",
              "f_000bc7.exe",
              "content.js",
              "Distribution via GitHub repositories"
            ]
          },
          {
            "name": "Kernel-Level Security Evasion",
            "slug": "defense-evasion-edr-killer",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001"
            ],
            "observables": [
              "Rapuncel kernel-level EDR killer payload",
              "Disabling of remote access and alarms"
            ]
          },
          {
            "name": "Rapuncel Infostealing",
            "slug": "credential-access-infostealer",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Rapuncel stealer searching for credentials",
              "Accessing protected systems via found credentials"
            ]
          },
          {
            "name": "Autonomous AI-Driven C2",
            "slug": "command-and-control-autonomous-ai",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "CLOSEDQUORUM malware binary",
              "Delegation of actions to LLM panels via API calls",
              "Autonomous C2 decision making"
            ]
          },
          {
            "name": "Data Encryption and Impact",
            "slug": "impact-ransomware-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Qilin ransomware incidents",
              "The Gentlemen leak-site listings",
              "Encryption of files and manipulation of pumping cycles in utility systems"
            ]
          }
        ],
        "summary": "This social engineering campaign targets technical professionals with fake consultancy and job offers to distribute trojanised software via platforms like GitHub. Successful infections deploy kernel-level EDR killers and 'Rapuncel' infostealers, while advanced variants utilize 'CLOSEDQUORUM' for autonomous AI-driven command-and-control before final ransomware deployment."
      },
      "severity": "high",
      "rationale": "Focus on high-value developer workstations and servers that might host sensitive data or research, as these are primary targets for AI-driven elicitation and exfiltration.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.",
      "parameters": {
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "ai_api_domains": {
          "from": {
            "ref": "https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[domain]",
          "default": [
            "api.openai.com",
            "api.anthropic.com",
            "api.cohere.ai",
            "api.groq.com"
          ],
          "description": "Known LLM API endpoints used for autonomous C2 orchestration."
        },
        "malware_hashes": {
          "from": {
            "ref": "talos",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[hash]",
          "default": [
            "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
            "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
            "540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8",
            "cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a",
            "38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55"
          ],
          "description": "Hashes for CLOSEDQUORUM and associated tools."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/",
          "name": "Talos \u2014 Trust and the enticing consultancy offer"
        }
      ],
      "blind_spots": [
        {
          "id": "no-process-visibility",
          "risk": "A host without an agent performing AI C2 will only be seen as encrypted traffic at the network level, which might be missed without DNS or socket telemetry.",
          "stage": "command-and-control-autonomous-ai",
          "question": "Are the AI-driven processes running on unmanaged hosts?",
          "requires": "endpoint agent process coverage"
        },
        {
          "id": "encrypted-c2-payload",
          "risk": "We can see the connection to api.openai.com, but cannot see the 'jailbreak terms' or 'prompt templates' used to orchestrate the attack without network inspection.",
          "stage": "command-and-control-autonomous-ai",
          "question": "What instructions were received from the LLM?",
          "requires": "TLS inspection for AI API endpoints"
        }
      ]
    },
    "name": "Autonomous AI Command-and-Control and Impact",
    "description": "This hunt targets the emerging threat of AI-integrated malware, specifically focusing on the CLOSEDQUORUM implant which delegates C2 decisions to Large Language Models. The hunt identifying suspicious processes matching known malware hashes or fileless execution states, then fanning out to look for connections to AI infrastructure and evidence of ransomware-style file encryption (Qilin). An agent weighs the combined telemetry to differentiate between benign AI research tools and malicious autonomous agents."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "trust-and-the-enticing-consultancy-offer",
          "index": 2,
          "title": "Trust and the enticing consultancy offer",
          "total": 2
        },
        "coverage": [
          {
            "stage": "command-and-control-autonomous-ai",
            "steps": [
              "suspicious-process-lead",
              "rare-ai-infrastructure-dns"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-ransomware-encryption",
            "steps": [
              "high-volume-encryption-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "social-engineering-elicitation",
            "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "trojanised-software-execution",
            "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-edr-killer",
            "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-infostealer",
            "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.",
        "blind_spots": [
          {
            "id": "no-process-visibility",
            "risk": "A host without an agent performing AI C2 will only be seen as encrypted traffic at the network level, which might be missed without DNS or socket telemetry.",
            "stage": "command-and-control-autonomous-ai",
            "question": "Are the AI-driven processes running on unmanaged hosts?",
            "requires": "endpoint agent process coverage"
          },
          {
            "id": "encrypted-c2-payload",
            "risk": "We can see the connection to api.openai.com, but cannot see the 'jailbreak terms' or 'prompt templates' used to orchestrate the attack without network inspection.",
            "stage": "command-and-control-autonomous-ai",
            "question": "What instructions were received from the LLM?",
            "requires": "TLS inspection for AI API endpoints"
          }
        ],
        "scoping_notes": "Focus on high-value developer workstations and servers that might host sensitive data or research, as these are primary targets for AI-driven elicitation and exfiltration.",
        "beyond_detection": "A single rule could flag the malware hash, but this hunt pivots between process injection states, rare AI API DNS resolutions, and high-volume file modifications to identify an active, autonomous infection chain that simple static rules would miss."
