CLOSEDQUORUM: New AI Malware Can Decide its Next Move Using Multiple Models

Cybersecurity researchers identified CLOSEDQUORUM, a Windows malware that uses multiple AI models to guide its actions. The program can communicate with Gemini, DeepSeek, Qwen, and Mistral, marking a shift from attackers simply using AI tools toward incorporating AI directly into malicious software.
AI malware is becoming its own category_ Researchers found a malicious program that uses multiple AI models to decide what to do
Written By:
Soham Halder
Reviewed By:
Achu Krishnan
Published on
Updated on

Cybersecurity researchers have identified a Windows malware program that uses multiple artificial intelligence models to decide what to do next, pointing to a new direction in the evolution of AI-assisted cyber threats. Researchers at Cisco Talos analyzed the malware, called CLOSEDQUORUM. 

Unlike conventional malware, which follows instructions embedded by its developers, CLOSEDQUORUM can contact several AI models and use their responses to make decisions during an attack. The discovery comes as security researchers increasingly track malicious software that incorporates AI into its operations.

CLOSEDQUORUM Uses Multiple AI Models

CLOSEDQUORUM can communicate with up to four AI systems: DeepSeek, Qwen, Mistral, and Google Gemini. Researchers describe the arrangement as resembling a “hive mind”, with the malware able to seek input from several models instead of depending on a single system.

If one AI service becomes unavailable, the others can continue providing responses. The malware is designed to operate without a human operator choosing its next action.

According to researchers, CLOSEDQUORUM can make decisions from a predefined set of activities. Those capabilities include stealing login credentials and cryptocurrency-related information. However, researchers have not established who created the malware or confirmed that it has been deployed successfully in real-world attacks.

Researchers Track a Growing Malware Category

Cisco Talos created the Cognitive Artifact Intelligence Research Network (CAIRN) to identify and study malware that incorporates AI. Researchers say AI-enabled programs can leave behind identifiable traces that help security teams distinguish them from conventional malware.

When Cisco Talos first searched for malware with AI integration, researchers found about nine named families and several proof-of-concept samples. After developing CAIRN, they identified roughly 20 additional examples within a few months, suggesting the technique is appearing more frequently.

Also Read: AI Agents, Zero-Click Attacks: The Next Cybersecurity Threat

AI Moves Beyond a Tool for Attackers

The findings point to a shift in how AI can be used in cybercrime. Previously, much of the discussion centered on attackers using AI to write malicious code, create phishing messages or automate other tasks.

CLOSEDQUORUM represents a different approach: AI models are incorporated into the malware itself and can provide guidance during an operation. Cisco Talos researcher Matt Olney said attackers are beginning to “operationalize” AI, potentially allowing malicious campaigns to adapt to different systems and expand their reach. 

For security teams, this means monitoring AI-related indicators could become an increasingly important part of malware detection and analysis.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp
logo
Artificial Intelligence News & Cryptocurrency News: Latest Trends | Analytics Insight
www.analyticsinsight.net