A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack.
The Go-based malware acts with no commands from a human operator, using reconnaissance information and a voting system to decide its next step on infected hosts.
When votes are tied, DeepSeek has priority at making the final call, based on the option it considers most appropriate, followed by Qwen, Mistral, and Gemini.
Cisco Talos researchers analyzing ClosedQuorum say that the models are restricted to a predefined set of decisions, including:
The stolen details are then passed to the operators via a Discord webhook, so apart from the malware delivery, the attack can be fully automated.
Talos describes ClosedQuorum as the first publicly documented Windows implant to delegate tactical command-and-control (C2) decisions to a panel of AI models, commenting that this adds greater speed and scaling potential to malicious operations.
The researchers also highlight that this eliminates human interaction, allowing the attack chain to proceed at any time.
However, Cisco notes that this may also pose challenges in certain cases where rate limits are hit, output is malformed, or commercial APIs that the system relies on are temporarily unavailable.
Since it is not a sophisticated piece of malware, it is unclear if ClosedQuorum is a test or experiment. However, the researchers warn that it represents an “architectural shift towards attack-chain automation.”
“While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025,” explains Cisco Talos.
The binary that Cisco Talos analyzed contains placeholder API credentials and a dummy Discord webhook, although the creators can add those in their custom ClosedQuorum builds.
Cisco Talos discovered ClosedQuorum through CAIRN, an open-source toolkit it released to help researchers track and analyze AI-integrated malware.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
New RatHat Android malware uses AI to automate device control
OpenAI details more cases of AI agents taking unauthorized actions
Anthropic wants Claude to analyze your bank account and financial data
Spain’s data agency gets first report of AI-powered data breach
Hackers abused Claude to extract secrets from 1.8M Android apps
Researchers escape OpenAI Codex sandbox to run commands on host
Malicious npm packages evade install-script defenses at runtime
Microsoft reminds admins to migrate Entra ID users to passkeys
Automate Onboarding and Access Reviews with No-Code IGA: See how it works
Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection
Overdue a password health-check? Audit your Active Directory for free
Overdue a password health-check? Audit your Active Directory for free
Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



