Skip to content
Tech News
← Back to articles

Cisco Talos finds ClosedQuorum, a Windows malware that uses AI models to run attacks

read original get YubiKey 5 NFC Security Key → more articles
GoKawiil Brief

Cisco Talos researchers identified a Go-based Windows malware called ClosedQuorum that queries Google Gemini, DeepSeek, Qwen, and Mistral to decide post-compromise actions without human input. The models vote on options such as credential theft, code injection, and persistence, with DeepSeek breaking ties, and stolen data is sent to attackers via a Discord webhook.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Talos describes this as the first publicly documented Windows implant that hands tactical command-and-control decisions to a panel of AI models rather than a human operator, which the researchers say could increase the speed and scale of attacks. Removing human interaction from the decision loop could let intrusions proceed continuously, though the malware still requires human-driven delivery to reach a target initially.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — With malware like ClosedQuorum autonomously stealing credentials from browsers and system memory, hardware-based two-factor authentication is a strong defense since stolen passwords alone become useless without the physical key. A YubiKey adds a layer of protection that credential-dumping malware simply can't bypass.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-22

Published there as: “New ClosedQuorum Windows malware uses AI for attack decisions”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.