ClosedQuorum is a new Windows malware that uses Google Gemini, DeepSeek, Qwen, and Mistral AI to autonomously choose post-compromise actions without human operator commands. Cisco Talos says it can steal credentials, inject shellcode, or persist on infected hosts, and that stolen data is exfiltrated through a Discord webhook. #ClosedQuorum #GoogleGemini #DeepSeek #Qwen #Mistral #CiscoTalos
Keypoints
- ClosedQuorum is a Go-based Windows malware that automates post-compromise decisions using AI models.
- It relies on Google Gemini, DeepSeek, Qwen, and Mistral to vote on the next action.
- DeepSeek has priority when model votes are tied.
- The malware can steal credentials, inject shellcode, or establish persistence.
- Cisco Talos says it may mark an architectural shift toward attack-chain automation.