Cisco Talos said CLOSEDQUORUM is a Windows malware binary that uses large language models to choose its next post-compromise move without a human steering each step. Talos, using its CAIRN research project, says this is the first publicly documented Windows implant to do so, and it tied artifacts in the sample to a developer posting on criminal forums since 2025, though in-the-wild deployment is unconfirmed.
The implant does not ask an operator for commands. Instead, it sends the situation to up to four models — Google Gemini, DeepSeek, Qwen, and Mistral — and follows the vote from a fixed menu of actions such as stealing credentials, injecting code, or persisting on the device. That shifts part of command and control into the malware itself, so the attack can keep moving even when no attacker is online.
For defenders, the lesson is about trust assumptions, not just malware novelty. If your detection and response model assumes every post-compromise step depends on a live operator, CLOSEDQUORUM shows how that control plane can be delegated to the implant; the exposure is the unattended phase of the intrusion, not a specific product or patch.
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack.