Cybersecurity researchers have identified a Windows malware program that uses multiple artificial intelligence models to decide what to do next, pointing to a new direction in the evolution of AI-assisted cyber threats. Researchers at Cisco Talos analyzed the malware, called CLOSEDQUORUM.
Unlike conventional malware, which follows instructions embedded by its developers, CLOSEDQUORUM can contact several AI models and use their responses to make decisions during an attack. The discovery comes as security researchers increasingly track malicious software that incorporates AI into its operations.
CLOSEDQUORUM can communicate with up to four AI systems: DeepSeek, Qwen, Mistral, and Google Gemini. Researchers describe the arrangement as resembling a “hive mind”, with the malware able to seek input from several models instead of depending on a single system.
If one AI service becomes unavailable, the others can continue providing responses. The malware is designed to operate without a human operator choosing its next action.
According to researchers, CLOSEDQUORUM can make decisions from a predefined set of activities. Those capabilities include stealing login credentials and cryptocurrency-related information. However, researchers have not established who created the malware or confirmed that it has been deployed successfully in real-world attacks.
Cisco Talos created the Cognitive Artifact Intelligence Research Network (CAIRN) to identify and study malware that incorporates AI. Researchers say AI-enabled programs can leave behind identifiable traces that help security teams distinguish them from conventional malware.
When Cisco Talos first searched for malware with AI integration, researchers found about nine named families and several proof-of-concept samples.
Source link







