New ClosedQuorum Windows malware uses AI for attack decisions

New ClosedQuorum Windows malware uses AI for attack decisions
ClosedQuorum is a new Windows malware that uses Google Gemini, DeepSeek, Qwen, and Mistral AI to autonomously choose post-compromise actions without human operator commands. Cisco Talos says it can steal credentials, inject shellcode, or persist on infected hosts, and that stolen data is exfiltrated through a Discord webhook. #ClosedQuorum #GoogleGemini #DeepSeek #Qwen #Mistral #CiscoTalos

Keypoints

  • ClosedQuorum is a Go-based Windows malware that automates post-compromise decisions using AI models.
  • It relies on Google Gemini, DeepSeek, Qwen, and Mistral to vote on the next action.
  • DeepSeek has priority when model votes are tied.
  • The malware can steal credentials, inject shellcode, or establish persistence.
  • Cisco Talos says it may mark an architectural shift toward attack-chain automation.

Read More: https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/