{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Autonomous C2 infrastructure using legitimate AI providers evades traditional domain-based blocking and allows attackers to maintain persistence without active manual intervention."
      },
      "name": "Autonomous LLM Decision Loop",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1071.001",
        "attack.t1047",
        "attack.t1003.001"
      ],
      "series": {
        "slug": "the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant",
        "index": 1,
        "title": "The Closed Quorum: Inside the first reported autonomous AI C2 implant",
        "total": 2
      },
      "related": [
        {
          "hunt": "persistence-establishment-closedquorum",
          "reason": "Specific WMI and registry persistence techniques are handled by a dedicated persistence hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single detection rule would struggle to link host-side discovery with the specific quorum pattern of sequential DNS lookups. This hunt correlates rare discovery processes with infrastructure resolution across three or more providers, weighing behavioral prevalence against infrastructure patterns.",
      "coverage": [
        {
          "stage": "host-discovery-initialization",
          "steps": [
            "discovery-prevalence"
          ],
          "status": "covered"
        },
        {
          "stage": "autonomous-llm-c2",
          "steps": [
            "ai-quorum-dns"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-establishment",
          "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "process-injection-execution",
          "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-and-wallet-theft",
          "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Host Discovery and Initialization",
            "slug": "host-discovery-initialization",
            "tactic": "discovery",
            "techniques": [
              "T1047"
            ],
            "observables": [
              "gatherSystemInfo() function call",
              "Collection of hostname, Windows version, CPU count, and architecture",
              "Admin status check"
            ]
          },
          {
            "name": "Autonomous LLM C2 Orchestration",
            "slug": "autonomous-llm-c2",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "main.queryLLM() function call",
              "ModelOrchestrator polling DeepSeek, Qwen, Mistral, and Google Gemini APIs",
              "Structured JSON prompts containing 'TARGET: %s' context",
              "Polling intervals of 5 to 15 minutes",
              "Discord webhooks for operator telemetry"
            ]
          },
          {
            "name": "WMI Persistence",
            "slug": "persistence-establishment",
            "tactic": "persistence",
            "techniques": [
              "T1047"
            ],
            "observables": [
              "establishPersistence() function call",
              "WMI event subscription creation"
            ]
          },
          {
            "name": "Process Injection",
            "slug": "process-injection-execution",
            "tactic": "defense-evasion",
            "techniques": [
              "T1055"
            ],
            "observables": [
              "injectProcess() function call",
              "earlyBirdInject() function call",
              "PEB-walk process hollowing",
              "APC injection into suspended processes"
            ]
          },
          {
            "name": "Credential and Wallet Harvesting",
            "slug": "credential-and-wallet-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1003",
              "T1003.001"
            ],
            "observables": [
              "lsassDump() function call",
              "dumpBrowserCredentials() targeting Chrome, Edge, and Firefox",
              "extractCryptoWallets() function call",
              "Access to 'exodus.wallet'",
              "Access to MetaMask Chrome extensions",
              "Access to 'ethPath' Ethereum wallets"
            ]
          }
        ],
        "summary": "CLOSEDQUORUM is an autonomous Windows implant that uses a panel of commercial LLMs (DeepSeek, Mistral, Gemini, Qwen) as its command-and-control infrastructure. The malware independently gathers host information, polls the LLM providers for instructions, and uses a plurality voting mechanism to execute actions including credential theft, process injection, and WMI-based persistence, exfiltrating data via Discord webhooks."
      },
      "severity": "high",
      "rationale": "The hunt identifies Windows systems first. Analysts should prioritize developer or researcher machines that might legitimately use AI APIs, as the implant aims to blend into this traffic.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An autonomous implant performs host discovery and then queries multiple commercial AI providers to decide its next tactical moves, bypassing traditional C2 infrastructure.",
      "parameters": {
        "ai_domains": {
          "from": {
            "ref": "talos-closed-quorum",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "list[domain]",
          "default": [
            "api.deepseek.com",
            "dashscope.aliyuncs.com",
            "api.mistral.ai",
            "generativelanguage.googleapis.com"
          ],
          "description": "Commercial LLM provider API endpoints used for autonomous C2."
        },
        "scope_hosts": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "list[host]",
          "default": [],
          "description": "Specific hosts to narrow the hunt; leave empty for the full estate."
