Security researchers at Cisco Talos have documented what they describe as the first publicly known Windows malware to hand its tactical decisions to a panel of commercial AI models rather than a human operator. The malware, called CLOSEDQUORUM, queries up to four AI services, DeepSeek, Qwen, Mistral, and Google Gemini, and acts on whichever action receives the most votes.
The way the malware works is pretty straightforward. Each time it needs to decide what to do next on a compromised machine, it sends basic system information to the four models, along with a fixed menu of options: steal, inject, persist, or move. Each model votes; the majority choice wins, and the malware acts on it without any instruction from a human operator. It has its favourite too, and if two options tie, CLOSEDQUORUM defaults to DeepSeek first, then Qwen, then Mistral, then Gemini.
Popular Now: AFTERSHOCK's $14,200 Cherry Bloom gaming PC uses titanium flowers that bloom with heat
The steal option directs the malware to dump credentials from Windows memory, copy saved passwords from Chrome, Edge, and Firefox, and extract data from cryptocurrency wallets including MetaMask and Exodus. The inject option runs code inside another process using Early Bird APC injection or process hollowing. The persist option sets up three separate footholds: a Registry Run key, a scheduled task, and a WMI event subscription that restarts the malware every 60 seconds, all named to look like routine Windows Update activity.
That said, Talos says it didn't see the malware in action against a live target, and it has no confirmed victims. The attacker appears to compile working copies with real keys and sell them to buyers. Talos also noted that CLOSEDQUORUM's reliance on commercial AI services is a structural weakness, since those services can refuse requests, rate-limit responses, or return broken output, and the malware has no control over any of them.


Frequently Asked Questions
Open a question for an answer from TweakTown's coverage of this news, or ask your own below.
Which data can the malware steal from Windows memory, browsers, and crypto wallets like MetaMask and Exodus?
How does the malware maintain persistence using a Registry Run key, scheduled task, and WMI event subscription?
What are Early Bird APC injection and process hollowing in the context of CLOSEDQUORUM's inject option?
Why does Cisco Talos say CLOSEDQUORUM's dependence on commercial AI services is a weakness for attackers?
Have a question that isn't listed here? Ask below, and TweakBot will answer it.
AI has been making its way into cybersecurity on both sides of the fight, helping defenders while also giving attackers new tools to work with. With every new report, the situation is becoming harder to ignore. For example, just last week, Claude Opus 5 helped researchers hack OpenAI in less than 72 hours.







