# ClosedQuorum malware delegates attack decisions to four AI models

_Published Tuesday, September 22, 2026 at 3:08 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![ClosedQuorum malware delegates attack decisions to four AI models — Primary](https://www.bleepstatic.com/content/hl-images/2025/10/21/Robot.jpg)

Cisco Talos researchers analyzed a Windows implant called ClosedQuorum that uses Gemini, DeepSeek, Qwen and Mistral models to vote on post-compromise actions without instructions from a human operator. Its predefined options include stealing credentials and cryptocurrency wallets, injecting code and establishing persistence; a lateral-movement option exists but is not implemented in the analyzed build.

Stolen data can be sent through a Discord webhook. Talos found placeholder API credentials and a dummy webhook in the sample and has not confirmed deployment in the wild, leaving open whether the software is an operational threat or an experiment.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/)

---
Canonical: https://techandbusiness.org/newswire/4nzYL14oSwDqZa2PT4QAGc
Published: 2026-09-22T19:08:05.879Z
Story chronology: 2026-09-22T18:04:39.000Z
Retrieved: 2026-09-22T20:36:53.490Z
Publisher: Tech & Business (techandbusiness.org)
