Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Autonomous Malware Evolution: How Windows CLOSEDQUORUM Malware Uses AI Models to Outmaneuver Security Measures


Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions, marking a significant shift in the approach of cybercriminals and highlighting the need for security measures to adapt to these new challenges.

  • Windows CLOSEDQUORUM malware utilizes Artificial Intelligence (AI) models to autonomously select post-compromise actions.
  • CLOSEDQUORUM is the first publicly documented Windows implant to use Large Language Models (LLMs) for command-and-control (C2) operations.
  • The malware can query up to four LLM providers to select from predefined post-compromise actions, including stealing credentials and injecting malicious code.
  • The malware's AI-driven decision-making process is facilitated by a quorum of LLMs, which vote on what action to take next.
  • The malware is customized for each operator with their Discord webhook and LLM API keys, making it challenging for security measures to detect and mitigate.
  • The emergence of CLOSEDQUORUM malware highlights the need for security measures to adapt to the evolving nature of cybersecurity threats.



  • The cybersecurity landscape has witnessed an evolution in the tactics employed by malicious actors. The latest addition to this trend is the emergence of Windows CLOSEDQUORUM malware, which utilizes Artificial Intelligence (AI) models to autonomously select post-compromise actions. This development marks a significant shift in the approach of cybercriminals, as it enables them to carry out sophisticated attacks with increased speed and scale, thereby bypassing the traditional human bottleneck.

    According to recent research by security firm Cisco Talos, CLOSEDQUORUM is the first publicly documented Windows implant to use Large Language Models (LLMs) for command-and-control (C2) operations. This novel approach allows the malware to query up to four LLM providers, including Google Gemini, DeepSeek, Qwen, and Mistral, to autonomously select from predefined post-compromise actions. These actions include stealing users' credentials and cryptocurrency wallets, injecting malicious code, and establishing persistence on the infected device.

    The malware's AI-driven decision-making process is facilitated by a quorum of LLMs, which vote on what action to take next. In the event of a tied vote, DeepSeek's vote takes precedence, followed by Qwen, Mistral, and Gemini. This hierarchical approach enables the malware to adapt to different scenarios and make informed decisions based on the available information.

    The developers of CLOSEDQUORUM have provided each operator with a customized executable containing their Discord webhook and LLM API keys, which are injected at compile time. This approach allows the malware to maintain a level of customization and flexibility, making it more challenging for security measures to detect and mitigate the threat.

    Stolen credentials are encrypted with a daily rotating key, derived from the message timestamp, and land in the operator's Discord channel. The "most useful detection strategy" according to Talos analyst Ryan Fetterman is to look at behavioral characteristics, not domain blocking. Fetterman notes that legitimate applications may contact the LLM providers independently, but far fewer should do so while accessing LSASS, injecting into suspended processes, or creating WMI persistence.

    The emergence of CLOSEDQUORUM malware highlights the evolving nature of cybersecurity threats and the need for security measures to adapt to these new challenges. As AI technology continues to advance, it is essential for security professionals to stay informed about the latest threats and develop strategies to mitigate their impact.

    In conclusion, the use of AI models by Windows CLOSEDQUORUM malware represents a significant development in the field of cybersecurity. By autonomously selecting post-compromise actions, this malware can carry out sophisticated attacks with increased speed and scale, making it more challenging for security measures to detect and mitigate the threat. As the threat landscape continues to evolve, it is essential for security professionals to stay vigilant and develop strategies to address these emerging challenges.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Autonomous-Malware-Evolution-How-Windows-CLOSEDQUORUM-Malware-Uses-AI-Models-to-Outmaneuver-Security-Measures-ehn.shtml

  • https://www.theregister.com/security/2026/09/22/windows-closedquorum-malware-uses-ai-models-to-autonomously-select-post-compromise-actions/5298435


  • Published: Tue Sep 22 17:32:27 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us