Cisco Talos researchers identified Windows malware named CLOSEDQUORUM that consults DeepSeek, Qwen, Mistral and Google Gemini to decide its next actions on infected machines, continuing to function if one service goes down. The tool, designed to steal credentials and cryptocurrency, has no built-in mechanism for human operators to issue commands directly, and Talos linked it to 2025 credit-card fraud forum activity, though the creator and any real-world targets remain unidentified.
techspot.com
· 2026-09-23
Cisco Talos researchers identified a Go-based Windows malware called ClosedQuorum that queries Google Gemini, DeepSeek, Qwen, and Mistral to decide post-compromise actions without human input. The models vote on options such as credential theft, code injection, and persistence, with DeepSeek breaking ties, and stolen data is sent to attackers via a Discord webhook.
bleepingcomputer.com
· 2026-09-22
Cisco Talos researchers released an open-source system called CAIRN designed to detect and classify malware that relies on artificial intelligence for decision-making. Using the tool, they identified a new strain, CLOSEDQUORUM, which queries up to four large language models to determine its next actions inside a compromised system rather than following pre-programmed commands.
wired.com
· 2026-09-22
Cisco Talos reported that three distinct threat groups—including Qilin ransomware affiliates and state-sponsored actors—have been exploiting two vulnerabilities in Cisco Secure Firewall Management Center. The flaws, a maximum-severity authentication bypass (CVE-2026-20079) and a static credential issue (CVE-2026-20316), let attackers gain root access, deploy web shells, steal credentials, and in some cases install Qilin ransomware or Cyclops Blink malware. Cisco has issued hot fixes and urges immediate patching, with broader hardening updates planned next week.
bleepingcomputer.com
· 2026-09-10
Cisco Talos researchers identified two separate ClickFix-style social engineering campaigns that trick victims into executing malicious code themselves, one aimed at stealing cryptocurrency and another designed to gain persistent enterprise network access. One campaign uses a publicly shared Google Sheet to distribute malicious browser code that hijacks Chrome transaction interfaces, while both operations abuse legitimate cloud services and trusted software to disguise malicious activity as normal user behavior.
darkreading.com
· 2026-09-08