Cisco Talos researchers say they have identified Windows malware that plots its next moves by polling up to four large language models and taking orders from that hive mind — with no human command channel — WIRED reported Tuesday.
Dubbed CLOSEDQUORUM, the tool checks with DeepSeek, Qwen, Mistral, and Google Gemini to build a consensus on what to do inside a target system. If one AI service is down, it still polls the others, creating redundancy so the system stays closed. Talos linked the sample to cybercriminal forum chatter about credit-card fraud going back to 2025; it is designed to steal login credentials and cryptocurrency. Researchers could not confirm who built it or whether it has been used in real-world attacks.
The find came via CAIRN — Cognitive Artifact Intelligence Research Network — an open-source framework Talos shared Monday to fingerprint and classify AI-integrated malware. Lead researcher Ryan Fetterman said publicly named AI malware families were still scarce a year after Ukraine’s CERT-UA warned about LAMEHUG, but CAIRN has since surfaced about 20 additional examples. “Now what we’re seeing is that it’s becoming operationalized,” said Matt Olney, senior director of threat intelligence at Cisco Talos.
Sources: WIRED










