CLOSEDQUORUM is a 64-bit Windows implant written in the Go programming language that represents a new frontier in automated malware operation. Unlike traditional remote access trojans that phone home to an attacker's command server, this threat delegates all decision-making to commercial artificial intelligence platforms—specifically, large language model providers. First documented by Cisco Talos researchers in late 2024, CLOSEDQUORUM collects information about your infected machine, sends that context to up to four AI services simultaneously, and executes whatever action the majority of these models recommend. The implant targets credentials from system memory, web browsers, and cryptocurrency wallets, making it a severe threat to both personal and business data.
What makes this malware particularly concerning for computer users in Roswell and throughout Georgia is its ability to operate without traditional network signatures. Security appliances that watch for connections to known malicious servers may miss CLOSEDQUORUM entirely, since the malware communicates exclusively with legitimate commercial AI services that thousands of businesses use every day. The operators behind this threat have essentially weaponized artificial intelligence to automate cyberattacks, creating a system that adapts its behavior based on what it finds on each infected machine.
Threat Profile
| Attribute | Value |
|---|---|
| Canonical name | CLOSEDQUORUM |
| Known aliases | BALZAK |
| Platform | Windows (64-bit) |
| File type | Portable Executable (PE), compiled from Go source |
| First documented | Q4 2024 (Cisco Talos report) |
| Primary payload | Credential theft, shellcode execution capability |
| C2 mechanism | Delegates command decisions to commercial LLM providers via API |
| Persistence method | Typical for this family (registry run keys, scheduled tasks) |
| Privilege requirements | Typically requires elevated privileges for LSASS access |
| Network signatures | HTTPS to legitimate AI service endpoints (difficult to block) |
| Decryption required | Varies by sample; Go binaries often contain embedded configuration |
| Data exfiltration | Stolen credentials likely transmitted via same LLM API channels |
How It Spreads
CLOSEDQUORUM distribution follows patterns common to sophisticated credential-stealing malware. The initial infection vector typically involves social engineering—convincing a victim to run a disguised executable or open a malicious document. Because the malware is written in Go and compiled as a standalone Windows executable, it doesn't require any runtime interpreters or unusual dependencies that might raise suspicion during the infection phase. The operators behind CLOSEDQUORUM favor distribution methods that establish a foothold before users realize something is wrong.
Based on the technical profile and targeting of high-value credentials like cryptocurrency wallets, this malware likely spreads through channels that reach users who maintain such assets. The use of cutting-edge AI-driven command and control suggests the operators invest significant resources in initial access, rather than relying on mass-spam campaigns. However, once a network is compromised, lateral movement capabilities would allow CLOSEDQUORUM to spread to additional machines within the same organization or home network.
Common distribution vectors for this threat family include:
- Phishing emails with malicious attachments disguised as invoices, shipping notices, or business documents that drop the CLOSEDQUORUM executable
- Trojanized software downloads from unofficial sources, including cracked applications, game cheats, or pirated productivity tools
- Supply chain compromises where legitimate software update mechanisms are hijacked to deliver the implant
- Exploit kits targeting unpatched browser or system vulnerabilities on machines visiting compromised websites
- USB/removable media carrying autorun configurations or disguised executables, particularly in business environments
- Remote Desktop Protocol (RDP) brute-force attacks that establish initial access before deploying CLOSEDQUORUM as a persistent backdoor
What It Does On Your Machine
Once CLOSEDQUORUM executes on your Windows system, it begins by collecting comprehensive information about the infected machine. The malware inventories your running processes, installed security software, user accounts, and network configuration. This reconnaissance data is packaged into a structured format and transmitted to the AI decision panel—typically four different commercial large language model providers that the attackers have configured. Each AI service receives the same context and must respond with a recommended action from the malware's limited command set, formatted as constrained JSON. The implant then tallies these recommendations and executes whichever action received the most votes, with ties broken according to a predetermined provider priority list.
The credential theft capabilities of CLOSEDQUORUM are its primary danger to Roswell residents and small business owners. The malware specifically targets the Local Security Authority Subsystem Service (LSASS) process in Windows memory, extracting plaintext passwords, NTLM hashes, and Kerberos tickets that can grant attackers access to your domain accounts, email, and network resources. It also systematically pillages browser password stores from Chrome, Firefox, Edge, and other common browsers, as well as scanning for cryptocurrency wallet files from Bitcoin, Ethereum, and other digital asset applications. For victims who maintain business accounts or personal crypto holdings, this represents an immediate financial threat.
