Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move: A Threat to Cybersecurity


A new type of Windows malware, CLOSEDQUORUM, is using artificial intelligence models to guide its actions, posing a significant threat to cybersecurity. Defenders are advised to watch for behavior rather than block AI service domains, and to use specialized rules to detect the malware's signs.

  • CLOSEDQUORUM is a Windows malware that utilizes artificial intelligence (AI) models to guide its actions.
  • The malware takes orders from a vote of up to four AI models instead of an attacker's server, introducing a new layer of complexity to the traditional command-and-control (C2) server-based attack model.
  • The AI models used in CLOSEDQUORUM are commercial services that offer natural language processing, image recognition, and predictive analytics.
  • The malware's outcome is determined by the number of votes each action receives from the AI models, making it unpredictable and dynamic.
  • The reliance on AI services creates potential weak points in the malware's design, such as service refusal or censorship.
  • The malware performs various actions, including stealing login credentials, injecting code, and setting up persistence.
  • Defenders are advised to watch for behavior rather than block AI service domains and use specialized rules to detect the malware's signs.



  • The threat landscape of cyber attacks has seen numerous twists and turns in recent years, with various forms of malware and viruses emerging to compromise the security of personal and corporate networks. One of the most recent and intriguing threats to have come to light is a Windows malware known as CLOSEDQUORUM, which, as the name suggests, utilizes a unique mechanism involving artificial intelligence (AI) models to guide its actions. In this article, we will delve into the details of this malware, its functionality, and the potential risks it poses to cybersecurity.

    According to Cisco Talos, a trusted cybersecurity news platform, CLOSEDQUORUM is a Windows malware designed to take orders from a vote of up to four AI models instead of an attacker's server. This approach not only shifts the decision-making process from human operators to AI-driven algorithms but also introduces a new layer of complexity to the traditional command-and-control (C2) server-based attack model.

    The AI models in question are DeepSeek, Qwen, Mistral, and Google Gemini, all of which are commercial AI services that offer a range of functionalities, including natural language processing, image recognition, and predictive analytics. In the context of CLOSEDQUORUM, these AI models are used to choose between four possible actions: steal, inject, persist, and move. The malware sends basic information about the computer, including its name, Windows version, and administrator status, along with a fixed list of actions for the models to choose from.

    The outcome of this vote is determined by the number of votes each action receives from the AI models. If a model's answer is not in the required format, it is discarded, and the malware waits for the next attempt. This approach means that the attacker does not need to constantly send commands to the malware once it is installed, as the AI models will make decisions based on the information provided.

    However, this reliance on AI services also creates potential weak points in the malware's design. Talos notes that the AI services can refuse requests, limit the number of responses they provide, or return broken output, which can cause the malware to fail or behave erratically. Furthermore, the malware relies on companies it does not control, which means that any disruption or censorship of these services could impact the malware's functionality.

    When the vote picks the "steal" action, the malware performs three actions at once: dumping the memory of the LSASS process, which holds login credentials; copying saved passwords from Chrome, Edge, and Firefox; and data from MetaMask, Exodus, and Ethereum crypto wallets. The "inject" choice runs code inside another program, using a method called Early Bird APC injection or process hollowing if the model requests it. The "persist" choice sets up three ways for the malware to start again automatically: a value under the current user's Registry Run key, a scheduled task, and a WMI event subscription that starts it every 60 seconds.

    In terms of defense, Talos recommends that defenders watch for behavior rather than block the domains of the AI services. Legitimate programs may contact these services, but fewer would do so while also accessing LSASS, injecting code into suspended processes, or creating WMI persistence. The malware's signs include AI-service traffic from a Windows program that is not expected to use AI, similar requests sent to several AI providers within a short time, prompts containing details about the computer or attack language, process injection, LSASS access, or new persistence, and Discord webhook traffic from the same program or computer.

    To identify the malware, defenders can use a Snort rule published by Talos, which looks for the malware's prompts to the AI services. However, this rule would likely need TLS inspection to match the prompts, as they are likely to be visible only with this level of decryption.

    The article concludes by highlighting the potential risks posed by CLOSEDQUORUM and the need for cybersecurity defenders to be vigilant in detecting and mitigating this threat.

    A new type of Windows malware, CLOSEDQUORUM, is using artificial intelligence models to guide its actions, posing a significant threat to cybersecurity. Defenders are advised to watch for behavior rather than block AI service domains, and to use specialized rules to detect the malware's signs.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/This-Windows-Malware-is-Built-to-Let-Up-to-Four-AI-Models-Vote-on-Its-Next-Move-A-Threat-to-Cybersecurity-ehn.shtml

  • https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html

  • https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/

  • https://windowsreport.com/closedquorum-malware-uses-gemini-deepseek-qwen-and-mistral-to-guide-attacks/

  • https://www.mcafee.com/blogs/other-blogs/mcafee-labs/bogus-deepseek-ai-installers-are-infecting-devices-with-malware-research-finds/

  • https://www.bleepingcomputer.com/news/security/google-says-hackers-are-abusing-gemini-ai-for-all-attacks-stages/

  • https://cybersecuritynews.com/gemini-ai-model-cyberattacks/


  • Published: Wed Sep 23 11:31:21 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us