Researchers Find Malware That Uses AI Models Instead of Human Hackers for Control
Researchers find CLOSEDQUORUM, a Windows malware that uses commercial LLMs as an autonomous decision engine for post-compromise actions like credential theft.
Cisco Talos researchers identified CLOSEDQUORUM, a Windows malware implant that uses commercial large language models as an autonomous command-and-control layer. The malware gathers host context, queries a panel of LLM providers (DeepSeek, Qwen, Mistral, Gemini), and executes prebuilt malicious capabilities like credential theft and process injection based on model votes. While not yet observed in active attacks, the sample is linked to criminal-forum activity from 2025, demonstrating a shift from human-driven to AI-driven attack phases.