< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 5 sources · 3 days · First seen · Last updated

ClosedQuorum AI-driven Windows malware

Overview

Security researchers at Cisco Talos identified ClosedQuorum, a Windows malware prototype that utilizes a quorum voting mechanism among multiple large language models (LLMs) to automate decision-making. The malware queries models including DeepSeek, Qwen, Mistral, and Gemini to select operational actions such as file collection, code injection, or network spreading. In the event of a tie, the system follows a specific hierarchy to resolve the deadlock.

While initially identified as a proof of concept, subsequent reports indicate that ClosedQuorum has been detected on over 10,000 endpoints within the finance, healthcare, and manufacturing sectors. The autonomous AI-driven command-and-control framework allows the malware to achieve behavioral variability, which reportedly reduces the mean time to compromise by approximately 40% and helps evade traditional antivirus and EDR tools. In response, Cisco Talos has released the open-source CAIRN hunter tool to identify anomalous model-invocation patterns.

Entities

ClosedQuorum · DeepSeek · Google Gemini · Mistral · Cisco Talos

Timeline

  1. 2 days ago

    [TECHNOLOGY] 3 sources
    ClosedQuorum malware uses AI quorum voting for autonomous attacks

    ClosedQuorum is a new autonomous malware strain that uses a quorum of LLMs, including Gemini and DeepSeek, to make independent command-and-control decisions, evading traditional security defenses.

  2. 4 days ago

    [TECHNOLOGY] 2 sources
    ClosedQuorum malware uses AI voting to automate Windows attacks

    ClosedQuorum is a new Windows malware prototype that uses a voting system between AI models like Gemini and DeepSeek to automate its next attack steps, reducing the need for human operators.

Sources

finance.technews.tw · flagthis.com · minutodaseguranca.blog.br · que.com · spacemoney.com.br