AI Promotes Malware: Researchers Find Windows Threat that Decides its Next Move

Researchers identified CLOSEDQUORUM, a Windows malware sample that uses Gemini, DeepSeek, Qwen and Mistral to autonomously choose predefined attack actions, although live deployment remains unconfirmed.
AI  Promotes Malware: Researchers Find Windows Threat that Decides its Next Move
Written By:
Published on

Researchers have identified a Windows malware sample that can use artificial intelligence models to decide what action it should take after infecting a computer. The malware, named CLOSEDQUORUM, was discovered by Cisco Talos through its new CAIRN research project.

Unlike conventional malware that relies on instructions from an attacker-controlled command-and-control server, CLOSEDQUORUM can delegate tactical decisions to multiple large language models (LLMs). Cisco Talos describes it as the first publicly documented Windows implant known to use this approach for command and control.

Malware Creates an AI-Based Decision System

CLOSEDQUORUM can query up to four commercial AI models: Google Gemini, DeepSeek, Qwen and Mistral. The models assess information from the infected computer and vote on the malware's next predefined action.

The system uses a quorum-style approach. Each model provides a decision, and the option receiving the most votes becomes the malware's next move. If there is a tie, the malware follows a fixed priority order, with DeepSeek receiving precedence.

The AI models do not have unlimited control over the system. Their responses must match a predefined decision structure embedded in the malware. Available actions include stealing information, injecting code and establishing persistence.

Credentials and Crypto Wallets among Targets

The malware contains capabilities designed to collect sensitive information from compromised Windows machines. These include credentials stored in LSASS memory, saved passwords from Chrome, Edge and Firefox, and data associated with cryptocurrency wallets.

CLOSEDQUORUM can also use process-injection techniques and persistence mechanisms. Information collected from the infected system is sent to an operator through a Discord webhook, according to Cisco Talos' analysis.

This architecture allows the malware to continue making tactical decisions without requiring an attacker to issue every command manually.

Safety Road Ahead

Despite the capabilities identified in the sample, Cisco Talos said, “ It has not confirmed deployment of CLOSEDQUORUM in real-world attacks. The publicly distributed binary examined by researchers contains placeholder API credentials and a dummy Discord webhook.”

However, Talos found artifacts connecting the malware's developer to criminal-forum posts related to carding dating back to 2025. This provides context about the developer but does not establish that CLOSEDQUORUM has been used successfully against victims.

Also Read: AI Safety Debate Intensifies as Nvidia CEO Jensen Huang Rejects Extinction Warnings

Analytics Insight UAE: Top Tech News Website in UAE, Dubai & Middle East
www.analyticsinsight.ae