All Posts
Operationalized Threat Intelligence
1
min read

Malware Gets a Brain: How AI Decision-Making Is Replacing Hard-Coded C2 Logic

Published on
September 30, 2026
Table of Contents

The command-and-control model that defenders have spent two decades learning to detect assumes a human operator making tactical decisions, issuing instructions, and responding to feedback. Three malware families documented in 2025 and 2026 show that this assumption can no longer be treated as universal. ClosedQuorum, RatHat, and Carbonato each delegate elements of tactical decision-making to artificial intelligence models, reducing or removing the operator from the moment-to-moment kill chain. This is no longer a purely theoretical capability: AI-directed malware architectures now exist in functional malicious tooling, with some observed in active campaigns. Detection logic built around human-paced C2 cadence therefore needs to account for attack chains capable of making and executing decisions without continuous operator interaction.

ClosedQuorum: Four Models, One Vote

ClosedQuorum is a 16.4 MB Go-based Windows implant that does not receive instructions from an operator after deployment. Instead, it convenes an internal panel of 4 commercial large language models (LLMs): DeepSeek, Qwen, Mistral, and Google Gemini. The implant sends each model a system prompt identifying itself as "an advanced malware strategist" and requests a single typed JSON response from a fixed menu of 4 actions: steal credentials, inject code, establish persistence, or move laterally [1]. The majority vote determines execution. Ties break deterministically in DeepSeek's favor, followed by Qwen, then Mistral [2].

Each action is operationally complete. A "steal" vote triggers simultaneous LSASS memory dumps, browser password sweeps across Chrome, Edge, and Firefox, and cryptocurrency wallet extraction from MetaMask and Exodus. A "persist" vote creates 3 overlapping mechanisms at once:

  • a Registry Run key
  • a scheduled task
  • a WMI event subscription firing every 60 seconds via PowerShell

The implant also suppresses Event Tracing for Windows (ETW) telemetry by overwriting EtwEventWrite with a return instruction, blinding Windows logging for the session [1]. Data exits encrypted with AES-256-GCM via Discord webhooks in 1,900-byte chunks at 1-second intervals.

Cisco Talos researchers, who discovered ClosedQuorum through their open-source CAIRN toolkit, describe it as "an architectural shift towards attack-chain automation" [3]. No confirmed in-the-wild deployments have been observed, but recovered development builds contain real API credentials injected at compile time, suggesting per-operator commercial distribution rather than a research sample [1]. The lateral movement module exists in the code but is non-functional in the analyzed build, indicating active development.

The 4-model voting structure has a specific defensive implication: a single provider's content safety refusal cannot block the attack. Three remaining models can still form a plurality [1]. Operators also use legitimate commercial API endpoints as the implicit C2 channel, making domain-level blocking impractical without disrupting enterprise AI tooling across the organization.

RatHat: AI-Driven Device Takeover on Android

RatHat operates on a different platform but applies the same logic: remove human decision-making from device control. Security researchers at Zimperium zLabs discovered this Android malware, attributed to Chinese threat actors based on Mandarin-language LLM prompts found in the binary [4]. It distributes via SMS phishing, malvertising, and third-party APK sites.

RatHat abuses Android's AccessibilityService APIs to enable Developer Options and Wireless Debugging, extract the device's ADB pairing code, and establish a local ADB session that provides shell-level command execution without requiring an external computer [4]. It installs 2 persistent Go-based agents: one for keylogging and command execution via local ADB shell, the other establishing a reverse-proxy tunnel to the attacker's infrastructure [4]. The AI component serializes the live Android Accessibility tree into XML and queries an unnamed LLM to identify UI element coordinates, extract on-screen text, and issue navigation instructions such as scroll commands [5]. Zimperium researchers believe the LLM is Google's Gemini, inferred from internal graphs, though this is not explicitly confirmed in the report.

The result is a malware that can navigate any app interface dynamically, without pre-scripted flows. Traditional automation-based mobile fraud requires the attacker to anticipate every screen state. AI-driven UI navigation does not. RatHat adapts to whatever the device presents [4].

The anti-analysis engineering is deliberate friction. RatHat uses multiple techniques designed to frustrate reverse engineering, including APK container tampering, a 61 MB AndroidManifest.xml containing unusual data blocks, invalid DEX pseudo-instructions, and string obfuscation [4]. These measures can cause common analysis tools to fail, crash, or exhaust resources. It actively blocks removal by intercepting the uninstall confirmation screen and displaying a fake Google Play error overlay. The mutual restoration relationship between RatHat and its ADB agent means removing one component triggers the other to reinstall it [4].

