Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 5 sources · 3 days · First seen · Last updated
ClosedQuorum AI-driven Windows malware
Overview
Security researchers at Cisco Talos identified ClosedQuorum, a Windows malware prototype that utilizes a quorum voting mechanism among multiple large language models (LLMs) to automate decision-making. The malware queries models including DeepSeek, Qwen, Mistral, and Gemini to select operational actions such as file collection, code injection, or network spreading. In the event of a tie, the system follows a specific hierarchy to resolve the deadlock.
While initially identified as a proof of concept, subsequent reports indicate that ClosedQuorum has been detected on over 10,000 endpoints within the finance, healthcare, and manufacturing sectors. The autonomous AI-driven command-and-control framework allows the malware to achieve behavioral variability, which reportedly reduces the mean time to compromise by approximately 40% and helps evade traditional antivirus and EDR tools. In response, Cisco Talos has released the open-source CAIRN hunter tool to identify anomalous model-invocation patterns.
Entities
ClosedQuorum · DeepSeek · Google Gemini · Mistral · Cisco Talos
Timeline
-
2 days ago
[TECHNOLOGY] 3 sourcesClosedQuorum malware uses AI quorum voting for autonomous attacksClosedQuorum is a new autonomous malware strain that uses a quorum of LLMs, including Gemini and DeepSeek, to make independent command-and-control decisions, evading traditional security defenses.
-
4 days ago
[TECHNOLOGY] 2 sourcesClosedQuorum malware uses AI voting to automate Windows attacksClosedQuorum is a new Windows malware prototype that uses a voting system between AI models like Gemini and DeepSeek to automate its next attack steps, reducing the need for human operators.
Sources
finance.technews.tw · flagthis.com · minutodaseguranca.blog.br · que.com · spacemoney.com.br