Cybersecurity Research

Researchers Uncover First AI-Driven 'Autonomous' Malware Implant

Cisco Talos · 22 Sept 2026
Key Takeaway Small businesses should assume attackers can now automate decision-making mid-attack, so timely patching, credential monitoring, and endpoint detection are more important than ever since human attacker downtime can no longer be relied upon as a natural pause in an intrusion.

Cisco Talos has released research on a new Windows based malware implant, dubbed CLOSEDQUORUM, which the company describes as the first publicly documented case of malware using artificial intelligence to make its own tactical decisions during an attack. Rather than waiting for a human operator to issue commands through a command and control server, the malware consults a panel of commercial large language models to decide what action to take next, then carries it out itself. Its apparent goal is harvesting user credentials and cryptocurrency wallets.

Talos frames this as a shift beyond AI simply speeding up phishing emails or generating malicious code variants. Previously, human attackers remained in the loop, directing tools and choosing targets even when AI assisted them. CLOSEDQUORUM instead removes that bottleneck: because the AI can continue operating without an attacker actively watching, the malware does not need to 'go offline' when its operator is unavailable, potentially extending the pace and persistence of an attack.

To support ongoing research into this emerging threat category, Talos has released an open-source toolkit called CAIRN for tracking AI-integrated malware, with this report being the first in a planned series. The findings may range from experimental proof-of-concept code to more mature, active campaigns, but the underlying trend, malware capable of autonomous decision-making, is what defenders should watch closely.

AI malware command and control threat intelligence endpoint security Cisco Talos

Summarised by CISO AI from Cisco Talos. We link back to every original so you can read it yourself.