Malware Now Asks Four AI Models for Permission to Attack

iEXExchanger
Malware Now Asks Four AI Models for Permission to Attack

Cisco Talos found CLOSEDQUORUM, malware that skips human operators and asks Gemini, DeepSeek, Qwen and Mistral what to do on an infected PC — then acts on whichever move wins the vote, including draining crypto wallets.

Cisco Talos researchers have taken apart a Windows implant that doesn't wait for a hacker's orders or follow a fixed script. Once it lands on a machine, it queries four commercial AI models at once — Google Gemini, DeepSeek, China's Qwen and France's Mistral — and lets a vote decide what happens next. The team named it CLOSEDQUORUM and calls it the first publicly documented case of a malware fully handing tactical control to a panel of AI models.

Under the hood it's a 16.4MB, 64-bit Windows binary written in Go. Each model receives details about the compromised host and must pick one of four preset moves through a strict JSON schema: steal, inject, persist, or move. Whichever option gets the most votes wins; if the vote ties, DeepSeek casts the deciding one.

"Steal" is the busiest branch — it dumps credentials from LSASS memory, lifts saved logins from Chrome, Edge and Firefox, and reaches into crypto wallets including MetaMask, Exodus and Ethereum clients. Everything stolen gets AES-256-GCM encrypted, chopped into 1,900-byte chunks and exfiltrated through an ordinary Discord webhook — traffic that blends in with normal chat activity.

The point of the design is that traditional malware usually phones home to an attacker-run server, which defenders can trace and take down. Here, public AI APIs effectively act as the command channel: you can't block Gemini or Mistral outright, and requests to them look like traffic from any legitimate app. Because the attack logic isn't hardcoded but generated on the fly by the models, both analysis and signature-based detection get harder.

One important caveat: the sample Talos examined was a development build with placeholder API keys and a dummy webhook, meaning it wouldn't actually run as distributed. No confirmed real-world infections have surfaced yet, though artifacts tie the developer to carding-forum activity dating back to 2025. Alongside the writeup, Talos released CAIRN, an open-source toolkit for hunting AI-driven malware — CLOSEDQUORUM is the first case studied under that project.

Even as a proof of concept, it shifts what defenders need to watch for: not just the IP addresses of hacker servers, but odd query patterns to legitimate AI services.

Questions and answers

Frequently asked questions about this article

What is CLOSEDQUORUM?

It's a Windows malware implant found by Cisco Talos that, instead of taking orders from a hacker, queries four commercial AI models and picks its next move by vote.

Which AI models take part in the vote?

Google Gemini, DeepSeek, China's Qwen and France's Mistral. If the vote is tied, DeepSeek casts the deciding vote.

Has the malware infected real computers?

Talos hasn't found confirmed real-world infections. The sample it analyzed was a development build with placeholder API keys and a dummy webhook, so it wouldn't run as distributed.

What exactly can CLOSEDQUORUM steal?

Credentials from LSASS memory, saved logins in Chrome, Edge and Firefox, and the contents of crypto wallets like MetaMask, Exodus and Ethereum clients.

What is CAIRN and why did Talos release it?

CAIRN is Talos's open-source toolkit for hunting and classifying AI-driven malware. CLOSEDQUORUM is the first case studied under that project.