CLOSEDQUORUM:首个让四个 AI 模型投票决定下一步的 Windows 植入体

·阅读约11分钟·Evergreen Tools Team

2026 年 9 月 22 日,Cisco Talos 公开了一个名为 CLOSEDQUORUM 的 Windows 植入体。它最反常识的地方不在加密、不在免杀,而在于:部署之后,它不再等待任何人类指令,而是召集四个商用大模型——DeepSeek、Qwen、Mistral 和 Google Gemini——就下一个攻击动作投票,然后执行胜出的那一个。Talos 说,这是它已知的第一个把 C2(命令与控制)决策交给模型的公开记录的 Windows 植入体。

Talos 到底发现了什么

先说清楚已确认的事实。CLOSEDQUORUM 是一个 64 位、Go 语言编写的 Windows 植入体,通过 Talos 同日发布的 CAIRN 研究工具集发现——CAIRN 是用来猎捕、分类和追踪「AI 集成型恶意软件」的。它的核心机制是:把某个攻击阶段压缩成一道有限选项的选择题,四个模型各自作答,多数票胜出,二进制执行赢家。Talos 表示,目前没有确认它在真实环境中被部署;它从二进制里提取的痕迹,把开发者关联到了 2025 年的信用卡盗刷论坛帖。此前的代号 BALZAK 现已更名为 CLOSEDQUORUM。

// The shape of the trick: collapse a phase of the attack into a multiple-choice
// question, then let several independent models vote. LLMs are most reliable
// exactly where the output space is small.

type Action struct {
    Verb   string // "credential_dump" | "inject" | "persist"
    Target string
}

var candidates = []Action{
    {Verb: "credential_dump", Target: "lsass"},
    {Verb: "inject", Target: "explorer.exe"},
    {Verb: "persist", Target: "Run\\Software"},
}

// Ask N models the same constrained question. Majority wins. No operator needed.
func quorum(ask func(Action) bool, acts []Action) Action {
    tally := map[Action]int{}
    for _, a := range acts {
        if ask(a) {
            tally[a]++
        }
    }
    var best Action
    for a, n := range tally {
        if n > tally[best] || (n == tally[best] && a.Verb < best.Verb) {
            best = a
        }
    }
    return best
}
被投票驱动的恶意软件

第一次有公开记录的 Windows 植入体把 C2 决策交给模型投票

为什么是「投票」,以及为什么这很重要

关键不在于「三个模型达成一致」这个噱头,而在于它把攻击者的精力挪到了哪里。LLM 最可靠的地方,恰恰是输出空间被收窄成有限选项的时候。CLOSEDQUORUM 把「窃取凭据、进程注入、建立持久化」这三条路交给模型去推理,等于把战术决策从人类操作员手里彻底摘掉。Talos 的措辞很克制:这是一种「精力位移」——攻击链条中越来越大的部分,可以在没有操作员参与的情况下执行。一个失去连接、去睡觉或换时区的攻击者,不再会中断一场正在进行的攻击。

// The vote is only half the design. The other half is the transport: results are
// delivered through a chat webhook, so there is no attacker-owned C2 domain to
// blocklist. That is the part your egress policy has to catch instead.

type VoteRecord struct {
    Provider string // "deepseek" | "qwen" | "mistral" | "gemini"
    Chosen   string
    At       int64
}

func report(votes []VoteRecord, hook string) error {
    body := map[string]any{"content": votes, "username": "sync"}
    payload, _ := json.Marshal(body)
    // One POST to a chat endpoint is indistinguishable from normal API traffic
    // unless you are watching which processes are allowed to make it.
    return post(hook, "application/json", payload)
}

目前阻止它扩散的那些细节

先别恐慌,有几条硬约束值得记住。每一份副本都需要 API 密钥和一个真实的 Discord webhook;测试版本显示,密钥是在构建时被编译进程序的,公开版本的密钥和 webhook 都是占位符,因此它既够不到模型,也发不出数据。Talos 为开发过程中的六个构建公布了 SHA-256 哈希。还有一个实操细节:The Hacker News 在 9 月 23 日检查时发现,CAIRN 随附的规则文件里并没有 CLOSEDQUORUM 的检测规则——你需要自己手动加进去。

# You cannot blocklist your way out of a quorum C2. You can watch who is calling
# model providers, from where, and with whose key. Start with the outflow.

