Researchers Uncover Windows Malware That Lets AI Models Choose Its Next Move
Cisco Talos researchers have identified what they describe as the first publicly documented Windows malware to use large language models for command and control decisions. Named CLOSEDQUORUM, the implant describes an infected computer to up to four commercial AI models, including DeepSeek, Alibaba's Qwen, Mistral and Google Gemini, and acts on whichever response wins the most votes among them.
The malware's design means it does not need a dedicated attacker-run server, making it harder for defenders to trace and block since it blends in with legitimate traffic to popular AI services. The models can direct the malware to steal Windows credentials and browser-saved passwords, steal cryptocurrency wallet data, inject code into running processes, or set up persistence through the Windows Registry, scheduled tasks or WMI event subscriptions. A fourth option, to move laterally, exists in the code but was not functional in the sample analysed.
Talos stressed that the publicly available version of CLOSEDQUORUM was an inert template with placeholder API keys and a dummy Discord webhook, meaning researchers did not observe a full attack in action and have no evidence it has been used against real victims. They described it as a demonstration of where attack automation is heading, rather than a currently sophisticated threat.
Key Takeaway: Australian small businesses should keep endpoint protection and credential monitoring up to date, since AI-directed malware is expected to make attacks harder to detect through traditional network-based blocking alone.