        },
        "lookback_days": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/",
          "name": "The Closed Quorum: Inside the first reported autonomous AI C2 implant"
        }
      ],
      "blind_spots": [
        {
          "id": "tls-encryption-gap",
          "risk": "Without inspecting the encrypted payload, we can only confirm that a process is talking to an LLM provider, not what it is saying.",
          "stage": "autonomous-llm-c2",
          "question": "Are the prompts being sent to LLMs truly the offensive JSON schema described in the report?",
          "requires": "TLS inspection or endpoint memory analysis"
        },
        {
          "id": "no-endpoint-telemetry",
          "risk": "The hunt only sees discovery and quorum behavior on the enrolled estate.",
          "stage": "host-discovery-initialization",
          "question": "Did the implant execute discovery on a host with no agent installed?",
          "requires": "hb_process_activity with high coverage"
        }
      ]
    },
    "name": "Autonomous LLM Decision Loop",
    "description": "This hunt identifies the unique LLM-as-C2 architecture used by the CLOSEDQUORUM implant. Instead of contacting a single attacker-controlled domain, the implant queries a quorum of commercial AI providers (DeepSeek, Qwen, Mistral, and Google Gemini) to receive instructions via structured JSON prompts. The hunt correlates initial system discovery commands with sequential DNS queries to these AI providers, identifying hosts where automated reasoning replaces human-directed command and control."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant",
          "index": 1,
          "title": "The Closed Quorum: Inside the first reported autonomous AI C2 implant",
          "total": 2
        },
        "coverage": [
          {
            "stage": "host-discovery-initialization",
            "steps": [
              "discovery-prevalence"
            ],
            "status": "covered"
          },
          {
            "stage": "autonomous-llm-c2",
            "steps": [
              "ai-quorum-dns"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-establishment",
            "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "process-injection-execution",
            "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-and-wallet-theft",
            "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An autonomous implant performs host discovery and then queries multiple commercial AI providers to decide its next tactical moves, bypassing traditional C2 infrastructure.",
        "blind_spots": [
          {
            "id": "tls-encryption-gap",
            "risk": "Without inspecting the encrypted payload, we can only confirm that a process is talking to an LLM provider, not what it is saying.",
            "stage": "autonomous-llm-c2",
            "question": "Are the prompts being sent to LLMs truly the offensive JSON schema described in the report?",
            "requires": "TLS inspection or endpoint memory analysis"
          },
          {
            "id": "no-endpoint-telemetry",
            "risk": "The hunt only sees discovery and quorum behavior on the enrolled estate.",
            "stage": "host-discovery-initialization",
            "question": "Did the implant execute discovery on a host with no agent installed?",
            "requires": "hb_process_activity with high coverage"
          }
        ],
        "scoping_notes": "The hunt identifies Windows systems first. Analysts should prioritize developer or researcher machines that might legitimately use AI APIs, as the implant aims to blend into this traffic.",
        "beyond_detection": "A single detection rule would struggle to link host-side discovery with the specific quorum pattern of sequential DNS lookups. This hunt correlates rare discovery processes with infrastructure resolution across three or more providers, weighing behavioral prevalence against infrastructure patterns."
      }
    },
    {
      "id": "scope-windows-endpoints",
      "type": "query",
      "label": "Scope Windows endpoints",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT hostname FROM hb_devices WHERE platform = 'Windows' AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_devices",
        "description": "Identify Windows systems within the estate that could be targeted by this 64-bit Windows implant.",
        "expected_signal": "A list of hostnames representing the Windows fleet. Silence means no Windows systems were indexed."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope Windows endpoints",
        "reads": [
          "hostname",
          "platform",
          "time"
        ],
        "source": "hb_devices",
        "target": "endpoint",
        "content": "SELECT DISTINCT hostname FROM hb_devices WHERE platform = 'Windows' AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames representing the Windows fleet. Silence means no Windows systems were indexed.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "discovery-prevalence",
      "type": "query",
      "label": "Rare system discovery commands",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%wmic%' OR LOWER(process_cmd_line) LIKE '%systeminfo%' OR LOWER(process_cmd_line) LIKE '%hostname%') AND LOWER(process_path) NOT LIKE 'c:\\windows\\system32\\%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name, process_cmd_line HAVING host_count <= 5",
        "surface": "hb_process_activity",
        "description": "The hunt finds uncommon processes performing system discovery using wmic or systeminfo, matching the implant's gatherSystemInfo() behavior, while filtering out standard system paths.",
        "expected_signal": "Discovery commands executed by non-standard processes across a small number of hosts. Fleet-wide management scripts are ignored."
