Enterprise DNA
News Trending AI News

AI Malware That Polls Four Models to Choose Its Next Attack

Cisco Talos discovered CLOSEDQUORUM, a Windows implant that holds a committee vote among DeepSeek, Qwen, Mistral, and Gemini to decide what to steal next.

Enterprise DNA | | via The Register
AI Malware That Polls Four Models to Choose Its Next Attack

Cisco Talos researchers disclosed a Windows malware implant on September 22 that does something genuinely new: instead of calling back to an attacker-controlled server for instructions, it queries four commercial AI models and lets them vote on what to do next.

The implant is called CLOSEDQUORUM. Talos has not confirmed any real-world deployment, and the public version researchers found does not fully work end to end. But the architecture it describes is a significant signal for anyone running AI tools inside their business.

How the Voting Works

When CLOSEDQUORUM executes on a compromised Windows machine, it gathers basic system information — the computer name, Windows version, and whether the process is running as an administrator. It packages that context alongside a fixed menu of four post-compromise actions: steal, inject, persist, and move.

That payload gets sent to all four AI services simultaneously: DeepSeek, Qwen, Mistral, and Google Gemini. Each model votes on which action to take. CLOSEDQUORUM tallies the responses and executes whichever action wins the majority.

If the winning action is steal, the malware targets Windows credential stores, saved browser passwords across major browsers, and crypto wallet data. The inject option refers to process injection for executing arbitrary code. Persist handles registry-based survival across reboots. Move enables lateral movement to other machines on the network.

Why This Architecture Matters

Traditional malware depends on command-and-control servers. Defenders know how to block those: take down the C2 infrastructure, sinkhole the domain, or simply monitor for unusual outbound connections to unusual IPs.

CLOSEDQUORUM routes its “decisions” through commercial AI API endpoints instead. From a network monitoring perspective, a machine calling out to Gemini or Mistral looks indistinguishable from a developer running a legitimate application. The API traffic blends in.

That is the design insight worth paying attention to, not the specific payload. The payload of CLOSEDQUORUM is relatively standard. The routing mechanism is the novel part.

Cisco Talos Also Released a Detection Tool

Alongside the CLOSEDQUORUM disclosure, Talos published an open-source tool called CAIRN specifically designed to hunt for malware that communicates with AI services. The tool is available on GitHub and gives defenders a way to flag suspicious AI API usage patterns in outbound traffic.

CAIRN does not solve the detection problem entirely. A business that deploys AI tools internally will generate substantial legitimate AI API traffic, and distinguishing malicious AI-routed decisions from legitimate developer usage is a non-trivial problem. But it is a start, and it gives security teams a concrete tool to evaluate.

What This Means for Business

This disclosure does not mean your business is under immediate threat from CLOSEDQUORUM specifically. Talos explicitly stated the public version is incomplete and they have not seen it deployed in the wild.

The more important message is that the same multi-agent architectures businesses are building for productivity workflows, the same pattern of “send context to an AI, get a decision back, execute it,” are also being explored as attack infrastructure. The architectural pattern is not inherently good or bad. It is just a pattern, and adversaries are now experimenting with it.

Three things are worth doing in response:

Audit your outbound AI API traffic. If you are running AI agents, tools, or development environments inside your network, you should have a baseline of which machines are calling which AI endpoints, and how often. An unexpected machine making repeated calls to Gemini or Qwen at odd hours is worth investigating.

Apply least-privilege to AI agent credentials. Any AI agent that operates inside your business should have the minimum permissions it needs to do its job. An agent that can read calendar data should not also have access to credential stores. Treat AI agents the same way you would treat a contractor: give them access to what they need, nothing more.

Stay current on CAIRN. Cisco Talos published the tool as open source. If your security team runs an endpoint detection stack, it is worth understanding what CAIRN looks for and whether you want to incorporate that pattern detection into your monitoring.

The broader trend here is that AI capability and AI-enabled attack surface are growing together. Businesses that are deploying AI thoughtfully and with proper access controls are also inadvertently building good defenses. The practices that make AI agents more reliable in production, clear boundaries, logged decisions, minimal permissions, are the same practices that make them harder to weaponize.

The architecture that powers your AI workforce is the same architecture someone else is building into their attack tooling. That is not a reason to stop building. It is a reason to build carefully.

Working With Claude field guide cover

Free Resource

Going deeper with Claude?

Get the free 32-page implementation guide for ANZ teams.

Add your name (optional)

No spam. Unsubscribe any time.