Skip to main content
The Wire
CyberNews by Zentrya One
Malware

CLOSEDQUORUM Malware Lets Four AI Models Vote on Its Next Move

Cisco Talos uncovers CLOSEDQUORUM, experimental Windows malware that lets DeepSeek, Qwen, Mistral and Gemini vote on whether to steal data, inject code or establish persistence.

Cybersecurity researchers have uncovered an experimental Windows malware called CLOSEDQUORUM that uses up to four commercial AI models to vote on what malicious action it should perform next.

Discovered by Cisco Talos, CLOSEDQUORUM differs from traditional malware because parts of its command-and-control decision-making are delegated to AI services rather than requiring an attacker to manually issue every command. Talos says it has not confirmed deployment against real-world victims, and the publicly analyzed build is nonfunctional without valid API credentials and a Discord webhook.

How the AI Voting Works

CLOSEDQUORUM can query four AI services:

  • DeepSeek
  • Qwen
  • Mistral
  • Google Gemini

The malware sends information about the infected computer—including its hostname, Windows version and administrator status—to the models and asks them to choose from predefined actions.

The available choices are:

Action Purpose
steal Steal credentials, browser passwords and crypto-wallet data
inject Inject malicious code into another process
persist Establish persistence on Windows
move Intended for movement to other systems, but not implemented in the analyzed build

Each model provides a recommendation, and the malware executes the action receiving the most valid votes.

System Information → AI Models → Vote → Winning Action → Malware Executes

If the models fail to return usable responses, CLOSEDQUORUM waits and tries again rather than automatically selecting an action.

What CLOSEDQUORUM Can Steal

If the AI models select steal, the malware can target:

  • Windows credentials from LSASS memory
  • Saved Chrome passwords
  • Saved Edge passwords
  • Saved Firefox passwords
  • MetaMask wallet information
  • Exodus wallet data
  • Ethereum cryptocurrency wallet information

For code injection, it supports techniques including Early Bird APC injection and process hollowing.

The persist option can establish access using Registry Run keys, scheduled tasks and permanent WMI event subscriptions.

Discord Still Plays a Role

Although AI models determine the next action, CLOSEDQUORUM does not completely eliminate traditional attacker infrastructure.

Before executing a decision, the malware sends the models' responses and reasoning to an attacker-controlled Discord channel using a webhook. Stolen information is also exfiltrated through Discord.

This creates an unusual architecture:

AI APIs → Tactical Decision

Discord → Monitoring and Data Exfiltration

Each operational build therefore requires valid AI API keys and a functioning Discord webhook.

An Early-Stage Malware Project

Cisco Talos discovered CLOSEDQUORUM using its CAIRN project, which is designed to identify malware incorporating AI services.

Researchers found artifacts linking the malware's developer to criminal-forum posts involving carding dating back to 2025. However, Talos says there is currently no confirmation that CLOSEDQUORUM has been deployed in the wild.

The public sample also contains placeholder API credentials and webhook information, meaning it cannot operate as distributed.

Its reliance on commercial AI platforms creates additional weaknesses: providers can revoke API keys, reject malicious prompts, impose rate limits or change service behavior.

What Security Teams Should Monitor

Rather than simply blocking AI-service domains, defenders should look for unusual combinations of behavior, such as:

  • Unexpected applications communicating with multiple AI APIs
  • AI API traffic combined with LSASS access
  • Browser credential-store access
  • Process injection activity
  • New scheduled tasks or WMI persistence
  • Discord webhook connections from unusual processes
  • Unknown Go binaries contacting AI platforms

Blocking AI providers outright may generate unnecessary disruption because the same services can have legitimate business and development uses.

Security Takeaway

CLOSEDQUORUM is notable because it moves AI beyond simply generating malicious scripts and instead uses models as part of the malware's tactical decision-making process.

The architecture can be summarized as:

Compromised Windows Host → Query Four AI Models → Majority Vote → Steal / Inject / Persist → Report Through Discord

However, CLOSEDQUORUM should currently be viewed as an experimental or developmental example rather than evidence of widespread autonomous AI malware. Talos has not confirmed real-world victim deployment, and the publicly available build requires additional configuration before it can function.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.