• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    ClosedQuorum IOC Hunt

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 10 days ago•6•1•23

    This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.

    Microsoft Sentinel (KQL)

    Tags

    T1059 - Command and Scripting InterpreterT1071 - Application Layer ProtocolT1567 - Exfiltration Over Web ServiceTA0002 - ExecutionTA0010 - ExfiltrationFile CreationFile Executable DetectedNetwork Connection OutboundDNS QueryMalware DetectedWindowsWindows Defender Atpkql

    Found in

    • ClosedQuorum Malware Uses AI for Autonomous C2 DecisionsLast updated 15 days ago
    • ClosedQuorum Malware Uses AI for Autonomous C2 DecisionsLast updated 15 days ago
    • ClosedQuorum Malware Uses AI for Autonomous C2 DecisionsLast updated 15 days ago
    • ClosedQuorum Malware Uses AI for Autonomous C2 DecisionsLast updated 15 days ago
    • ClosedQuorum Malware Uses AI for Autonomous C2 DecisionsLast updated 15 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?