New Windows Malware Lets AI Models Decide What to Steal Next
Cisco Talos researchers have identified a new Windows malware, dubbed CLOSEDQUORUM, that queries up to four AI language model providers, including Google Gemini, DeepSeek, Qwen and Mistral, to decide on its own what to do after it has broken into a system. Rather than waiting for instructions from a human attacker, the malware puts a set of pre-defined actions, such as stealing credentials or cryptocurrency wallets, to a vote among the AI models and then carries out whichever action wins.
Talos says this is the first publicly documented example of Windows malware using this kind of AI based decision making for its command-and-control process. The malware was discovered using a new open source toolkit Talos released to help defenders track AI-integrated threats. While there is no evidence yet that CLOSEDQUORUM has been used in real attacks, researchers found clues linking its developer to criminal forum activity dating back to 2025.
What makes this approach concerning is that it removes the need for a human operator to stay actively involved. Traditional attacks are limited by an operator's working hours and attention span, but malware that can independently choose from a fixed menu of actions using AI models can keep operating around the clock. Talos notes that the AI models are restricted to a small set of pre-approved, executable actions rather than open-ended commands.