CLOSEDQUORUM Malware Lets Four AI Models Vote on Its Next Move
Cisco Talos uncovers CLOSEDQUORUM, experimental Windows malware that lets DeepSeek, Qwen, Mistral and Gemini vote on whether to steal data, inject code or establish persistence.

Cybersecurity researchers have uncovered an experimental Windows malware called CLOSEDQUORUM that uses up to four commercial AI models to vote on what malicious action it should perform next.
Discovered by Cisco Talos, CLOSEDQUORUM differs from traditional malware because parts of its command-and-control decision-making are delegated to AI services rather than requiring an attacker to manually issue every command. Talos says it has not confirmed deployment against real-world victims, and the publicly analyzed build is nonfunctional without valid API credentials and a Discord webhook.
How the AI Voting Works
CLOSEDQUORUM can query four AI services:
- DeepSeek
- Qwen
- Mistral
- Google Gemini
The malware sends information about the infected computer—including its hostname, Windows version and administrator status—to the models and asks them to choose from predefined actions.
The available choices are:
| Action | Purpose |
|---|---|
steal |
Steal credentials, browser passwords and crypto-wallet data |
inject |
Inject malicious code into another process |
persist |
Establish persistence on Windows |
move |
Intended for movement to other systems, but not implemented in the analyzed build |
Each model provides a recommendation, and the malware executes the action receiving the most valid votes.
System Information → AI Models → Vote → Winning Action → Malware Executes
If the models fail to return usable responses, CLOSEDQUORUM waits and tries again rather than automatically selecting an action.
What CLOSEDQUORUM Can Steal
If the AI models select steal, the malware can target:
- Windows credentials from LSASS memory
- Saved Chrome passwords
- Saved Edge passwords
- Saved Firefox passwords
- MetaMask wallet information
- Exodus wallet data
- Ethereum cryptocurrency wallet information
For code injection, it supports techniques including Early Bird APC injection and process hollowing.
The persist option can establish access using Registry Run keys, scheduled tasks and permanent WMI event subscriptions.
Discord Still Plays a Role
Although AI models determine the next action, CLOSEDQUORUM does not completely eliminate traditional attacker infrastructure.
Before executing a decision, the malware sends the models' responses and reasoning to an attacker-controlled Discord channel using a webhook. Stolen information is also exfiltrated through Discord.
This creates an unusual architecture:
AI APIs → Tactical Decision
Discord → Monitoring and Data Exfiltration
Each operational build therefore requires valid AI API keys and a functioning Discord webhook.
An Early-Stage Malware Project
Cisco Talos discovered CLOSEDQUORUM using its CAIRN project, which is designed to identify malware incorporating AI services.
Researchers found artifacts linking the malware's developer to criminal-forum posts involving carding dating back to 2025. However, Talos says there is currently no confirmation that CLOSEDQUORUM has been deployed in the wild.
The public sample also contains placeholder API credentials and webhook information, meaning it cannot operate as distributed.
Its reliance on commercial AI platforms creates additional weaknesses: providers can revoke API keys, reject malicious prompts, impose rate limits or change service behavior.
What Security Teams Should Monitor
Rather than simply blocking AI-service domains, defenders should look for unusual combinations of behavior, such as:
- Unexpected applications communicating with multiple AI APIs
- AI API traffic combined with LSASS access
- Browser credential-store access
- Process injection activity
- New scheduled tasks or WMI persistence
- Discord webhook connections from unusual processes
- Unknown Go binaries contacting AI platforms
Blocking AI providers outright may generate unnecessary disruption because the same services can have legitimate business and development uses.
Security Takeaway
CLOSEDQUORUM is notable because it moves AI beyond simply generating malicious scripts and instead uses models as part of the malware's tactical decision-making process.
The architecture can be summarized as:
Compromised Windows Host → Query Four AI Models → Majority Vote → Steal / Inject / Persist → Report Through Discord
However, CLOSEDQUORUM should currently be viewed as an experimental or developmental example rather than evidence of widespread autonomous AI malware. Talos has not confirmed real-world victim deployment, and the publicly available build requires additional configuration before it can function.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.


