This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
thehackernews.com Sep 23, 2026

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

AI-summarised brief · reviewed before publication

Cisco Talos uncovered a Windows malware named CLOSEDQUORUM that delegates command decisions to up to four commercial AI services—DeepSeek, Qwen, Mistral, and Google Gemini—instead of a traditional command‑and‑control server. The code, dated June 17, 2026, instructs the AI models to choose from four actions: steal credentials, inject code, persist, or move. The malware reports its choices and stolen data to an attacker‑controlled Discord channel via a webhook. The public sample contains placeholder API keys, rendering it non‑functional, but Talos confirmed the design and potential impact.

💡 Why It Matters

  • · By outsourcing attack logic to AI, CLOSEDQUORUM introduces a novel, decentralized threat model that can evade conventional detection tied to known C2 domains.
  • · This approach forces defenders to monitor anomalous AI‑service interactions and internal Windows behaviors rather than relying solely on domain blacklists.