      },
      "parents": [
        {
          "id": "scope-windows-endpoints"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare system discovery commands",
        "reads": [
          "process_name",
          "process_cmd_line",
          "device_hostname",
          "process_path",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%wmic%' OR LOWER(process_cmd_line) LIKE '%systeminfo%' OR LOWER(process_cmd_line) LIKE '%hostname%') AND LOWER(process_path) NOT LIKE 'c:\\windows\\system32\\%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name, process_cmd_line HAVING host_count <= 5",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Discovery commands executed by non-standard processes across a small number of hosts. Fleet-wide management scripts are ignored.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name",
            "process_cmd_line"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "ai-quorum-dns",
      "type": "query",
      "label": "AI provider DNS quorum",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(DISTINCT query_hostname) AS unique_providers, GROUP_CONCAT(DISTINCT query_hostname) AS providers FROM hb_dns_activity WHERE instr(',' || '{{ai_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING unique_providers >= 3",
        "surface": "hb_dns_activity",
        "description": "The hunt identifies processes resolving multiple commercial LLM providers in sequence, representing the plurality voting loop of the implant.",
        "expected_signal": "A single process on a host contacting several unique AI providers (DeepSeek, Mistral, Gemini) in a short window. This identifies the quorum-polling behavior."
      },
      "parents": [
        {
          "id": "scope-windows-endpoints"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "AI provider DNS quorum",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(DISTINCT query_hostname) AS unique_providers, GROUP_CONCAT(DISTINCT query_hostname) AS providers FROM hb_dns_activity WHERE instr(',' || '{{ai_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING unique_providers >= 3",
        "silence": "not_evidence_of_absence",
        "expected": "A single process on a host contacting several unique AI providers (DeepSeek, Mistral, Gemini) in a short window. This identifies the quorum-polling behavior.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-quorum-behavior",
      "type": "analytic",
      "label": "Triage quorum behavior",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "discovery-prevalence",
          "ai-quorum-dns"
        ],
        "objective": "Determine if a single host or process exhibits both system discovery and the sequential polling of multiple AI providers. Prioritize processes that performed system discovery immediately preceding lookups to three or more distinct AI providers.",
        "description": "The agent correlates host discovery with AI infrastructure resolution to identify the autonomous C2 loop.",
        "max_iterations": 6,
        "expected_signal": "A per-host verdict on whether the autonomous loop is active.",
        "success_criteria": "A per-host verdict (malicious, suspicious, or benign) citing specific process names and resolved domains."
      },
      "parents": [
        {
          "id": "discovery-prevalence",
          "kind": "merge"
        },
        {
          "id": "ai-quorum-dns",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host exhibiting correlated system discovery and AI provider DNS traffic",
        "condition": "the triage verdict is malicious for at least one host exhibiting correlated system discovery and AI provider DNS traffic",
        "blind_spot": "tls-encryption-gap",
        "confidence": "high",
        "description": "The hunt routes based on the confidence of the autonomous C2 loop identification.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-quorum-behavior"
        }
      ]
    },
    {
      "id": "isolate-infected-host",
      "type": "action",
      "label": "Isolate infected host",
      "config": {
        "target": "endpoint",
        "description": "The hunt isolates the host to halt the autonomous decision loop.",
        "instructions": "Isolate the host from the network to stop the autonomous C2 loop and prevent credential exfiltration.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-manual-review",
      "type": "task",
      "label": "Analyst manual review",
      "config": {
        "assignee": "analyst",
        "description": "The analyst confirms the presence of the 16.4MB binary and any injected API keys.",
        "instructions": "Review the findings; confirm if the process identified is a legitimate AI tool or the CLOSEDQUORUM implant. Check for the 16.4MB binary and extract any injected API keys."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-infected-host"
        }
      ]
    },
    {
      "id": "close-hunt",
      "type": "task",
      "label": "Close hunt",
      "config": {
        "assignee": "analyst",
        "description": "The analyst documents the timeframe and providers used by the autonomous loop.",
        "instructions": "Document the findings, including any confirmed LLM API providers used and the timeframe of the autonomous activity."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-manual-review"
        }
      ]
    }
  ]
}