A new Windows malware strain called ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to decide what to do during post-compromise stages of an attack, according to Cisco Talos researchers.
The Go-based malware operates without commands from a human operator. It collects reconnaissance data and uses a voting system to select its next action on infected hosts. When the votes are tied, DeepSeek has priority, followed by Qwen, Mistral, and Gemini. The models can choose only from a predefined set of decisions.
Stolen information is sent to operators through a Discord webhook, meaning the attack can be fully automated after delivery. Talos says the design could give malicious operations greater speed and scaling potential, while allowing the attack chain to continue at any time.
The researchers note possible limits: rate limits, malformed model output, or temporary unavailability of the commercial APIs could disrupt the process. Because the malware is not sophisticated, it is unclear whether ClosedQuorum is a test or an experiment. Talos has no confirmation of deployment in the wild, although binary artifacts linked its developer to carding-related criminal-forum posts dating to 2025.
The analyzed binary contains placeholder API credentials and a dummy Discord webhook. Cisco Talos discovered ClosedQuorum through CAIRN, its open-source toolkit for tracking AI-integrated malware.
Comments
0No comments yet. Be the first to comment.