cyberpress.orgยท23 september 2026

CLOSEDQUORUM Windows Malware Uses AI Models for Autonomous C2 and Credential Theft

Image for the article: CLOSEDQUORUM Windows Malware Uses AI Models for Autonomous C2 and Credential Theft
Image via cyberpress.org

Cisco Talos discovered CLOSEDQUORUM, a Windows malware that uses AI models for autonomous command-and-control and credential theft. The malware queries AI providers like DeepSeek, Qwen, Mistral, and Google Gemini to decide actions such as credential theft, code injection, and persistence. CLOSEDQUORUM can steal Windows credentials, browser passwords, and cryptocurrency wallet data. The malware uses a voting mechanism among AI providers to determine its actions, reducing reliance on traditional command-and-control servers. Talos noted that the malware's AI prompts are constrained to predefined attack options, ensuring structured decision-making.