# 1) Which hosts in this fleet have ever resolved a model-provider endpoint?
for host in $(cat fleet.txt); do
  dig +short @$host api.deepseek.com api.mistral.ai generativelanguage.googleapis.com \
    | grep -q . && echo "MODEL EGRESS: $host"
done

# 2) Which local processes hold provider credentials they should not?
#    A desktop app should not carry an inference key compiled into it.
sudo lsof -nP | grep -Ei 'deepseek|mistral|generativelanguage' || echo "clean"
监控出站 API 调用

当 C2 变成「模型调用」,出站流量就是新的检测面

当攻击者是一票「投票」,怎么防

传统检测问的是「这个 C2 域名归谁」。当 C2 变成一次模型调用,那个问题就失效了。新的检测面是出站:哪个进程在调用模型供应商、用谁的密钥、从哪台机器发出。一台台式机应用不应该内置一个推理密钥;一个进程在一次会话里同时连通三家以上模型厂商,本身就该被标记。这不是银弹,但它把「无可阻断的 C2」重新拉回了可观测的范畴。

// Turn the Talos guidance into a rule you can actually run. The point is not the
// hash of one sample; it is the shape: a process that fans out to several model
// vendors in one session is worth an alert.

type EgressEvent struct { PID int; Host string; At int64 }

func flagMultiVendor(window []EgressEvent, providers map[string]bool) bool {
    seen := map[string]bool{}
    for _, e := range window {
        if providers[e.Host] {
            seen[e.Host] = true
        }
    }
    // One process, three or more model vendors, no user-driven feature that needs it.
    return len(seen) >= 3
}

// Pair this with key hygiene: keys should be short-lived, scoped, and never
// compiled into a binary where a security tool can recover them at rest.

今天就能加进流水线的四件事

第一,盘点出站:哪些主机解析过模型供应商的域名,哪些进程持有本不该有的推理密钥。第二,密钥卫生:密钥要短时效、有作用域,绝不编译进二进制。第三,告警规则:单一进程单次会话触达三家以上模型厂商,值得一条告警。第四,哈希核对:Talos 公布了六个构建的 SHA-256,先哈希,再谈规则。这四件事任何一个专职团队当下就能做,而它们对「没有硬编码 IP 的植入体」同样有效。

// Finally, verify what you were told. Talos published SHA-256 hashes for six
// builds from the malware's development, and its CAIRN rule file did not ship a
// CLOSEDQUORUM rule at first. Hash first, then rule.

import hashlib, pathlib

def sha256_file(p: str) -> str:
    h = hashlib.sha256()
    with open(p, "rb") as f:
        for chunk in iter(lambda: f.read(65536), b""):
            h.update(chunk)
    return h.hexdigest()

def match_known_hashes(path: str, known: set[str]) -> bool:
    return sha256_file(path) in known

# Do the same for every build artifact you keep. An implant that never ships a
# single hardcoded IP is exactly the kind that survives until you hash it.
多模型路由

四个供应商、一次投票、零人工指令

噪音背后的信号

把这件事放进趋势里看:把 AI 塞进恶意软件的尝试,正在从「给人类攻击者更好的工具」转向「让攻击链条自己跑」。必须区分事实与判断——事实是 Talos 披露了这么个样本、附上了哈希与 IOCs,并且明确说尚未确认野外部署;判断是「这会成为常态」。样本本身是概念验证,但它演示的那套「把决策空间收窄、再交给多个模型投票」的模式,是任何有 API 预算的人都能复制的。真正值得你今天调整的,不是某个哈希,而是你的出站假设。

📌 常见问题 FAQ

CLOSEDQUORUM 是什么?

它是 Cisco Talos 于 2026 年 9 月 22 日披露的一个 64 位 Go 编写的 Windows 植入体。其特殊之处在于:部署后由四个商用大模型(DeepSeek、Qwen、Mistral、Google Gemini)投票决定下一个攻击动作,然后执行胜出选项,无需人类操作员下达指令。Talos 称这是它已知首个公开记录的、把 C2 决策交给模型的 Windows 植入体。

Talos 说它在真实环境中被发现了吗?

没有。Talos 明确表示目前没有确认的野外部署。不过,从二进制中提取的痕迹把它关联到了 2025 年的信用卡盗刷论坛帖,说明开发者有犯罪背景。它此前被追踪为 BALZAK,后更名为 CLOSEDQUORUM。

它真的能跑起来吗,需要什么?

每份副本需要 API 密钥和一个真实的 Discord webhook。测试版本中密钥在构建时被编译进程序;公开版本里两者都是占位符,因此它既无法访问模型也无法外发数据。这也意味着它作为样本可被安全研究,而不是即插即用的武器。

为什么用「投票」而不是单个模型?

因为把决策空间收窄成有限选项后,LLM 的表现最可靠。多个独立模型投票可以降低单一模型出错或拒答的影响,同时把战术推理从人类操作员手中移走——攻击链条中更大的一部分可以在无人参与下运行。

我该怎么检测这类威胁?

从出站开始,而不是域名黑名单:盘点哪些主机解析过模型供应商端点、哪些进程持有推理密钥、哪个进程在单次会话中同时调用三家以上模型厂商。同时核对 Talos 公布的 SHA-256 哈希,并记得 CAIRN 的规则文件最初并未内置 CLOSEDQUORUM 规则,需要手动加入。