Skip to content
Security & Trust

Researchers Find Malware That Lets AI Models Vote on Its Next Move

Cisco Talos details a Windows implant where four AI models vote on the next attack step, no operator required.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Researchers Find Malware That Lets AI Models Vote on Its Next Move
Key finding

LLM providers queried as the C2 decision panel: 4 (Source: Cisco Talos (Sept. 28, 2026))

Cisco Talos has documented what it describes as the first publicly known Windows malware to hand an entire phase of an intrusion to a panel of commercial AI models. The implant, named CLOSEDQUORUM, queries up to four large language model providers after it lands on a machine, tallies their votes, and carries out whichever action wins — without further instructions from a human operator or a dedicated command server. Talos published the finding on September 28, 2026, as the first release from CAIRN, its new open-source toolkit for tracking AI-integrated malware.

No domain to block

Conventional command-and-control depends on infrastructure a defender can eventually find: a domain, an IP address, a listening server. Security teams track those indicators, and certificate transparency logs often expose new C2 infrastructure before an attacker even uses it. CLOSEDQUORUM sidesteps that model. Instead of a server the attacker controls, it calls the public APIs of DeepSeek, Qwen, Mistral, and Google Gemini — endpoints thousands of legitimate applications use every day. Each provider returns a decision in a fixed JSON format; the responses are tallied and the majority choice becomes the implant's next move. Talos found that if the vote ties, the outcome always favors DeepSeek first, then Qwen, Mistral, and Gemini, in that order.

4
LLM providers queried as the C2 decision panel
Source: Cisco Talos (Sept. 28, 2026)

What the implant is built to steal

Talos's static analysis of the Go-compiled binary shows the implant is aimed at credentials and cryptocurrency. Once a target is selected, it can dump the memory of the Windows LSASS process to lift saved logins, pull stored credentials from Chrome, Edge, and Firefox, and copy MetaMask, Exodus, and Ethereum wallet data from local storage. Persistence is layered across a registry run key, a scheduled task, and a WMI event subscription that checks in on a fixed schedule and, when triggered, runs a PowerShell script left in the Windows temp folder. Stolen material is encrypted, base64-encoded, and pushed out through a Discord webhook rather than a conventional C2 channel.

16.4MB
Size of the 64-bit Go-compiled Windows executable
Source: Cisco Talos (Sept. 28, 2026)
60 seconds
WMI persistence check-in interval that triggers the PowerShell payload
Source: Cisco Talos (Sept. 28, 2026)
1,900 bytes
Size of each encrypted segment posted to the Discord exfiltration channel, sent at one-second intervals
Source: Cisco Talos (Sept. 28, 2026)

A limited but concrete precedent

Talos is specific about what it has and hasn't observed. The publicly distributed build contains placeholder API keys and a dummy webhook, so it does not run end to end as found in the wild; the full autonomous decision loop is confirmed through static analysis and development builds, not a live campaign. Talos also assesses the implant is likely offered as a service — a developer appears to build a customized binary with a distinct exfiltration channel for each operator, who can then run the intrusion without staying online. Talos frames CLOSEDQUORUM less as a finished attack tool than as evidence that shifting tactical decisions from a human operator to a model panel is achievable today with ordinary commercial API access.

What to ask your security team

Talos's own recommendation is to watch for the pattern of behavior rather than block individual domains, since traffic to any single AI provider or to Discord is common on its own. For budget-holders, that points to questions for the team rather than a purchase order: Does our endpoint monitoring flag a single host contacting multiple external LLM APIs in short succession, especially alongside LSASS access or new WMI persistence entries? Do we log and review outbound traffic to Discord webhooks, which have little legitimate business purpose on most corporate endpoints? Can our detection stack tell approved AI-tool usage apart from an unapproved process reaching the same provider endpoints? And does our incident response plan account for malware that can keep operating on its own schedule, independent of when an attacker is actually at a keyboard?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cisco Talos.

Share this insight