AI-Controlled Malware Discovered
Security researchers have discovered CLOSEDQUORUM, an experimental Windows malware template designed to query multiple commercial artificial intelligence models to vote on its next tactical actions.

Security researchers discovered CLOSEDQUORUM, a Windows malware implant designed to integrate commercial artificial intelligence models into its command and control architecture. The software functions by querying up to four external models, specifically DeepSeek, Qwen, Mistral, and Gemini, to vote on its next execution step. To maintain a structured operation, the system restricts these models to choosing from four predefined actions: steal, inject, persist, or move. If the voting process results in a draw, the system is configured to use DeepSeek as the ultimate tie-breaker. However, the analyzed build of the malware is not fully functional, as the code block designated for the move command contains no functional code.
According to Cisco Talos, CLOSEDQUORUM represents the earliest known Windows implant utilizing large language models to automate command and control functions. Cisco Talos discovered the implant using CAIRN, an open-source research project designed to hunt AI-integrated malware. The researchers noted that the publicly distributed version of CLOSEDQUORUM exists as an inert template containing placeholder API keys and dummy Discord webhooks. Furthermore, Talos's code analysis suggests the malware is at least three months old, dating back to June 17, 2026. Clues within the code also reportedly connect the developer to criminal forum posts regarding carding activities dating back to 2025.
This discovery is significant as it demonstrates how threat actors are actively experimenting with autonomous decision-making in malicious software. However, the practical impact of this specific threat remains limited. Cisco Talos has not observed the malware operating from start to finish in the wild and has no confirmation of real-world victims. The analysis is strictly based on an experimental development build of CLOSEDQUORUM rather than an active, weaponized campaign. Because the analyzed binary contained dummy API keys, researchers could not observe the AI decision loop executing in a real-world scenario.
Industry observations confirm that the rule file bundled with the CAIRN toolkit did not include a specific rule for CLOSEDQUORUM when checked on September 23, 2026. Outside of the technical analysis provided by Cisco Talos, other security platforms and publishers have focused on the unique voting mechanism of the implant, noting that it represents a structural shift toward outsourcing tactical execution decisions to commercial AI platforms, even though the current iteration remains highly experimental and non-functional in live environments.
Several critical elements of the threat remain unknown. Researchers have not identified the initial infection vector used to deliver the malware to a victim's computer. It also remains unclear whether the developers intend to deploy a fully functional version of this voting system in active campaigns, or if the project was abandoned as an experimental proof of concept. Because the AI decision loop could not be executed during analysis, the actual reliability and behavior of the voting mechanism under real-world conditions remain unverified.
Sources
- The Hacker NewsPage Not Found – The Hacker News
- iTnewsNew malware lets commercial AI models call the shots: Talos
- Cisco Talos BlogThe Closed Quorum: Inside the first reported autonomous AI C2 implant
- Grab The AxeMalware That Lets Four Models Vote (09/22/2026) | The Axe Report
- forbes.comforbes.com
- The Hacker NewsThis Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
Verified claims
Written by The Quiet Search. Method: /about.