bleeping-computer · Crawled Sep 22, 2026
New ClosedQuorum Windows malware uses AI for attack decisions
2 IoCs
Read original article ↗
AI Summary
Cisco Talos discovered a new Windows malware named ClosedQuorum, which autonomously makes post-compromise attack decisions using multiple AI models including Google Gemini, DeepSeek, Qwen, and Mistral. The malware uses a voting system among the AI models to decide actions such as credential theft, code injection, persistence, and lateral movement, with DeepSeek breaking ties. Stolen data is exfiltrated via Discord webhooks. While the sample analyzed contains placeholder credentials and no active lateral movement capability, it represents an early example of fully automated, AI-driven attack chains with no human operator involvement.
AI-extracted · verify before operational use