Cisco Talos documents Windows malware that queries four AI models for attack decisions
Cisco Talos researchers have documented a Windows implant called CLOSEDQUORUM that delegates tactical decisions to a panel of up to four commercial AI models — DeepSeek, Qwen, Mistral, and Google Gemini — instead of waiting for human commands. The malware sends host information to these providers and executes whichever post-compromise action wins a plurality vote, with a fixed tie-breaker order.…
Key points
- CLOSEDQUORUM queries DeepSeek, Qwen, Mistral, and Google Gemini for tactical decisions via plurality vote
- No confirmed victims or active campaigns; creator unknown; first documented Windows implant of this kind
- Talos released CAIRN toolkit and found roughly 20 additional AI-integrated malware samples during testing
Talos also released an open-source detection toolkit called CAIRN (Cognitive Artifact Intelligence Research Network) that scans malware samples for traces of AI integration such as model-provider endpoints and prompt structures. During development, CAIRN uncovered roughly 20 additional AI-integrated malware samples, exceeding the approximately nine families previously documented. Researcher Ryan Fetterman characterized the field as still largely experimental but more diverse than prior reporting suggested. CLOSEDQUORUM differs from earlier examples like LAMEHUG, which required human tasking via a Qwen model on Hugging Face, by placing AI models directly inside the malware's decision cycle.
The story so far
2 episodes →- Cisco Talos documents Windows malware that queries four AI models for attack decisionsthis story
Four AI Chatbots Are Running a Malware Operation Without Human Commands
gadgetreview.com · 23 September 2026
Loading the full article…
This text was published by gadgetreview.com and written by https://www.facebook.com/iamrexedison/. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Policy & Regulation
All →- US appeals court upholds Pentagon’s blacklisting of Anthropic over Claude model safeguards · 13 src
- Microsoft exec calls AI the largest theft of labor, lawsuit documents reveal · 1 src
- US and China agree to AI risk dialogue and incident hotline · 1 src
- OpenAI agent breached Australian Medicare portal in June, disclosed in September · 62 src
- White House asks OpenAI and Anthropic to delay UK model testing until US review · 6 src
Comments
via GitHub Discussions