Beyond theft, CLOSEDQUORUM includes shellcode execution capabilities via Early Bird APC (Asynchronous Procedure Call) injection. This technique allows the malware to run arbitrary code within legitimate Windows processes, evading behavioral detection systems that watch for suspicious process creation. The AI decision panel can direct the implant to download and execute additional payloads, transforming your compromised machine into a platform for ransomware deployment, banking trojans, or participation in a botnet. The full command set remains opaque to security researchers since the decision logic resides externally in the AI models rather than in reverse-engineerable code.
Manual Removal — Step by Step
Disconnect from all networks
Before attempting any removal steps, physically disconnect the infected machine from the internet and any local networks. Unplug the Ethernet cable and disable all wireless adapters through Windows settings or physical switches. This prevents CLOSEDQUORUM from receiving new instructions from its AI command panel or exfiltrating additional credentials while you work on cleanup.
Boot into Safe Mode with Networking
Restart your computer and press F8 repeatedly during boot (or Shift+Restart from Windows 10/11 to access the recovery menu). Select "Safe Mode with Networking" to load Windows with minimal drivers and services. This environment prevents most malware persistence mechanisms from activating, including CLOSEDQUORUM's registry-based autostart entries, making removal significantly easier and safer.
Run full system scan with updated security software
From Safe Mode, ensure your antivirus or anti-malware software has the latest definitions, then perform a comprehensive system scan. Windows Defender, Malwarebytes, or enterprise solutions may detect CLOSEDQUORUM under various heuristic names or behavioral signatures. Quarantine all identified threats. Note that Go-compiled malware sometimes evades signature detection, so a clean scan doesn't guarantee removal—proceed with manual verification steps.
Inspect and clean registry autostart locations
Press Windows+R, type regedit, and navigate to common persistence keys: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and the corresponding HKEY_LOCAL_MACHINE location. Look for unfamiliar entries, especially those pointing to executables in AppData\Roaming, AppData\Local\Temp, or system directories with randomized names. Delete suspicious entries, but document them first in case you need to restore legitimate software. CLOSEDQUORUM often creates entries with deceptive names like "WindowsSecurityUpdate" or similar system-sounding titles.
Check scheduled tasks and startup folders
Open Task Scheduler (type taskschd.msc in the Run dialog) and review all scheduled tasks, particularly those set to run at logon or system startup. Delete any tasks associated with suspicious executables. Also examine the physical Startup folders at C:\Users\[username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup and the all-users equivalent at C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup. Remove any unrecognized shortcuts or executables.
Locate and delete the malware executable
Using File Explorer with "Show hidden files" enabled, search the directories identified during your registry inspection. Common CLOSEDQUORUM locations include subfolders within %APPDATA%, %LOCALAPPDATA%, and %TEMP%. The executable may have a deceptive name or a randomized alphanumeric filename. Delete the file and empty the Recycle Bin immediately. If Windows prevents deletion due to active processes, use Task Manager to end any suspicious processes first—look for Go-compiled binaries consuming network bandwidth or memory.
Reset browser security and clear stored credentials
Since CLOSEDQUORUM steals browser passwords, you must assume all stored credentials are compromised. In each installed browser (Chrome, Firefox, Edge), access settings and choose to clear saved passwords, cookies, and cached data. Consider this a mandatory step even if inconvenient—the malware has already accessed this data. After cleanup is complete, you'll need to change passwords for all accounts, which we address in the next step.
Change all passwords from a clean device
Do not change passwords from the infected machine, even after apparent removal. Use a smartphone, tablet, or confirmed-clean computer to log into your email, banking, social media, and any cryptocurrency exchange accounts. Enable two-factor authentication wherever available. For business users, immediately notify your IT administrator about the breach—domain credentials stolen via LSASS dumping compromise your entire network and require coordinated response across all systems.
Monitor for cryptocurrency wallet compromise
If you store cryptocurrency wallets on the infected machine, those private keys must be considered exposed. Transfer any remaining funds to new wallets with freshly generated keys from a secure device before the attackers drain your accounts. Check blockchain transaction histories for unauthorized transfers. This is time-sensitive—credential-stealing malware operators often have automated systems that immediately attempt to liquidate stolen crypto assets.
