This Malware Doesn’t Wait for Hackers—It Asks AI Models What to Do Next
Cisco Talos documents CLOSEDQUORUM, a Windows implant that votes across DeepSeek, Qwen, Mistral, and Gemini APIs to choose attack actions autonomously.
Cisco Talos's CAIRN research project identified CLOSEDQUORUM, a Windows malware sample that replaces dedicated C2 by sending host details to up to four AI models—DeepSeek, Qwen, Mistral, and Gemini—and letting the majority vote select actions like credential theft, process injection, or persistence. The implant targets Windows and browser passwords plus cryptocurrency wallets, reports via a Discord webhook, and uses WMI-based persistence, though lateral movement has no working handler in the distributed build. The public build contains placeholder keys and a dummy reporting address, researchers did not observe it operating end to end, and there is no confirmed deployment in the wild. Development artifacts were linked to a carding forum user, but no victims or active campaign have been identified.