Un malware que hace votar a cuatro IAs para decidir su próximo golpe
La noticia se lee sola: apareció un malware de Windows, CLOSEDQUORUM , que en vez de recibir órdenes de un servidor de mando le pregunta a cuatro modelos de IA —DeepSeek, Qwen, Mistral y Gemini— qué hacer, y ejecuta la acción más votada: robar, inyectarse, persistir o moverse. Cuando gana "robar", vuelca las credenciales de Windows desde LSASS, se lleva las contraseñas de Chrome, Edge y Firefox,…
A new Windows malware called CLOSEDQUORUM has been discovered, which instead of following commands from a remote server, asks four different AI models – DeepSeek, Qwen, Mistral, and Gemini – what action to take. The malware then carries out the action with the most votes: stealing data, injecting itself, persisting, or moving. If the malware wins, it can dump Windows credentials, steal passwords from Chrome, Edge, and Firefox, and empty MetaMask, Exodus, and Ethereum wallets.
While this may seem impressive, it's important to note that the malware is likely just a demonstration and not functional. The version that's publicly available includes placeholder API keys and a Discord webhook, but no one has seen it operate end-to-end. The only new feature is the voting command from the four AI models. However, using this method to command the malware is unlikely to be more effective than a simple, hard-coded logic.
In fact, the recommendation is to block the AI domain domains, monitor for behavioral signatures like process injection, LSASS access, WMI persistence, and repeated queries to AI APIs every 5-15 minutes. The voting mechanism doesn't make the malware more dangerous; it makes it noisier. It's a demonstration of evasion, making the attack harder to analyze without sacrificing its functionality.
A notable detail is that the author knows what the malware does and yet chose to showcase the process, possibly to demonstrate discipline. The second reading reveals that the pattern of using multiple models to make a decision is a powerful defensive technique. In high-stakes security reviews, multiple models independently review a change and then verify each other's findings.
This diversity in models ensures that if one model misses something, another can catch it. This is not just theory. In a recent closure of a medical records system, the advice to use multiple models proved effective. While a single reviewer missed a critical error that could have irreversibly deleted a patient's file with an incorrect death date, the consensus of four models caught the mistake.
The same principle applied in reverse at CLOSEDQUORUM, using the consensus of multiple models to decide whether to allow a critical security defect or not. The technique of using multiple independent views and a consensus verdict can be used for both malicious purposes, like stealing data, and defensive purposes, like protecting systems.
The key takeaway is that AI techniques aren't inherently good or bad; it depends on how they're applied.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.