Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
'first' publicly documented Windows implant to use LLMs for C2
A newly discovered Windows malware known as CLOSEDQUORUM has the ability to query up to four large language model (LLM) providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously determine which post-compromise actions to take. These actions include stealing user credentials, cryptocurrency wallets, and other sensitive data.
Once deployed, the malware requires no further commands from a human operator, making it a particularly concerning threat. Cisco Talos, the security firm that discovered the malware, is the first to document this type of AI-integrated Windows implant. The researchers used their CAIRN toolkit to identify and track the malware, which they have made available as open source.
While no instances of CLOSEDQUORUM have been observed in the wild, Talos suspects the malware's developer has been active on criminal forums since at least 2025. The malware's operation involves delegating its next course of action to a quorum of the LLMs, which vote on the most appropriate response. In the event of a tie, DeepSeek's vote takes precedence, followed by Qwen, Mistral, and Gemini.
The malware's design aims to bypass human intervention and the associated limitations, such as attention span, working hours, and cognitive load. The models are limited to a set of predefined actions, which they must choose from. Each action is carefully defined and executed without deviation.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.