Cisco Talos uncovered ClosedQuorum, a Windows malware that polls four large language models—DeepSeek, Qwen, Mistral, and Google Gemini—to autonomously decide its next attack steps. The fully autonomous malware tool operates without human commands, using AI models for attack decisions including credential theft and shellcode injection.

AI Malware Breakthrough: ClosedQuorum Operates Without Human Commands

Cisco Talos researchers have identified ClosedQuorum, a Windows malware that represents an unprecedented shift in AI-integrated malware capabilities

1

2

. This fully autonomous malware tool polls four large language models—DeepSeek, Qwen, Mistral, and Google Gemini—to determine its attack strategy through a voting system, creating what researchers describe as malware guided by an AI hive mind. When votes are tied, DeepSeek makes the final decision, followed by Qwen, Mistral, and Google Gemini in priority order

2

. The discovery emerged from CAIRN (Cognitive Artifact Intelligence Research Network), an open-source framework released by Cisco Talos specifically designed to track and classify AI-integrated malware

1

.

Source: Wired

Source: Wired

How Windows Malware Uses AI Models for Attack Decisions

ClosedQuorum operates as a Go-based implant that uses AI models for attack decisions across multiple attack stages without requiring human operator input

2

. The AI in cyberattacks determines actions from a predefined set including credential theft, shellcode injection, persistence mechanisms, and lateral movement capabilities. When the malware executes its "steal" command, it simultaneously runs LSASS credential dumping, extracts browser credentials from Chrome, Edge, and Firefox, and targets cryptocurrency wallets including MetaMask, Exodus, and Ethereum

2

. Stolen data transmits to operators via a Discord webhook, making the entire attack chain—apart from initial delivery—completely automated. Ryan Fetterman, the Cisco Talos security researcher who led CAIRN development, explains that even if one AI service becomes unavailable, the system maintains redundancy by polling remaining models, creating a closed system with no mechanism for human input

1

.

CAIRN Framework Reveals Expanding Threat Landscape

The CAIRN framework identifies AI-integration characteristics from metadata to classify and tag malware samples, then analyzes each artifact within its library to illustrate trends and connections across the threat landscape

1

. Fetterman initially expected a boom in AI-integrated malware following the July 2025 discovery of LAMEHUG by Ukrainian cybersecurity response unit CERT-UA, which communicated with the Qwen2.5-Coder-32B-Instruct model through a Hugging Face API

1

. However, his retrospective analysis found only nine documented named malware families, including research proofs of concept. After developing CAIRN over recent months, Fetterman discovered approximately 20 additional examples of AI-integrated malware, revealing that "the landscape is a lot more complex and diverse than has been publicly reported"

1

. Matt Olney, senior director of threat intelligence at Cisco Talos, notes that AI has evolved from a productivity tool to becoming operationalized, allowing attackers to run more campaigns and handle different computers because "they have this very intelligent box in the backend that can ask questions and give responses"

1

.

Attack-Chain Automation and Future Cybersecurity Threats

ClosedQuorum marks what Cisco Talos describes as an "architectural shift towards attack-chain automation" and the first publicly documented Windows implant delegating tactical command-and-control decisions to a panel of AI models

2

. This attack-chain automation adds speed and scaling potential to malicious operations while eliminating time constraints tied to human interaction. Researchers traced artifacts from the binary to postings on criminal forums related to carding dating back to 2025, though they could not confirm the developer's identity or whether ClosedQuorum has been deployed in real-world attacks

1

2

. The analyzed binary contains placeholder API credentials and a dummy Discord webhook, allowing creators to add legitimate credentials in custom builds. Cisco Talos acknowledges potential operational challenges including rate limits, malformed output, or temporary unavailability of commercial APIs the system relies upon

2

. While uncertainty remains about whether ClosedQuorum represents a test or active threat, the discovery provides an early signal of emerging cybersecurity threats as attackers increasingly incorporate large language models into their toolkits.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved