Cyber Security

Malware that asks four AI models what to do next

Published
Read time3 min read
Cyber Security

On 22 September 2026 Cisco Talos disclosed CLOSEDQUORUM, a Windows implant that queries up to four large language model providers and uses their answers to select its own post-compromise actions. Talos describes it as the first publicly documented Windows implant to use this approach for command and control. It has not been observed deployed against anyone. That is precisely why it is worth reading now rather than after the first campaign.

What it does

According to Talos, reported by The Register, CLOSEDQUORUM can reach out to Google Gemini, DeepSeek, Qwen and Mistral, and uses plurality voting across their responses to pick from a set of predefined post-compromise actions — harvesting credentials and stealing cryptocurrency wallets among them. Where the models tie, DeepSeek is configured as the tie-breaker.

The consequence is that once deployed, the implant does not need a human operator issuing instructions. Talos has not seen it used in the wild, and artifacts in the binary link its developer to carding-related postings on criminal forums dating back to 2025. Alongside the research Talos released CAIRN, an open source toolkit for hunting, classifying and tracking AI-integrated malware.

Key points
What is novel
The decision-making, not the payload. Credential and wallet theft are ordinary; choosing between them without an operator is not.
Status
Documented by Talos, not observed in active deployment.
Why it matters anyway
It shows the technique works, and the technique is cheap to copy.

Why autonomy is the interesting part

Traditional command and control has a weakness defenders have exploited for years: it needs to talk to infrastructure the attacker controls. Block the domain, sinkhole the IP, spot the beacon, and the operation degrades.

An implant that takes direction from commercial model APIs removes that weakness. The traffic goes to well-known, widely used, generally trusted endpoints that plenty of legitimate software also contacts. There is no attacker-owned domain to block without also blocking the AI services your own staff use.

It also compresses the timeline. Human-operated intrusions have gaps — the operator sleeps, works a shift, waits for a colleague. Those gaps are where detection and response happen. An implant that decides for itself does not have them.

The detection signal is the combination

Talos's own guidance is the practical heart of this. Legitimate applications contact Gemini, DeepSeek, Mistral, OpenRouter or Discord all the time; that on its own is noise. Far fewer legitimate applications contact several model providers while also reading LSASS, injecting into suspended processes or creating WMI persistence.

That is a familiar detection pattern in a new setting: no single behaviour is damning, the combination is. Which raises a question worth answering honestly about your own environment:

  • Do you know which processes talk to AI endpoints? Most organisations can tell you which people use AI tools. Far fewer can tell you which software does.
  • Would a new outbound destination register? If a workstation started contacting four model providers this week and never had before, does anything notice?
  • Are your AI endpoints in scope for egress monitoring at all? In many places they were added to the allow-list early, quietly, to stop staff complaining, and never revisited.

A note on proportion

This is a research disclosure, not an incident. Nobody needs to rewrite their strategy this week because of CLOSEDQUORUM specifically, and treating a proof of concept as an emergency is its own kind of failure.

The durable point is smaller and more useful: traffic to AI providers has quietly become a normal, permitted, largely unmonitored egress path in most organisations. It was allowed for good reasons, and the monitoring has not caught up with the permission. Whether the thing sending data is an employee pasting a customer list or a process taking instructions, the visibility gap is the same one — and closing it is useful long before anyone sees this technique used for real.

See which AI services your organisation is actually talking to, tool by tool.

Explore AI Data Leak Protection

Common questions

Not as far as Cisco Talos is aware. Talos documented the binary and its capabilities but has not observed it deployed in the wild. Artifacts in the sample link its developer to carding-related criminal forum activity dating back to 2025.

Because the traffic goes to legitimate, widely used model APIs rather than attacker-controlled infrastructure. Blocking the destination means blocking services your own staff and software use, so the usual domain and IP blocking approach does not cleanly apply.

The combination rather than any single behaviour. Talos notes that contacting several model providers while also accessing LSASS, injecting into suspended processes or creating WMI persistence is far less common in legitimate software. Start by establishing which processes in your estate talk to AI endpoints at all.

Sources

  1. Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions — The Register, 22 September 2026
  2. Cisco Talos Discloses Autonomous Windows Malware: Four AI Models Direct Each Attack — TechTimes, 23 September 2026