{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Autonomous AI implants collapse the decision space of an attack, requiring response speeds that outpace human analysts; confirming the absence of these specific endpoint behaviors ensures no such system is active."
      },
      "name": "CLOSEDQUORUM AI Payload Actions",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1003",
        "attack.t1003.001",
        "attack.t1047",
        "attack.t1055",
        "attack.t1071",
        "attack.t1566"
      ],
      "series": {
        "slug": "the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant",
        "index": 2,
        "title": "The Closed Quorum: Inside the first reported autonomous AI C2 implant",
        "total": 2
      },
      "related": [
        {
          "hunt": "autonomous-llm-c2-network-correlation",
          "reason": "This hunt focuses on endpoint actions; correlating the multi-provider network traffic requires a separate network-centric hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "autonomous-llm-decision-loop",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule for LSASS access or WMI creation exists, but this hunt pivots across three independent capabilities (steal, inject, persist) and uses prevalence to find the rare behaviors an autonomous implant produces that a static rule would miss.",
      "coverage": [
        {
          "stage": "persistence-establishment",
          "steps": [
            "wmi-persistence-baseline"
          ],
          "status": "covered"
        },
        {
          "stage": "process-injection-execution",
          "steps": [
            "injected-code-detection"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-and-wallet-theft",
          "steps": [
            "wallet-access-lead"
          ],
          "status": "covered"
        },
        {
          "stage": "host-discovery-initialization",
          "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "autonomous-llm-c2",
          "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Host Discovery and Initialization",
            "slug": "host-discovery-initialization",
            "tactic": "discovery",
            "techniques": [
              "T1047"
            ],
            "observables": [
              "gatherSystemInfo() function call",
              "Collection of hostname, Windows version, CPU count, and architecture",
              "Admin status check"
            ]
          },
          {
            "name": "Autonomous LLM C2 Orchestration",
            "slug": "autonomous-llm-c2",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "main.queryLLM() function call",
              "ModelOrchestrator polling DeepSeek, Qwen, Mistral, and Google Gemini APIs",
              "Structured JSON prompts containing 'TARGET: %s' context",
              "Polling intervals of 5 to 15 minutes",
              "Discord webhooks for operator telemetry"
            ]
          },
          {
            "name": "WMI Persistence",
            "slug": "persistence-establishment",
            "tactic": "persistence",
            "techniques": [
              "T1047"
            ],
            "observables": [
              "establishPersistence() function call",
              "WMI event subscription creation"
            ]
          },
          {
            "name": "Process Injection",
            "slug": "process-injection-execution",
            "tactic": "defense-evasion",
            "techniques": [
              "T1055"
            ],
            "observables": [
              "injectProcess() function call",
              "earlyBirdInject() function call",
              "PEB-walk process hollowing",
              "APC injection into suspended processes"
            ]
          },
          {
            "name": "Credential and Wallet Harvesting",
            "slug": "credential-and-wallet-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1003",
              "T1003.001"
            ],
            "observables": [
              "lsassDump() function call",
              "dumpBrowserCredentials() targeting Chrome, Edge, and Firefox",
              "extractCryptoWallets() function call",
              "Access to 'exodus.wallet'",
              "Access to MetaMask Chrome extensions",
              "Access to 'ethPath' Ethereum wallets"
            ]
          }
        ],
        "summary": "CLOSEDQUORUM is an autonomous Windows implant that uses a panel of commercial LLMs (DeepSeek, Mistral, Gemini, Qwen) as its command-and-control infrastructure. The malware independently gathers host information, polls the LLM providers for instructions, and uses a plurality voting mechanism to execute actions including credential theft, process injection, and WMI-based persistence, exfiltrating data via Discord webhooks."
