{"id":309,"date":"2026-09-22T13:49:08","date_gmt":"2026-09-22T13:49:08","guid":{"rendered":"https:\/\/bugleblast.com\/?p=309"},"modified":"2026-09-22T13:49:08","modified_gmt":"2026-09-22T13:49:08","slug":"closedquorum-ai-hive-mind-malware-cisco-talos","status":"publish","type":"post","link":"https:\/\/bugleblast.com\/?p=309","title":{"rendered":"MALWARE THAT ASKS FOUR AIs WHAT TO DO NEXT! | Cisco Talos finds CLOSEDQUORUM hive-mind C2 \u2014 no human in the loop"},"content":{"rendered":"<p>Cisco Talos researchers say they have identified Windows malware that plots its next moves by polling up to four large language models and taking orders from that hive mind \u2014 with no human command channel \u2014 WIRED reported Tuesday.<\/p>\n<p>Dubbed CLOSEDQUORUM, the tool checks with DeepSeek, Qwen, Mistral, and Google Gemini to build a consensus on what to do inside a target system. If one AI service is down, it still polls the others, creating redundancy so the system stays closed. Talos linked the sample to cybercriminal forum chatter about credit-card fraud going back to 2025; it is designed to steal login credentials and cryptocurrency. Researchers could not confirm who built it or whether it has been used in real-world attacks.<\/p>\n<p>The find came via CAIRN \u2014 Cognitive Artifact Intelligence Research Network \u2014 an open-source framework Talos shared Monday to fingerprint and classify AI-integrated malware. Lead researcher Ryan Fetterman said publicly named AI malware families were still scarce a year after Ukraine\u2019s CERT-UA warned about LAMEHUG, but CAIRN has since surfaced about 20 additional examples. \u201cNow what we\u2019re seeing is that it\u2019s becoming operationalized,\u201d said Matt Olney, senior director of threat intelligence at Cisco Talos.<\/p>\n<p><strong>Sources:<\/strong> <a href=\"https:\/\/www.wired.com\/story\/a-tool-for-tracking-ai-integrated-malware-uncovered-an-autonomous-command-system\/\">WIRED<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco Talos finds CLOSEDQUORUM hive-mind C2 \u2014 no human in the loop<\/p>\n","protected":false},"author":1,"featured_media":308,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-309","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/bugleblast.com\/wp-content\/uploads\/2026\/09\/bb-closedquorum-malware-0922.jpg","_links":{"self":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=309"}],"version-history":[{"count":0,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/309\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/media\/308"}],"wp:attachment":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}