Verify removal and restore normal operations
Restart your computer normally (not in Safe Mode) and observe system behavior for several days while monitoring network traffic and process activity. Run additional scans with multiple security tools. Watch for unusual outbound HTTPS connections to AI service endpoints or unexpected process creation. If any CLOSEDQUORUM indicators reappear, the manual removal was incomplete—at that stage, professional remediation or complete system reinstallation is advisable.
Prevention
- Maintain current Windows updates and security patches. Microsoft regularly addresses vulnerabilities that malware exploits for initial access and privilege escalation. Enable automatic updates or establish a monthly patching schedule for home and business systems. Many infections succeed only because systems run outdated software with known security flaws.
- Never disable or delay security software. Some CLOSEDQUORUM distribution methods involve tricking users into temporarily disabling antivirus protection to "fix" a fake error or install a "required" update. Legitimate software never requires you to turn off security tools. Maintain active real-time protection and configure your security software to scan downloaded files before execution.
- Implement the principle of least privilege. Don't run your daily user account with administrator rights. CLOSEDQUORUM needs elevated privileges to dump LSASS memory and access protected credential stores. Operating as a standard user forces malware to explicitly request elevation, giving you an opportunity to deny the permission and investigate the request. For business networks, enforce strict account separation between administrative and standard user roles.
- Adopt a password manager with strong master credentials. While CLOSEDQUORUM can steal browser-stored passwords, a properly secured password manager with a strong master password and two-factor authentication provides better protection than browser storage. Choose a reputable manager that encrypts the vault locally, and never store the master password in a text file or browser autofill. This limits damage even if the machine is compromised.
- Secure cryptocurrency holdings in hardware wallets. If you maintain significant crypto assets, move them off any internet-connected computer to a dedicated hardware wallet device. Hot wallets stored on Windows machines represent easy targets for credential stealers like CLOSEDQUORUM. Hardware wallets keep private keys isolated from the operating system, preventing memory-based theft techniques from accessing your funds.
- Exercise extreme caution with email attachments and downloads. The most effective defense against CLOSEDQUORUM is preventing initial infection. Never open attachments from unknown senders, verify unexpected attachments with the supposed sender through a separate communication channel, and only download software from official vendor websites. Pirated software, cracks, and "free" premium tools are common malware distribution vectors.
- Enable advanced security features in Windows. Turn on Controlled Folder Access in Windows Security to protect critical directories from unauthorized changes. Enable Credential Guard on supported Windows 10/11 Pro and Enterprise editions to isolate LSASS memory through virtualization-based security. Configure Attack Surface Reduction rules that block suspicious behaviors like Office macros creating child processes or unsigned executables running from USB drives.
- Monitor your network for unusual HTTPS traffic patterns. For business networks or technically sophisticated home users, inspect outbound HTTPS connections for high-volume traffic to AI service APIs or unusual patterns of requests. While these services are legitimate, malware command-and-control abuse of them can sometimes be identified through frequency analysis or correlation with suspicious process activity. Consider deploying a next-generation firewall that performs SSL inspection on outbound traffic.
Bring It In
CLOSEDQUORUM represents a sophisticated threat that combines credential theft, AI-driven automation, and advanced evasion techniques in ways that challenge even experienced computer users. While the manual removal steps above can eliminate the immediate infection, they don't address the deeper security implications—compromised domain credentials that threaten your business network, stolen cryptocurrency that requires immediate action across multiple wallets, or the uncertain question of whether the malware deployed additional payloads during its active period. Professional malware removal provides forensic verification that the threat is truly gone, comprehensive credential reset guidance, and security hardening to prevent reinfection.
Computer Repair Roswell has served homeowners and small businesses throughout the Roswell area for years, handling everything from routine virus removal to complex security incidents like CLOSEDQUORUM infections. Our technicians understand that credential-stealing malware creates urgency—every hour of delay potentially means more compromised accounts or drained crypto wallets. We offer same-day emergency service for active infections, and we work directly with your banks, email providers, and IT administrators to coordinate the multi-account password resets that complete the recovery process. Don't gamble with a half-cleaned system or risk missing hidden persistence mechanisms. Call us at (770) 637-1435 or bring your machine to our Roswell shop—we'll eliminate CLOSEDQUORUM, verify your system is clean, and help you establish defenses against the next generation of AI-driven malware threats.