IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE35 IOCs

CLOSEDQUORUM: Malware Puts AI in the C2 Loop

PO
PolySwarm
Published September 28, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYAPT28APT29APT33INFRASTRUCTUREunknownCAPABILITYAcidRainAkiraAsyncRATVICTIMunknown
Adversary(34)
Infrastructure
Capability(41)
Victim

Indicators of Compromise

Indicators of Compromise35

TypeIndicatorConfidenceScoreFirst Seen
CVECVE-2023-1389
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2025-49704
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2022-30190
exploitintel-blogloader
High
77
Jun 12, 26
CVECVE-2025-0994
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2022-47986
exploitintel-blogloader
High
77
Oct 9, 26
SHA256250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
botnetfile-hashintel-blog
High
85
Sep 23, 26
CVECVE-2025-55182
aptespionageexploit
High
80
Jun 2, 26
CVECVE-2021-3493
exploitintel-blogloader
High
77
Oct 9, 26
SHA2565191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
botnetfile-hashintel-blog
High
85
Sep 23, 26
SHA256c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
botnetfile-hashintel-blog
High
85
Sep 23, 26
CVECVE-2023-34362
aptespionageexploit
High
78
Sep 3, 26
CVECVE-2025-3248
botnetddosexploit
High
79
Jun 29, 26
SHA256c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
file-hashintel-blogloader
High
85
Sep 23, 26
CVECVE-2025-53770
exploitintel-blogloader
High
79
Jun 12, 26
CVECVE-2022-31199
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2021-21974
exploitintel-blogloader
High
81
Oct 9, 26
CVECVE-2022-21894
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2025-49706
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2023-46604
exploitintel-blogloader
High
78
Aug 27, 26
CVECVE-2021-4034
exploitintel-blogloader
High
78
Jun 2, 26
CVECVE-2022-26134
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2023-2868
exploitintel-blogloader
High
77
Jun 2, 26
CVECVE-2024-3400
aptespionageexploit
High
79
Jun 2, 26
CVECVE-2023-22518
aptespionageexploit
High
81
Oct 9, 26
CVECVE-2024-21412
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2021-33044
exploitintel-blogloader
High
78
Jul 30, 26
SHA256eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5
botnetfile-hashintel-blog
High
85
Sep 23, 26
CVECVE-2026-21509
aptespionageexploit
High
79
Jun 2, 26
CVECVE-2017-7921
exploitintel-blogloader
High
77
Jun 3, 26
SHA256f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c
botnetfile-hashintel-blog
High
85
Sep 23, 26
CVECVE-2024-7344
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2023-36025
exploitintel-blogloader
High
77
Oct 9, 26
CVECVE-2025-53771
exploitintel-blogloader
High
81
Oct 9, 26
CVECVE-2024-40766
exploitintel-blogloader
High
79
Sep 9, 26
CVECVE-2025-21042
exploitintel-blogloader
High
77
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph35 total IOCs
CVESHA256
CVE29SHA2566Actors5Malware5REPORTCLOSEDQUORUM: Malware PutsAPT28APT29APT33APT34APT35AcidRainAkiraAsyncRATBazarLoaderBlack Basta
scroll to zoom · drag to pan · click IOC to open