Summary
Symantec Threat Hunter has published analysis of ClosedQuorum, a previously undocumented Windows malware family that incorporates an embedded lightweight AI model to make autonomous attack decisions during post-exploitation activity without requiring contact with command-and-control infrastructure. Unlike prior AI-assisted malware families that query external AI APIs, ClosedQuorum runs its decision engine entirely on the compromised host using a quantized language model small enough to execute on consumer hardware without GPU acceleration. The on-device model receives observations about the local network environment, running processes, and discovered credentials, and produces decisions about which lateral movement paths to pursue, which credentials to prioritize, and when to pause activity to avoid detection. The malware was attributed to a financially motivated threat actor operating primarily against financial services and professional services organizations.
Timeline
| Date | Event |
|---|---|
| Mid-2026 | ClosedQuorum samples first captured in Symantec telemetry during incident response at financial services firm |
| August-September 2026 | Symantec Threat Hunter completes full technical analysis of ClosedQuorum AI decision engine architecture |
| Sep 21, 2026 | BleepingComputer reports Symantec findings; Symantec publishes indicators of compromise |
What Happened
ClosedQuorum is delivered as a second-stage payload after initial access is established through phishing or exploitation of public-facing services. In the reconnaissance phase it collects information about the local system and network: running processes, installed software, network neighbors, domain controller presence, discovered file shares, and credentials accessible through Windows Credential Manager, browser stores, and LSASS memory. This reconnaissance output is serialized and passed to the embedded AI model.
The on-device AI model is a quantized transformer architecture with approximately 1.3 billion parameters, small enough to load into RAM on a standard business workstation without requiring dedicated GPU hardware and without installing any visible software dependency. The model was trained or fine-tuned on attack playbook data and receives the reconnaissance output as a structured prompt. It produces an ordered list of recommended next actions: which network paths to attempt lateral movement through, which credential sets to prioritize testing against which targets, whether current network activity levels make movement safe or suggest pausing, and which data repositories to target for exfiltration based on apparent value.
The architectural significance of ClosedQuorum is the elimination of the C2 callback requirement for decision-making. Conventional post-exploitation frameworks require periodic communication with command-and-control infrastructure to receive operator instructions — a communication that network monitoring tools detect as anomalous outbound beaconing. ClosedQuorum’s on-device decision engine means the malware can pursue lateral movement and credential testing activities with no outbound network communication beyond the attacks themselves, which blend into normal network traffic patterns. The C2 infrastructure is only contacted for data exfiltration, not for instructions, significantly reducing the malware’s network detection footprint during its most active operational phase.
Note on Domain Intelligence
ClosedQuorum is a malware family targeting financial services and professional services organizations. No single named victim domain is the subject of this bulletin. Domain intelligence for specific targeted organizations is available at warmbadge.com where those domains have been evaluated.
The Trust Observatory · thetrustobservatory.com · September 22, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026