      }
    },
    {
      "id": "suspicious-process-lead",
      "type": "query",
      "label": "Processes matching malware hashes or fileless state",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, process_hash_sha256, user_name, on_disk, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR on_disk = 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify potential AI-driven C2 implants based on known hashes or evidence of injection.",
        "expected_signal": "A process matching a known hash or running without a backing file on disk. Silence proves these specific indicators are not running."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Processes matching malware hashes or fileless state",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "process_hash_sha256",
          "user_name",
          "on_disk",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, process_hash_sha256, user_name, on_disk, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR on_disk = 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A process matching a known hash or running without a backing file on disk. Silence proves these specific indicators are not running.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-ai-infrastructure-dns",
      "type": "query",
      "label": "Rare DNS queries to AI API endpoints",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT query_hostname, process_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{ai_api_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY query_hostname, process_name HAVING host_count <= 3",
        "surface": "hb_dns_activity",
        "description": "Identify processes communicating with AI services that are not widespread in the fleet.",
        "expected_signal": "Processes on a few hosts talking to LLM APIs; common usage by developers will be filtered by the host count."
      },
      "parents": [
        {
          "id": "suspicious-process-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare DNS queries to AI API endpoints",
        "reads": [
          "query_hostname",
          "process_name",
          "device_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT query_hostname, process_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{ai_api_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY query_hostname, process_name HAVING host_count <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Processes on a few hosts talking to LLM APIs; common usage by developers will be filtered by the host count.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "query_hostname"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "high-volume-encryption-activity",
      "type": "query",
      "label": "High-volume file modification activity",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(*) as file_count, MIN(time) as start_time FROM hb_file_activity WHERE activity_id IN (1, 3, 4, 5) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_count > 100",
        "surface": "hb_file_activity",
        "description": "Detect the impact phase where the malware encrypts local files.",
        "expected_signal": "A single process touching hundreds of files on a host. Benign processes like indexers or updates may appear but will be weighed by the agent."
      },
      "parents": [
        {
          "id": "suspicious-process-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "High-volume file modification activity",
        "reads": [
          "device_hostname",
          "process_name",
          "activity_id",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(*) as file_count, MIN(time) as start_time FROM hb_file_activity WHERE activity_id IN (1, 3, 4, 5) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_count > 100",
        "silence": "not_evidence_of_absence",
        "expected": "A single process touching hundreds of files on a host. Benign processes like indexers or updates may appear but will be weighed by the agent.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-ai-threat",
      "type": "analytic",
      "label": "Weigh AI C2 and Encryption",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "suspicious-process-lead",
          "rare-ai-infrastructure-dns",
          "high-volume-encryption-activity"
        ],
        "objective": "Assess if processes matching known hashes or injected states are communicating with AI services and subsequently encrypting files, indicating an autonomous AI C2 infection.",
        "description": "Determine if the identified processes are coordinating malicious actions via AI endpoints or performing ransomware encryption.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict on whether the observed telemetry indicates an autonomous AI threat.",
        "success_criteria": "A verdict of malicious | suspicious | benign citing specific process, DNS, and file activity rows."
      },
      "parents": [
        {
          "id": "rare-ai-infrastructure-dns",
          "kind": "merge"
        },
        {
          "id": "high-volume-encryption-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-ai-threat verdict is malicious for at least one host",
        "condition": "the triage-ai-threat verdict is malicious for at least one host",
        "blind_spot": "no-process-visibility",
        "confidence": "high",
        "description": "Determine whether to contain the host based on the agent's findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-ai-threat"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Halt the autonomous AI agent and prevent further encryption.",
        "instructions": "Isolate the host and preserve memory for forensic analysis of the CLOSEDQUORUM implant.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-final-review",
      "type": "task",
      "label": "Analyst final review",
      "config": {
        "assignee": "analyst",
        "description": "Final validation of the AI C2 hypothesis and tuning of detection logic.",
        "instructions": "Review the DNS queries and file modification counts. Confirm if the AI API usage is consistent with C2 delegation described in the research."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Log the hunt results and tune for future AI-driven threats.",
        "instructions": "Document false positives (e.g., local LLM development) and ensure the detection candidate is promoted if effective."
      },
      "parents": [
        {
          "id": "analyst-final-review"
        }
      ]
    }
  ]
}