ClosedQuorum AI-driven Windows post-compromise malware activity
Malware Activity
Summary
Hide ▲
Show ▼
The ClosedQuorum Windows malware now uses Google Gemini, DeepSeek, Qwen, and Mistral AI to automate post-compromise attack decisions, increasing the speed and scale of credential theft and persistence operations. The malware can choose among predefined actions such as LSASS dumping, browser credential theft, shellcode injection, and persistence without direct human commands. Researchers say the design shifts tactical C2 decisioning toward AI model voting and away from operator-driven control.
Timeline
-
22.09.2026 21:04 2 articles · 1h ago
ClosedQuorum malware uses AI model voting to choose post-compromise actions
Technical Analysis UpdateCisco Talos describes ClosedQuorum, a Go-based Windows malware that uses Google Gemini, DeepSeek, Qwen, and Mistral AI to decide among predefined post-compromise actions on infected hosts without human operator commands. The malware can steal credentials, inject shellcode, or execute its persistence module, and tied votes are resolved by DeepSeek first, then Qwen, Mistral, and Gemini; Talos also notes a Discord webhook used to pass stolen details to operators and a defined move option that the analyzed build cannot execute.
Show sources
- New ClosedQuorum Windows malware uses AI for attack decisions — www.bleepingcomputer.com — 22.09.2026 21:04
- New ClosedQuorum Windows malware uses AI for attack decisions — www.bleepingcomputer.com — 22.09.2026 21:04