Theregister New Windows Malware CLOSEDQUORUM Uses AI for Autonomous Actions
Article Content
- •CLOSEDQUORUM malware autonomously selects actions using AI models.
- •It can execute tasks like credential theft without human input.
- •Cisco Talos has not observed any in-the-wild deployment yet.
A new Windows malware named CLOSEDQUORUM has been discovered, capable of autonomously selecting post-compromise actions by querying multiple large language models (LLMs). Developed by an unidentified actor linked to criminal forums since 2025, it can execute actions such as stealing user credentials and cryptocurrency wallets without human intervention. The malware utilizes a quorum of four LLMs—Google Gemini, DeepSeek, Qwen, and Mistral—to vote on decisions, streamlining the attack process. Cisco Talos, which identified the malware, has not seen it deployed in the wild yet. The malware's design allows it to operate continuously, independent of human operators, potentially increasing the speed and scale of cyber intrusions. Talos has released a new toolkit, CAIRN, to help track AI-integrated malware, which is now available as an open-source resource. The implications of this malware could be significant, as it represents a shift in how attacks are executed, moving from human-driven to AI-driven processes.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Closedquorum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cisco Talos Launches CAIRN to Combat AI-Integrated Malware On September 22, 2026, Cisco Talos released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware. The first documented malware analyzed with CAIRN is CLOSEDQUORUM, a Windows implant that autonomously delegates command-and-control decisions to commercial large language models…
New BigDiskBuster Zero-Day Blocks Microsoft Defender Updates Security researcher Abdelhamid Naceri, known as NightmareEclipse, released a proof-of-concept tool named BigDiskBuster that prevents Microsoft Defender from installing critical updates. This zero-day vulnerability affects all supported versions of Windows by filling disk space to block update processes. The tool does…