Skip to content
New Windows Malware CLOSEDQUORUM Uses AI for Autonomous Actions

New Windows Malware CLOSEDQUORUM Uses AI for Autonomous Actions

First seen 22 Sep 2026, 22:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 23:57 UTC
  • CLOSEDQUORUM malware autonomously selects actions using AI models.
  • It can execute tasks like credential theft without human input.
  • Cisco Talos has not observed any in-the-wild deployment yet.

A new Windows malware named CLOSEDQUORUM has been discovered, capable of autonomously selecting post-compromise actions by querying multiple large language models (LLMs). Developed by an unidentified actor linked to criminal forums since 2025, it can execute actions such as stealing user credentials and cryptocurrency wallets without human intervention. The malware utilizes a quorum of four LLMs—Google Gemini, DeepSeek, Qwen, and Mistral—to vote on decisions, streamlining the attack process. Cisco Talos, which identified the malware, has not seen it deployed in the wild yet. The malware's design allows it to operate continuously, independent of human operators, potentially increasing the speed and scale of cyber intrusions. Talos has released a new toolkit, CAIRN, to help track AI-integrated malware, which is now available as an open-source resource. The implications of this malware could be significant, as it represents a shift in how attacks are executed, moving from human-driven to AI-driven processes.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-01-01
CLOSEDQUORUM development linked to criminal forums
Artifacts from the malware's binary trace its developer to postings on criminal forums since 2025.
Theregister
2026-09-22
CLOSEDQUORUM malware identified by Cisco Talos
Cisco Talos announced the discovery of CLOSEDQUORUM, the first documented Windows implant using AI for command-and-control.
Theregister
2026-09-22
CAIRN toolkit released
Cisco Talos released the CAIRN toolkit to help track AI-integrated malware, making it available as an open-source resource.
Theregister

More articles in this cluster (4)

Following this threat?

Track Closedquorum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed