bleeping-computer · Crawled Sep 22, 2026

New ClosedQuorum Windows malware uses AI for attack decisions

2 IoCs
Read original article ↗

AI Summary

Cisco Talos discovered a new Windows malware named ClosedQuorum, which autonomously makes post-compromise attack decisions using multiple AI models including Google Gemini, DeepSeek, Qwen, and Mistral. The malware uses a voting system among the AI models to decide actions such as credential theft, code injection, persistence, and lateral movement, with DeepSeek breaking ties. Stolen data is exfiltrated via Discord webhooks. While the sample analyzed contains placeholder credentials and no active lateral movement capability, it represents an early example of fully automated, AI-driven attack chains with no human operator involvement.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename ClosedQuorum Details →
GitHub Repo Cisco/CAIRN Details →