Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClosedQuorum AI-driven Windows post-compromise malware activity

Malware Activity
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

The ClosedQuorum Windows malware now uses Google Gemini, DeepSeek, Qwen, and Mistral AI to automate post-compromise attack decisions, increasing the speed and scale of credential theft and persistence operations. The malware can choose among predefined actions such as LSASS dumping, browser credential theft, shellcode injection, and persistence without direct human commands. Researchers say the design shifts tactical C2 decisioning toward AI model voting and away from operator-driven control.

Timeline

  1. 22.09.2026 21:04 2 articles · 1h ago

    ClosedQuorum malware uses AI model voting to choose post-compromise actions

    Technical Analysis Update

    Cisco Talos describes ClosedQuorum, a Go-based Windows malware that uses Google Gemini, DeepSeek, Qwen, and Mistral AI to decide among predefined post-compromise actions on infected hosts without human operator commands. The malware can steal credentials, inject shellcode, or execute its persistence module, and tied votes are resolved by DeepSeek first, then Qwen, Mistral, and Gemini; Talos also notes a Discord webhook used to pass stolen details to operators and a defined move option that the analyzed build cannot execute.

    Show sources