3 days ago
CLOSEDQUORUM Shows Malware Letting Four AIs Choose Its Actions
Researchers found a malicious Windows program called CLOSEDQUORUM.
Instead of waiting for a person to tell it what to do, it asks several AI systems for instructions.
The systems can include DeepSeek, Qwen, Mistral and Google’s Gemini.
The malware is designed to steal passwords and cryptocurrency wallets.
This could let an attacker control more computers without constantly giving commands.
However, researchers have not confirmed that it attacked real victims.
They studied a finished software file and found clues linking it to criminal activity.
The same AI connections that make the malware unusual could also help defenders find it.
Cisco Talos disclosed CLOSEDQUORUM, a Windows implant that uses AI models to select its next actions.
The malware can consult DeepSeek, Qwen, Mistral and Google’s Gemini through a panel called a quorum.
Its stated targets include user credentials and cryptocurrency wallets.
Talos has not confirmed that CLOSEDQUORUM was deployed against real victims or used in a live campaign.
The malware’s AI connections may help defenders detect it through prompts, endpoints, API-key patterns and protocol traces.
- Who
- Cisco Talos researchers analyzed CLOSEDQUORUM, a Windows implant attributed to a plausible criminal origin.
- What
- CLOSEDQUORUM uses a panel of commercial AI models to choose its next malware actions.
- Where
- The implant operates on Windows machines and connects to commercial AI services.
- When
- The article does not provide a specific disclosure date; related criminal-forum artifacts reportedly date to 2025.
- Why
- Its stated purpose is to steal user credentials and cryptocurrency wallets while reducing the need for a human operator.
Why the Finding Is Significant
Why the Finding Requires Caution
Autonomous operation
Why the Finding Is Significant
CLOSEDQUORUM can consult AI models and select actions without an attacker-run command server or continuous human instructions.
Why the Finding Requires Caution
The analysis shows a working proof of concept, but there is no confirmation that it has operated in a real attack.
Defensive impact
Why the Finding Is Significant
Removing a human operator could make attacks more scalable and eliminate a central server that defenders might disconnect.
Why the Finding Requires Caution
The malware must contact AI providers and use prompts, API keys and recognizable protocols, creating fingerprints defenders can hunt.
Criminal significance
Why the Finding Is Significant
Artifacts linked to the implant were connected to criminal-forum postings about payment-card fraud from 2025, suggesting plausible criminal intent.
Why the Finding Requires Caution
Those links do not establish that CLOSEDQUORUM was deployed in a confirmed live campaign or caused actual victim losses.
Key facts
- Malware
- CLOSEDQUORUM
- Developer or analyst
- Cisco Talos, Cisco’s security arm
- Platform
- Windows
- AI providers
- DeepSeek, Qwen, Mistral and Google’s Gemini
- Stated targets
- User credentials and cryptocurrency wallets
- Deployment status
- No confirmed deployment against real victims
- Detection clues
- Embedded prompts, provider endpoints, API-key patterns and AI-related syntax