      },
      "severity": "high",
      "rationale": "Focus on developer workstations and hosts with high-value crypto identities. Widen history if the hunt finds any injected code without a lead hit.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An autonomous AI implant is performing credential theft, process injection, or WMI persistence based on plurality-vote decisions reached by a panel of LLM providers.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-scoping",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "list[host]",
          "default": [],
          "description": "Specific hosts to focus the investigation on; defaults to the whole estate."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "wallet_targets": {
          "from": {
            "ref": "talos-closedquorum",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "list[string]",
          "default": [
            "exodus.wallet",
            "wallet.dat",
            "ethpath",
            "metamask"
          ],
          "description": "Specific filenames associated with targeted crypto wallet files named in the research."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/",
          "name": "The Closed Quorum: Inside the first reported autonomous AI C2 implant"
        }
      ],
      "blind_spots": [
        {
          "id": "no-memory-visibility",
          "risk": "The implant's injection module may leave no persistent process trace after its execution cycle completes, making it invisible to point-in-time snapshots.",
          "owner": "Detection Engineering",
          "stage": "process-injection-execution",
          "question": "Was the code injected into a process that has since terminated?",
          "requires": "EDR memory scanning or thread injection telemetry",
          "remediation": "Enable high-fidelity process injection events in the EDR."
        },
        {
          "id": "tls-prompt-invisibility",
          "risk": "Without inspecting the HTTPS traffic to DeepSeek or Gemini, we cannot see the structured JSON decision and reasoning fields being sent to the implant.",
          "owner": "Network Security",
          "question": "What reasoning is the AI providing for its actions?",
          "requires": "TLS inspection for LLM provider domains",
          "remediation": "Deploy TLS inspection for known AI API endpoints on sensitive hosts."
        }
      ]
    },
    "name": "CLOSEDQUORUM AI Payload Actions",
    "description": "This hunt identifies the endpoint artifacts of CLOSEDQUORUM decisions: specifically, the steal capability targeting crypto wallets, the inject capability using process hollowing or APC injection, and the persist capability using WMI event subscriptions. The hunt starts with a lead query for wallet access to identify potentially compromised hosts, then fans out to detect fileless code and rare WMI persistence commands across the estate. An agent weighs the combined telemetry to confirm the presence of an autonomous implant session."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant",
          "index": 2,
          "title": "The Closed Quorum: Inside the first reported autonomous AI C2 implant",
          "total": 2
        },
        "coverage": [
          {
            "stage": "persistence-establishment",
            "steps": [
              "wmi-persistence-baseline"
            ],
            "status": "covered"
          },
          {
            "stage": "process-injection-execution",
            "steps": [
              "injected-code-detection"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-and-wallet-theft",
            "steps": [
              "wallet-access-lead"
            ],
            "status": "covered"
          },
          {
            "stage": "host-discovery-initialization",
            "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "autonomous-llm-c2",
            "reason": "Belongs to another part of the 'The Closed Quorum: Inside the first reported autonomous AI C2 implant' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An autonomous AI implant is performing credential theft, process injection, or WMI persistence based on plurality-vote decisions reached by a panel of LLM providers.",
        "blind_spots": [
          {
            "id": "no-memory-visibility",
            "risk": "The implant's injection module may leave no persistent process trace after its execution cycle completes, making it invisible to point-in-time snapshots.",
            "owner": "Detection Engineering",
            "stage": "process-injection-execution",
            "question": "Was the code injected into a process that has since terminated?",
            "requires": "EDR memory scanning or thread injection telemetry",
            "remediation": "Enable high-fidelity process injection events in the EDR."
          },
          {
            "id": "tls-prompt-invisibility",
            "risk": "Without inspecting the HTTPS traffic to DeepSeek or Gemini, we cannot see the structured JSON decision and reasoning fields being sent to the implant.",
            "owner": "Network Security",
            "question": "What reasoning is the AI providing for its actions?",
            "requires": "TLS inspection for LLM provider domains",
            "remediation": "Deploy TLS inspection for known AI API endpoints on sensitive hosts."
          }
        ],
        "scoping_notes": "Focus on developer workstations and hosts with high-value crypto identities. Widen history if the hunt finds any injected code without a lead hit.",
        "beyond_detection": "A single rule for LSASS access or WMI creation exists, but this hunt pivots across three independent capabilities (steal, inject, persist) and uses prevalence to find the rare behaviors an autonomous implant produces that a static rule would miss."
