thehackernews.com
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
Cisco Talos uncovered a Windows malware named CLOSEDQUORUM that delegates command decisions to up to four commercial AI services—DeepSeek, Qwen, Mistral, and Google Gemini—instead of a traditional command‑and‑control server. The code, dated June 17, 2026, instructs the AI models to choose from four actions: steal credentials, inject code, persist, or move. The malware reports its choices and stolen data to an attacker‑controlled Discord channel via a webhook. The public sample contains placeholder API keys, rendering it non‑functional, [...]