CLOSEDQUORUM malware reportedly uses LLM quorum to autonomously select post-compromise actions
Why it matters — This malware removes the human bottleneck from the post-compromise phase, allowing attacks to continue indefinitely and at a scale that exceeds operator attention spans. Defenders can no longer rely on blocking specific C2 domains, as the malware uses legitimate AI provider endpoints, forcing a shift toward behavioral detection of combined malicious activities.