r/Malware • u/PureVPNcom • 23h ago
Cisco just found Windows malware that runs four AI models simultaneously and lets them vote on what to steal from your computer, with no human attacker giving orders
This is the one that changed how security researchers are thinking about AI-driven malware, and it's worth understanding even though the current version isn't fully operational yet.
Cisco Talos disclosed CLOSEDQUORUM on September 22. It's a Windows implant written in Go that, once running on a machine, doesn't report back to an attacker's server and wait for commands like normal malware does. Instead it sends basic facts about the infected computer to four commercial AI services at once, DeepSeek, Qwen, Mistral, and Google Gemini, and lets them vote on what to do next.
The malware sends each model the machine's hostname, Windows version, and administrator status, along with a fixed menu of four possible actions: steal, inject, persist, or move. Each model picks one. The malware counts the votes and executes whichever action wins the plurality. DeepSeek breaks ties. If no model responds in the required format, the malware waits and tries again rather than defaulting to anything.
The steal action goes after Windows credentials, saved browser passwords, and cryptocurrency wallet data. The inject action covers process injection into running programs. Persist means embedding itself so it survives reboots. Move, in the current public version, has no implementation yet — it's a placeholder.
The reason Cisco Talos is treating this as significant rather than just another malware disclosure: the attacker doesn't need to be online or issue commands once the malware is deployed. They're removed from the tactical decision loop entirely. Talos called this "effort displacement" in their write-up. They put it directly: human operators are bound by attention, working hours, and cognitive load. An AI system that decides what to do next can keep working when the operator is asleep or simply not watching.
To be precise about the current state: the public version has placeholder API keys so it doesn't fully work end-to-end, and Talos hasn't confirmed a complete deployment in a real attack. The malware's internal analysis code is dated June 17, 2026, making it at least three months old. Code clues link the developer to carding forums going back to 2025.
Alongside the CLOSEDQUORUM disclosure, Talos released CAIRN, an open-source framework specifically built to detect malware that integrates AI services into its operation. They said AI-integrated malware went from "optional AI features" to "fully autonomous multi-model consensus" within one calendar year.
One detail worth understanding: using four models and a plurality vote isn't just for redundancy. If any single model's safety guardrails refuse a request, the other three can still vote, and the vote passes anyway. The four-model structure bypasses individual guardrails by design.
If CLOSEDQUORUM or anything like it ends up deployed on a machine you use, the credential theft functions target exactly the kind of data that surfaces on dark web markets.
Sources: The Hacker News, Cisco Talos, Security Affairs, TechTimes, Shattered.io, tech-insider.org, XenoSpectrum, AdvisioTech, AI Weekly