CLOSEDQUORUM, the malware that asks four AI models what to do next
Cisco Talos says CLOSEDQUORUM lets four commercial AI models vote on credential and wallet theft.
Cisco Talos documented CLOSEDQUORUM, a Windows implant that sends host context to DeepSeek, Qwen, Mistral, and Google Gemini and executes the majority vote among steal, inject, persist, or move. The steal path dumps LSASS credentials, saved passwords from Chrome, Edge, and Firefox, and wallets such as MetaMask and Exodus, then exfiltrates AES-256-GCM data through a Discord webhook. The public sample is inert with placeholder API keys, while development builds embed real credentials. Talos found it with the CAIRN toolkit and linked artifacts to carding-forum posts from 2025.