< Back to all clusters
[TECHNOLOGY] · United States · 7 sources

started · updated

Cisco Talos identifies AI-driven malware using LLMs for autonomous attacks

Cisco Talos researchers have identified a novel Windows malware named CLOSEDQUORUM that utilizes large language models (LLMs) to make autonomous tactical decisions. Unlike traditional malware that relies on a human operator or a central command-and-control server, CLOSEDQUORUM queries four commercial AI models—Google Gemini, DeepSeek, Qwen, and Mistral—to determine its next move.

Every five to 15 minutes, the malware sends the state of the infected host to these models, prompting them to act as “an advanced malware strategist.” The models vote on one of four possible actions: steal, inject, persist, or move laterally. The decision with the most votes is executed, with DeepSeek serving as the tie-breaker. The malware’s primary objectives include stealing Windows credentials, browser passwords from Chrome, Edge, and Firefox, and cryptocurrency wallet data from platforms like MetaMask and Exodus.

To combat this evolving threat, Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network), an open-source toolkit designed to detect and classify malware that integrates AI. CAIRN identifies “cognitive artifacts,” such as embedded prompts and API endpoints, to track AI-driven attack chains without needing to execute the malicious files directly.

Entities

Cisco Systems Inc. · Cisco Talos · DeepSeek · Google Gemini · Mistral