Researchers found malware that uses four different AI chatbots to run itself
The malware, called CLOSEDQUORUM, checks with DeepSeek, Qwen, Mistral and Google Gemini before selecting its next action. It can continue operating if one of those services is unavailable because it can query the others. Cisco Talos said the tool has no built-in path for a human operator to issue commands... Read Entire Article
Researchers at Cisco Talos have identified a new Windows malware called CLOSEDQUORUM that leverages four distinct AI chatbots—DeepSeek, Qwen, Mistral, and Google Gemini—to determine its next steps on a compromised machine. This marks a growing trend in AI-enabled malware, moving beyond simple code generation and phishing support towards more autonomous and resilient command-and-control systems.
CLOSEDQUORUM checks with the various AI services before deciding on its next action, demonstrating the ability to continue operating even if one service is unavailable, as it can still query the others. The malware is designed to steal login credentials and cryptocurrency. Links to cybercrime forum activity involving credit-card fraud dating back to 2025 have been traced back to the malware, though the creators and any real-world targets remain unidentified.
To track malware that relies on AI services, Cisco Talos developed the Cognitive Artifact Intelligence Research Network (CAIRN), an open-source framework. CAIRN identifies technical traces linked to AI use in malware samples, assigning an identifier to each sample for comparative analysis. This system helps analysts detect patterns in how attackers integrate large language models (LLMs) into malware and command-and-control operations.
The key differentiator for CLOSEDQUORUM is its use of LLMs as part of the control system itself, rather than merely leveraging models to generate code or content. This shift indicates that AI is evolving from a support tool to a core component of attack infrastructure. Matt Olney, senior director of threat intelligence at Cisco Talos, notes that attackers can now run more campaigns, target a wider range of systems, and handle various types of computers, thanks to the intelligent backend that can query AI services and provide responses.
The discovery of CLOSEDQUORUM came from a new Cisco Talos project focused on tracking malware that utilizes AI services. Early examples of AI-related malware have primarily involved attackers using models to write code, create phishing content, or automate parts of a campaign. However, CLOSEDQUORUM represents a more advanced development, where LLM responses directly guide the malware's actions on a compromised system.
While the activity remains largely experimental, the existence of this malware and the broader set of AI-integrated samples found by CAIRN suggest that the public reporting of AI-enabled malware has only scratched the surface of the evolving threat landscape.
Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.