New Windows Malware Skips Command Servers and Lets Four AI Models Vote on What to Steal
Cisco Talos documented CLOSEDQUORUM, a Windows implant that polls DeepSeek, Qwen, Mistral, and Gemini to vote on its next move instead of calling home to a C2 server. On a tie it favors DeepSeek, then Qwen, then Mistral, then Gemini.

Most malware phones home to a server the attacker controls. A new Windows implant documented by Cisco Talos does something stranger. It asks a panel of commercial AI models what to do next and then acts on the majority vote, with no traditional command-and-control server in the loop.
Talos calls the sample CLOSEDQUORUM and describes it as the first publicly known Windows implant to hand its post-compromise decisions to a group of large language models, Help Net Security reported. The implant queries four models, DeepSeek, Qwen, Mistral, and Gemini, and each votes on a fixed menu of actions: steal data, inject code, or set up persistence.
The tie-break logic is the part worth lingering on. When the vote splits evenly, the malware defers to DeepSeek first, then Qwen, then Mistral, then Gemini. That ordering is baked into the code, a small design choice that quietly hands a Chinese model the deciding say.
The stated goals are ordinary enough: harvest user credentials and drain crypto wallets. The delivery is a 16.4MB binary written in Go.
There is a large caveat, and it matters. The copy Talos examined shipped with placeholder API keys and a dummy webhook. Researchers confirmed the decision loop through static analysis, but they did not watch it run end to end against a live target with working keys. This is a research disclosure of a technique, not a report of a mass outbreak.
Alongside the writeup, Talos released CAIRN, an open-source framework for classifying AI-integrated malware from its metadata without executing the sample. The lab traces the lineage back to LAMEHUG, flagged by CERT-UA in July 2025 as an early case of AI woven directly into malware.
The consensus-voting trick is new, but the direction of travel is not. Defenders have already watched AI agents help compromise 395 organizations running PaperCut, and a separate crew recently pointed rented AI agents at online retailers and walked off with 600,000 stolen cards. CLOSEDQUORUM pushes the same idea one step deeper, into the malware's own decision loop.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free