This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
AI Summary
Cisco Talos identified a novel Windows malware named CLOSEDQUORUM that leverages commercial AI models—DeepSeek, Qwen, Mistral, and Google Gemini—to make autonomous decisions on attack actions through a voting mechanism. The malware performs credential theft, code injection, persistence, and lateral movement based on consensus from AI models, with decisions logged and data exfiltrated via a Discord webhook. While the public version is non-functional due to placeholder API keys and webhook URLs, the malware represents a new paradigm in AI-driven threats. Indicators include specific behaviors such as AI service queries from non-AI applications, LSASS memory dumping, process injection, and WMI-based persistence with Windows Update-themed names.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 8 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7 | Details → |
| SHA-256 | c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7 | Details → |
| SHA-256 | c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f | Details → |
| SHA-256 | f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c | Details → |
| SHA-256 | 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb | Details → |
| SHA-256 | eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5 | Details → |
| Filename | wmi.ps1 | Details → |
| Registry User | WindowsUpdate | Details → |