cyberpress.orgยท23 september 2026
CLOSEDQUORUM Windows Malware Uses AI Models for Autonomous C2 and Credential Theft

security
malware
Ethereum
Mistral
command-and-control
LSASS memory
cybersecurity
AI
Exodus
Discord
Cisco Talos
DeepSeek
Google Gemini
MetaMask
credential theft
Cairn
Qwen
cyberpress.org
Cisco Talos discovered CLOSEDQUORUM, a Windows malware that uses AI models for autonomous command-and-control and credential theft. The malware queries AI providers like DeepSeek, Qwen, Mistral, and Google Gemini to decide actions such as credential theft, code injection, and persistence. CLOSEDQUORUM can steal Windows credentials, browser passwords, and cryptocurrency wallet data. The malware uses a voting mechanism among AI providers to determine its actions, reducing reliance on traditional command-and-control servers. Talos noted that the malware's AI prompts are constrained to predefined attack options, ensuring structured decision-making.