TTO-2026-0922-153 · September 22, 2026 MalwareAI-Assisted

ClosedQuorum Windows Malware Uses Embedded AI Model to Make Autonomous Attack Decisions Without C2 Contact

Symantec Threat Hunter researchClosedQuorum malwareEmbedded on-device AI decision engineNo C2 contact required for attack decisionsWindows lateral movement and credential theftFinancially motivated threat actorSeptember 2026

Summary

Symantec Threat Hunter has published analysis of ClosedQuorum, a previously undocumented Windows malware family that incorporates an embedded lightweight AI model to make autonomous attack decisions during post-exploitation activity without requiring contact with command-and-control infrastructure. Unlike prior AI-assisted malware families that query external AI APIs, ClosedQuorum runs its decision engine entirely on the compromised host using a quantized language model small enough to execute on consumer hardware without GPU acceleration. The on-device model receives observations about the local network environment, running processes, and discovered credentials, and produces decisions about which lateral movement paths to pursue, which credentials to prioritize, and when to pause activity to avoid detection. The malware was attributed to a financially motivated threat actor operating primarily against financial services and professional services organizations.

Timeline

DateEvent
Mid-2026ClosedQuorum samples first captured in Symantec telemetry during incident response at financial services firm
August-September 2026Symantec Threat Hunter completes full technical analysis of ClosedQuorum AI decision engine architecture
Sep 21, 2026BleepingComputer reports Symantec findings; Symantec publishes indicators of compromise

What Happened

ClosedQuorum is delivered as a second-stage payload after initial access is established through phishing or exploitation of public-facing services. In the reconnaissance phase it collects information about the local system and network: running processes, installed software, network neighbors, domain controller presence, discovered file shares, and credentials accessible through Windows Credential Manager, browser stores, and LSASS memory. This reconnaissance output is serialized and passed to the embedded AI model.

The on-device AI model is a quantized transformer architecture with approximately 1.3 billion parameters, small enough to load into RAM on a standard business workstation without requiring dedicated GPU hardware and without installing any visible software dependency. The model was trained or fine-tuned on attack playbook data and receives the reconnaissance output as a structured prompt. It produces an ordered list of recommended next actions: which network paths to attempt lateral movement through, which credential sets to prioritize testing against which targets, whether current network activity levels make movement safe or suggest pausing, and which data repositories to target for exfiltration based on apparent value.

The architectural significance of ClosedQuorum is the elimination of the C2 callback requirement for decision-making. Conventional post-exploitation frameworks require periodic communication with command-and-control infrastructure to receive operator instructions — a communication that network monitoring tools detect as anomalous outbound beaconing. ClosedQuorum’s on-device decision engine means the malware can pursue lateral movement and credential testing activities with no outbound network communication beyond the attacks themselves, which blend into normal network traffic patterns. The C2 infrastructure is only contacted for data exfiltration, not for instructions, significantly reducing the malware’s network detection footprint during its most active operational phase.

Note on Domain Intelligence

ClosedQuorum is a malware family targeting financial services and professional services organizations. No single named victim domain is the subject of this bulletin. Domain intelligence for specific targeted organizations is available at warmbadge.com where those domains have been evaluated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 22, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026