Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CLOSEDQUORUM: A Revolutionary Malware That Employs AI to Automate Cyber Attacks


CLOSEDQUORUM, a new type of malware, uses four commercial AI models to make decisions about its next course of action, effectively automating the attack process. This malware is an example of "effort displacement," a concept that refers to the transfer of an entire phase of the attack from the operator to the system.

  • CLOSEDQUORUM is a new type of malware that uses four commercial AI models to make decisions about its next course of action.
  • CLOSEDQUORUM is the first Windows malware to use this approach, known as "effort displacement," which automates the attack process.
  • The malware's decision-making process involves gathering host information and sending it to each of the four AI models, which tally their answers and act on the most popular choice.
  • CLOSEDQUORUM can encrypt stolen data and send it through a Discord webhook, making it difficult for security teams to identify.
  • Defenders can identify CLOSEDQUORUM by watching for Windows binaries contacting multiple AI providers and Discord within a short period, as well as accessing LSASS or creating suspended processes.



  • Cybercrime has long been a concern for individuals and organizations alike, with malware and other forms of malicious software posing a significant threat to digital security. Recently, a new type of malware has been discovered that is pushing the boundaries of what is possible in the world of cybercrime. Dubbed CLOSEDQUORUM, this malware is unique in that it employs four commercial AI models to make decisions about its next course of action, effectively automating the attack process.

    According to a recent report by Cisco Talos, CLOSEDQUORUM is the first Windows malware to use this approach, which involves delegating tactical decisions to a panel of commercial AI models. The malware was discovered using a new open-source toolkit called CAIRN, designed to find threats that use AI. The name CLOSEDQUORUM is apt, as it refers to the requirement of a minimum number of members to make a decision, and this malware has exactly four members: DeepSeek, Qwen, Mistral, and Google Gemini.

    The report notes that CLOSEDQUORUM is an example of "effort displacement," a concept that refers to the transfer of an entire phase of the attack from the operator to the system. This means that the human-in-the-loop, which was once the bottleneck in the attack process, is no longer necessary. Instead, the AI system can continue when the operator is not watching, effectively allowing the malware to operate around the clock.

    The malware's decision-making process involves gathering basic host information and sending it to each of the four AI models, which must answer with one of exactly four options: steal, inject, persist, or move. The AI models then tally their answers and act on whichever choice gets the most votes. The malware also includes a feature that allows it to encrypt the stolen data and send it out through a Discord webhook, which can make it difficult for security teams to identify the malware.

    One of the most interesting aspects of CLOSEDQUORUM is its use of commercial AI APIs, which can be rate-limited or rejected by the providers. However, the malware's predictable tie-breaking mechanism makes it easier to identify. Talos recommends watching for Windows binaries that contact several AI providers and Discord within a short period while also accessing LSASS or creating suspended processes.

    The discovery of CLOSEDQUORUM highlights the growing threat of AI-powered malware and the need for defenders to be aware of this emerging threat model. As effort displacement expands across more phases of an intrusion, its effects will compound with the speed and scale already afforded by modern AI.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CLOSEDQUORUM-A-Revolutionary-Malware-That-Employs-AI-to-Automate-Cyber-Attacks-ehn.shtml

  • https://securityaffairs.com/199640/malware/closedquorum-the-malware-that-asks-four-ai-models-what-to-do-next.html


  • Published: Thu Sep 24 01:25:51 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us