Two Malware Families Handed the Wheel to an LLM This Week. One Spends Inference, the Other Steals It. We Held Six of Fourteen Indicators and Could Not Find Them by Name.
Two research teams published on the same day, September 22, and between them they describe both halves of the category we have been calling tokentheft: the theft of metered inference capacity. Cisco Talos found a Windows implant that asks four commercial AI models to vote on what it should steal next. ThreatDown, the Malwarebytes research team, found a botnet that worms through exposed Docker hosts, installs an AI agent on each one, and tells that agent to go find AI API keys before it goes looking for anything else.
One spends inference to make decisions. The other steals inference to fund the operation. That's the story, and it's also a fair description of where we held up and where we didn't.
CLOSEDQUORUM: the committee in the implant
Ryan Fetterman at Cisco Talos calls CLOSEDQUORUM the first publicly documented Windows implant that hands tactical command and control to a panel of commercial LLMs. It is written in Go. After it lands, it takes a reconnaissance snapshot of the host and shows the same snapshot to up to four providers: DeepSeek, Qwen, Mistral and Google Gemini. Each model picks from a fixed menu rather than writing free-form commands. The menu is harvest Windows credentials, pull saved browser passwords, go after cryptocurrency wallet files, inject into another process, or establish persistence. Ties go to DeepSeek, then Qwen, then Mistral, then Gemini. Results leave through a Discord webhook.
There is no human operator in that loop and no attacker-run C2 server. That's the part worth sitting with. The traditional network tell of an implant, a beacon to infrastructure somebody registered, is replaced by calls to the same API hosts your developers use every day.
Talos is careful about the limits, and so are we. They have not confirmed CLOSEDQUORUM in a real attack. The public sample carries placeholder API keys and a dummy webhook, so nobody watched it run end to end. Artifacts in the binary tie its developer to carding-forum posts going back to 2025. Talos found it with CAIRN, a new toolkit for hunting AI-integrated malware from metadata alone, and they open-sourced it. That's the right way to ship a discovery like this, and it deserves the credit.
CARBONATO: the agent that goes shopping for keys
ThreatDown found CARBONATO the way you sometimes find the best evidence: its operators left a Docker registry open. Nearly 60 repositories and 4.3 GB of images, with operational evidence running from October 2024 to August 2026.
The chain is plain. It finds a Docker daemon listening on port 2375 with no authentication, tells it to launch a privileged container with the host filesystem mounted, and owns the host. It opens a reverse SSH tunnel to a relay in Costa Rica, installs an SSH server with the operators' key, and reports the new node over Telegram. Then it installs Hermes Agent, an unmodified open-source agent framework, and overwrites the agent's persona file, SOUL.md, with instructions to exploit, persist and collect. Tasking arrives over Telegram. In ThreatDown's words, the model "interprets the task, writes terminal commands, reads the output, and decides what to do next." Every five minutes it scans the neighboring /24 for more open Docker daemons and repeats the process without an operator.
The loot list is the tell. At the top, above SSH keys and cloud tokens, are AI API keys for OpenAI, Anthropic, Google and Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM and One API. The operators also run their own LLM gateway and a set of LLM proxies on Vercel. An agent that needs inference to work, and whose first job is to steal inference: the botnet pays for itself with your bill.
The same category from two directions
The detection lesson is the one tokentheft always teaches. Whether you can see it depends on the shape of your normal. A Windows laptop in accounting that has never spoken to an LLM API and suddenly calls three of them in a minute is loud. A developer workstation that talks to all four all day is not. A Docker host whose provider bill doubles overnight is loud if somebody is watching the bill and silent if nobody is.
What a cash-poor defender does on Monday
For CARBONATO, which has real infrastructure, start with your own exposure. Nothing should answer on tcp/2375 from outside the host, and on most machines nothing should answer at all. If you run Docker remotely, it belongs on 2376 with TLS client certificates, or behind SSH. Block the five IPs below. Then hunt for the artifacts ThreatDown published: images or containers named gh0st, fsociety, netd-svc, system/resolved or scrub-empty; a file at /usr/local/bin/.docker-network-monitor; environment variables GH0ST_C2, FSOCIETY_DISABLE_TUNNEL or CARBONATO_API_KEY; an immutable cron or systemd hook that re-pulls an image you don't recognize; and any /usr/sbin/systemd-logind that isn't the one your package manager installed. If you find any of it, assume every AI API key, SSH key and cloud token on that host is gone, and rotate them before you start cleaning up.
Put a hard spending cap and an alert on every LLM provider account you have. That's the cheapest tokentheft detector there is, and it works on both of these families.
For CLOSEDQUORUM, there is no attacker infrastructure to block, and you should not block the AI providers either. The API hosts it calls are the same ones your business uses, so we deliberately left them out of the feed. What you can do is decide which executables are allowed to reach LLM APIs and alert on everything else, especially a process that also posts to a Discord webhook and touches LSASS or browser credential stores in the same window. Block the six hashes.
What we held, and what we didn't
Both timestamps, side by side, because that's the rule.
CLOSEDQUORUM: Talos published September 22. Our vendor-blog watcher ingested all six SHA256 hashes at 19:48 UTC the same day, conf 80, which put them in the hash feed within hours. That's a same-day ingest of Talos's work, not a detection lead, and we're not claiming one. The miss is quieter. The watcher wrote those six hashes with an empty malware family, so a search for CLOSEDQUORUM in our own corpus returned nothing. A defender who pulled our feed was protected. A defender who asked us whether we knew about CLOSEDQUORUM was told, in effect, no. This batch re-tags all six with the family name and attribution.
CARBONATO: we held none of the eight network indicators, five IPs and three Vercel proxy hostnames, until this batch. ThreatDown published no file hashes, so there are none to feed. The Vercel proxies are already suspended, so they go in at confidence 75, below our own edge-shield floor. Your min_confidence setting decides whether you block them.
One more zero, stated so nobody has to find it: ThreatDown withheld the registry fleet's IPs while those hosts are live. We don't have them, and we're not going to guess.
Indicators
CARBONATO network, per ThreatDown, all operator infrastructure: 45.79.183.61 (C2 hub), 91.99.195.164 (earlier fsociety-era C2), 213.136.79.115 (beacon and reverse shell), 213.136.83.197 (operator LLM gateway), 190.211.124.187 (reverse-tunnel sink, Costa Rica). LLM proxies, suspended: carbonato-proxy-drab.vercel.app, carbonato-proxy-zeta.vercel.app, carbonato-proxy-zeta-2.vercel.app. Block the exact hostnames, never vercel.app.
CLOSEDQUORUM SHA256, per Cisco Talos: 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7, c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7, c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f, f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c, 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb, eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5.
All fourteen are in our STIX feed and the CSV blocklists, sourced as manual-batch-carbonato and manual-batch-closedquorum, with the primary research linked on every record.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=two-malware-families-handed-the-wheel-to-an-llm-this-week-one-spends-inference-the-other-steals-it




Comments