      }
    },
    {
      "id": "wallet-access-lead",
      "type": "query",
      "label": "Lead: Crypto wallet harvesting",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, file_path, file_name, time FROM hb_file_activity WHERE (instr(',' || '{{wallet_targets}}' || ',', ',' || LOWER(file_name) || ',') > 0 OR instr(',' || '{{wallet_targets}}' || ',', ',' || LOWER(file_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify hosts where a process has accessed file paths or names associated with the implant's steal capability.",
        "expected_signal": "Rows naming a Go-compiled binary or a suspicious system process reading wallet files. Silence suggests the 'steal' module has not executed."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Lead: Crypto wallet harvesting",
        "reads": [
          "device_hostname",
          "process_name",
          "file_path",
          "file_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, file_path, file_name, time FROM hb_file_activity WHERE (instr(',' || '{{wallet_targets}}' || ',', ',' || LOWER(file_name) || ',') > 0 OR instr(',' || '{{wallet_targets}}' || ',', ',' || LOWER(file_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows naming a Go-compiled binary or a suspicious system process reading wallet files. Silence suggests the 'steal' module has not executed.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "injected-code-detection",
      "type": "query",
      "label": "Detect injected or fileless code",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE on_disk = 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find processes running without a binary on disk to detect the implant's process hollowing and APC injection modules.",
        "expected_signal": "Legitimate system processes like svchost.exe or explorer.exe running without a corresponding file on disk."
      },
      "parents": [
        {
          "id": "wallet-access-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Detect injected or fileless code",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time",
          "on_disk"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE on_disk = 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Legitimate system processes like svchost.exe or explorer.exe running without a corresponding file on disk.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "wmi-persistence-baseline",
      "type": "query",
      "label": "WMI event subscription baseline",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%wmic.exe' OR LOWER(process_name) LIKE '%scrcons.exe') AND (LOWER(process_cmd_line) LIKE '%activescripteventconsumer%' OR LOWER(process_cmd_line) LIKE '%commandlineeventconsumer%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING host_count <= 5 ORDER BY host_count ASC",
        "surface": "hb_process_activity",
        "description": "Stack-count WMI commands to isolate rare permanent event consumers created by the implant's persistence module.",
        "expected_signal": "A rare WMI command creating a permanent event consumer. Silence confirms no rare WMI persistence was established in the window."
      },
      "parents": [
        {
          "id": "wallet-access-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "WMI event subscription baseline",
        "reads": [
          "process_cmd_line",
          "device_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%wmic.exe' OR LOWER(process_name) LIKE '%scrcons.exe') AND (LOWER(process_cmd_line) LIKE '%activescripteventconsumer%' OR LOWER(process_cmd_line) LIKE '%commandlineeventconsumer%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING host_count <= 5 ORDER BY host_count ASC",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A rare WMI command creating a permanent event consumer. Silence confirms no rare WMI persistence was established in the window.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-quorum-actions",
      "type": "analytic",
      "label": "Triage quorum actions",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "wallet-access-lead",
          "injected-code-detection",
          "wmi-persistence-baseline"
        ],
        "objective": "Determine if the observed endpoint behavior matches the known 'steal', 'inject', and 'persist' modules of the CLOSEDQUORUM implant.",
        "description": "Analyze the combined evidence of wallet access, process hollowing, and WMI persistence to confirm an autonomous attack session.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict linking these behaviors into a single intrusion timeline.",
        "success_criteria": "A verdict of malicious | suspicious | benign per host, citing specific rows of activity."
      },
      "parents": [
        {
          "id": "injected-code-detection",
          "kind": "merge"
        },
        {
          "id": "wmi-persistence-baseline",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host exhibiting wallet access, injected code, or suspicious WMI persistence",
        "condition": "the triage verdict is malicious for at least one host exhibiting wallet access, injected code, or suspicious WMI persistence",
        "blind_spot": "no-memory-visibility",
        "confidence": "high",
        "description": "Direct the response based on the agent's confidence in the presence of an autonomous implant.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-quorum-actions"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Immediately sever the autonomous C2 loop to prevent further credential theft.",
        "instructions": "Isolate the host and preserve memory to analyze the injected thread and LLM API keys.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-review",
      "type": "task",
      "label": "Forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Search for the source of the injected code to identify the original implant binary.",
        "instructions": "Search the host for a Go-compiled binary (approx 16MB) in user profile or %TEMP% directories. Recover any Discord webhook URLs found in memory or strings."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "hunt-close-out",
      "type": "task",
      "label": "Hunt close out",
      "config": {
        "assignee": "analyst",
        "description": "Record findings and document any new wallet paths for future hunting.",
        "instructions": "Record the specific WMI event filter logic and the user account used for wallet access. Document any LLM provider domains observed in network traffic."
      },
      "parents": [
        {
          "id": "forensic-review"
        }
      ]
    }
  ]
}