Cisco Talos researchers have taken apart a Windows implant that doesn't wait for a hacker's orders or follow a fixed script. Once it lands on a machine, it queries four commercial AI models at once — Google Gemini, DeepSeek, China's Qwen and France's Mistral — and lets a vote decide what happens next. The team named it CLOSEDQUORUM and calls it the first publicly documented case of a malware fully handing tactical control to a panel of AI models.
Under the hood it's a 16.4MB, 64-bit Windows binary written in Go. Each model receives details about the compromised host and must pick one of four preset moves through a strict JSON schema: steal, inject, persist, or move. Whichever option gets the most votes wins; if the vote ties, DeepSeek casts the deciding one.
"Steal" is the busiest branch — it dumps credentials from LSASS memory, lifts saved logins from Chrome, Edge and Firefox, and reaches into crypto wallets including MetaMask, Exodus and Ethereum clients. Everything stolen gets AES-256-GCM encrypted, chopped into 1,900-byte chunks and exfiltrated through an ordinary Discord webhook — traffic that blends in with normal chat activity.
The point of the design is that traditional malware usually phones home to an attacker-run server, which defenders can trace and take down. Here, public AI APIs effectively act as the command channel: you can't block Gemini or Mistral outright, and requests to them look like traffic from any legitimate app. Because the attack logic isn't hardcoded but generated on the fly by the models, both analysis and signature-based detection get harder.
One important caveat: the sample Talos examined was a development build with placeholder API keys and a dummy webhook, meaning it wouldn't actually run as distributed. No confirmed real-world infections have surfaced yet, though artifacts tie the developer to carding-forum activity dating back to 2025. Alongside the writeup, Talos released CAIRN, an open-source toolkit for hunting AI-driven malware — CLOSEDQUORUM is the first case studied under that project.
Even as a proof of concept, it shifts what defenders need to watch for: not just the IP addresses of hacker servers, but odd query patterns to legitimate AI services.



