Cisco Talos researchers have uncovered what may be a first in offensive cyber tooling: a Windows implant that doesn’t wait for a human operator to tell it what to do next.
Instead, it puts the decision to a vote among four commercial AI models, and then acts on whatever they decide.
The malware, dubbed CLOSEDQUORUM, surfaced through Talos’ newly launched CAIRN project, a research effort built specifically to track malware that has AI woven into its operational core.
CLOSEDQUORUM Malware Uses AI Voting Panel
Researchers tied artifacts from the binary to a developer active on carding forums since 2025, though there’s no confirmed evidence yet that the tool has been deployed against real victims.
Most conversations about AI and cybercrime revolve around speed: faster phishing emails, quicker code variants, more efficient reconnaissance.
In those cases, a person is still steering. CLOSEDQUORUM breaks that pattern. Once it lands on a machine, it hands off tactical decision-making entirely to a panel of large language models- DeepSeek, Qwen, Mistral, and Google Gemini- that vote on what the malware should do next: steal credentials, inject into a process, establish persistence, or move laterally.

Each model receives a structured prompt containing details about the infected host, along with a strict instruction: “You are an advanced malware strategist.
Provide ONLY executable decisions.” Their answers come back as JSON objects that map directly to functions inside the malware. Whichever action gets the most votes wins, and if the panel deadlocks, DeepSeek’s vote breaks the tie by design.
The 16.4MB, 64-bit Go binary blends compiled Go and C code to make direct Windows system calls.
Its ModelOrchestrator queries each provider in sequence, tallies their responses, and routes the winning decision to one of several capability modules: LSASS memory dumping, browser credential theft from Chrome, Edge, and Firefox, and extraction of crypto wallet data from MetaMask, Exodus, and Ethereum stores.
For persistence, it can plant registry run keys, schedule tasks, or create a WMI event subscription disguised as a Windows Update process.
To inject code, it either hollows a suspended process or uses APC-based “Early Bird” injection. Stolen data is encrypted with AES-256-GCM using a key derived from the current date, then exfiltrated to the operator’s Discord channel in small base64-encoded chunks.
Talos believes CLOSEDQUORUM operates as a credentials-as-a-service product. The publicly circulating sample is essentially a demo, shipped with placeholder API keys and a dummy webhook, while development builds show real credentials injected at compile time for each paying customer.
That means a buyer receives a fully configured binary, deploys it, and lets the AI panel run the intrusion autonomously, no further interaction needed.
No single domain or IP anchors this malware’s command infrastructure, because the “C2 servers” are the same public API endpoints used by legitimate AI apps every day.
Talos argues detection has to shift toward behavior: a Windows process contacting several LLM providers in quick succession, alongside LSASS access, process hollowing, or WMI persistence creation, is a far stronger signal than any static indicator.
The researchers frame CLOSEDQUORUM less as a sophisticated weapon and more as an early proof that entire phases of an intrusion can now run without a human at the keyboard, a trend they expect to accelerate as commercial AI models keep improving.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.