Carbonato: AI Agents Targeting Infrastructure

Carbonato extends the pattern to infrastructure. Security researchers at ThreatDown discovered this botnet malware targeting Docker hosts with unauthenticated APIs exposed on port 2375 [6]. After gaining access, Carbonato opens a reverse SSH tunnel, installs an SSH server with the operator's key, and deploys the Hermes Agent AI framework under a persona named "GH0ST."

The model "interprets the task, writes terminal commands, reads the output, and decides what to do next," per ThreatDown's characterization [6]. The agent receives high-level task commands via Telegram, executes them autonomously on victim hosts, and returns results. It collects AI API keys, SSH credentials, and access tokens without operator involvement in each individual step. Carbonato also scans networks attached to every compromised host every 5 minutes for additional exposed Docker daemons, propagating without human direction [6].

The Hermes Agent framework used here is not purpose-built malware. It is a repurposed AI agent platform that has appeared in other malicious campaigns, including a card-skimming operation that stole 600,000 credit card details [6]. This matters because commodity AI agent frameworks are increasingly available and require minimal adaptation for offensive use.

Documented Escalation, Not Isolated Cases

A November 2025 AI threat tracker assessment from Google's Threat Intelligence Group identified 5 novel AI-enabled malware families that year, with 3 already observed in active operations [7]. PROMPTSTEAL, used by the Russian state-linked actor APT28 against Ukrainian targets, represents the first observed instance of malware querying an LLM during live operations to dynamically generate execution commands, using the open-source Qwen2.5-Coder model via the Hugging Face API [7]. PROMPTFLUX, attributed to an unidentified threat actor, uses the Gemini API to rewrite its own VBScript source code on an hourly cycle to evade detection [7].

Taken together, ClosedQuorum, RatHat, Carbonato, and the families documented in the Google threat assessment represent a documented escalation across a single calendar year. The competitive "first" claims across researchers reflect the speed of development, not a contradiction: different research teams are encountering different implementations of the same underlying architectural shift as it proliferates.

The Real Problem Is Autonomy, Not Evasion

The framing that AI integration is primarily an evasion upgrade understates the actual threat. Evasion is a component, but the structural change is autonomy. When a malware family makes its own tactical decisions, it removes the operator from the kill chain during active execution. That compresses the window between initial access and damage. It also breaks incident response assumptions.

Detection strategies that rely on the timing and cadence of interactive attacker activity become less reliable when parts of the attack chain execute autonomously. Carbonato scans attached networks and Docker bridges for new hosts every 5 minutes, while ClosedQuorum begins after an initial 5-minute delay and subsequently executes on randomized 5-to-15-minute cycles [1]. These actions can continue without an operator making each tactical decision in real time. "Human operators are bound by attention, working hours, and cognitive load; a panel of models voting in a loop isn't," as one security analyst noted [2].

The Defensive Gap

Signature-based detection was not designed for malware calling legitimate AI APIs as its C2 channel. Behavioral detection built on known C2 patterns was not designed for malware with no fixed C2 infrastructure at all. The CAIRN toolkit released alongside the ClosedQuorum disclosure identifies "cognitive artifacts" in malware binaries: embedded prompts, AI API endpoints, and orchestration logic that are detectable without execution [8]. That gives detection engineering a concrete foothold.

Research on ensemble detection architectures, including SimCLR-Gated Recurrent Unit (GRU) approaches that combine contrastive feature learning with temporal behavioral modeling, shows that adaptive detection is technically feasible [9]. These approaches address what signature-based methods cannot: behavioral patterns that change each cycle. However, laboratory performance figures do not translate directly to operational deployment. None of these frameworks are currently deployed at scale in enterprise environments.

The practical implication for detection engineers is specific. ClosedQuorum requires correlating LLM API calls to commercial endpoints against concurrent LSASS access, process injection indicators, or WMI persistence creation [2]. No single signal identifies it. The detection requires multi-signal correlation tuned to AI-augmented malware behavior, not a domain blocklist. An AI sandbox evasion technique first deployed by a red team researcher appeared in unrelated malware within 12 months [8]. That timeline applies here.

