hacker-news · Crawled Sep 24, 2026

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

8 IoCs 1 Malware
Read original article ↗

AI Summary

Cisco Talos identified a novel Windows malware named CLOSEDQUORUM that leverages commercial AI models—DeepSeek, Qwen, Mistral, and Google Gemini—to make autonomous decisions on attack actions through a voting mechanism. The malware performs credential theft, code injection, persistence, and lateral movement based on consensus from AI models, with decisions logged and data exfiltrated via a Discord webhook. While the public version is non-functional due to placeholder API keys and webhook URLs, the malware represents a new paradigm in AI-driven threats. Indicators include specific behaviors such as AI service queries from non-AI applications, LSASS memory dumping, process injection, and WMI-based persistence with Windows Update-themed names.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 8 extracted

Type Value Detail
SHA-256 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7 Details →
SHA-256 c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7 Details →
SHA-256 c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f Details →
SHA-256 f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c Details →
SHA-256 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb Details →
SHA-256 eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5 Details →
Filename wmi.ps1 Details →
Registry User WindowsUpdate Details →

MITRE ATT&CK TTPs 8 techniques