The C2 callback pattern that security operations tooling has been tuned to detect over two decades is being retired by a class of malware that has no dedicated C2 infrastructure, makes its own decisions, and operates at machine speed. Defenders who have not yet started instrumenting for decision-loop artifacts, LLM API call patterns, and autonomous propagation behavior are not slightly behind. They are operating with a detection model designed for a threat that is being actively replaced.

References

  1. TechTimes, "CLOSEDQUORUM: Windows Implant Uses Four-Model AI Voting Panel to Execute Attacks Without Human Command," 2026-09-23. [Online]. Available: https://www.techtimes.com/articles/327893/20260923/cisco-talos-discloses-autonomous-windows-malware-four-ai-models-direct-each-attack.htm [Accessed 28 Sep. 2026].
  2. Dev.to (or similar developer community platform), "CLOSEDQUORUM: AI-Directed Malware Using LLM Voting for Autonomous Decision-Making," Community blog platform (unverified), 2024. [Online]. Available: https://dev.to/thesnehamk/closedquorum-the-malware-that-lets-four-ai-models-vote-on-how-to-attack-you-g1d [Accessed 28 Sep. 2026].
  3. B. Toulas, "New ClosedQuorum Windows malware uses AI for attack decisions," BleepingComputer, Sep. 22, 2026. [Online]. Available: https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/ [Accessed 28 Sep. 2026].
  4. B. Toulas, "New RatHat Android malware uses AI to automate device control," BleepingComputer, 17-Sep-2026. [Online]. Available: https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/ [Accessed 28 Sep. 2026].
  5. HackTricks, "Android Accessibility Service Abuse," HackTricks, 2024. [Online]. Available: https://book.hacktricks.xyz/mobile-pentesting/android-app-pentesting/android-accessibility-service-abuse [Accessed 28 Sep. 2026].
  6. K. Poireault, "New Chinese-Made 'RatHat' Android Malware Leverages AI to Steal Financial Data," Infosecurity Magazine, 17-Sep-2026. [Online]. Available: https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/ [Accessed 28 Sep. 2026].
  7. B. Toulas, "New Carbonato malware uses AI agents to hijack exposed Docker hosts," BleepingComputer, Sep. 24, 2026. [Online]. Available: https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/ [Accessed 28 Sep. 2026].
  8. Google Threat Intelligence Group, "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools," Google Threat Intelligence Group, 2025. [Online]. Available: https://cloud.google.com/blog/topics/threat-intelligence/gtig-ai-threat-tracker-advances-in-threat-actor-usage-of-ai-tools [Accessed 28 Sep. 2026].
  9. Unknown (unidentified blog/website), "Researchers uncover malware that uses AI to choose its next move," Unknown, 2025. [Online]. Available: https://www.news4hackers.com/ai-powered-malware-emerges-with-strategic-decision-making-capabilities/ [Accessed 2025].

How Anomali Can Help

As AI-driven C2 logic evades static signatures, out-of-the-box detections, malware intelligence feeds, and dedicated C2 detection close the gap.

  • Anomali provides out-of-the-box detections aligned to MITRE ATT&CK, covering the TTPs described above so teams can deploy coverage for these techniques without writing rules from scratch.
  • Anomali's Malware Intelligence Channel tracks 300+ malware and ransomware families, delivering real-time hashes, IPs, domains, and C2 infrastructure indicators for the families described above, curated by the Anomali Threat Research team.
  • Anomali C2 Detection provides outside-in visibility of compromised hosts beaconing to the adversary command-and-control infrastructure described above, identifying affected systems even before internal endpoint tooling fires.

Does your current stack detect AI-driven C2 behavior before it adapts past your defenses?

Talk to Anomali.

‍

FEATURED RESOURCES

September 29, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Windows, Salesforce & Citrix Threats

Latest cyber threats: Windows Defender & CLOSEDQUORUM implants, Salesforce SalesBleed data leaks, Oracle WAF bypasses, Citrix zero-days, and more.
Read More
September 28, 2026
AI
Operationalized Threat Intelligence

From Feeds to Agents: What the AI Shift Asks of Your Data Foundation

New Gartner® research examines AI in cyberthreat intelligence operations. Our view on why the data foundation decides what your agents can safely do.
Read More
September 30, 2026
Operationalized Threat Intelligence

Malware Gets a Brain: How AI Decision-Making Is Replacing Hard-Coded C2 Logic

Read More
Explore All