Menu Close

Cisco Talos finds CLOSEDQUORUM malware that lets AI models vote on attacks

Editorial Cisco Talos CAIRN and CLOSEDQUORUM security board with LLM panel chips for DeepSeek, Qwen, Mistral, and Gemini, and a no-human-operator cue; no researcher likeness.

Cisco Talos released CAIRN, an open-source hunt for AI-integrated malware, and disclosed CLOSEDQUORUM — a Windows implant that polls DeepSeek, Qwen, Mistral, and Gemini to pick its next move without a human operator.

Cisco Talos on Tuesday published an open-source toolkit for spotting malware that wires in AI chatbots, and with it disclosed what researchers say is the first publicly documented Windows implant to hand tactical command-and-control decisions to a panel of large language models, WIRED reported.

The framework is called CAIRN, short for Cognitive Artifact Intelligence Research Network. It hunts from metadata — embedded prompts, provider endpoints, orchestration clues, and related artifacts — rather than requiring analysts to download and run every sample. Talos detailed the release in a CAIRN introduction and a technical write-up of the find, The Closed Quorum.

CLOSEDQUORUM is a roughly 16.4MB Go-based Windows binary. After it lands, Talos said, it queries up to four commercial model providers — DeepSeek, Qwen, Mistral, and Google Gemini — tallies their votes, and executes the winning choice from a constrained menu that includes credential theft, process injection, and persistence. There is no dedicated attacker-run C2 server issuing live tasking in that loop, and no human operator selecting the next move. Stolen material is meant to leave through a Discord webhook. BleepingComputer separately covered the same disclosure.

Talos linked development artifacts to criminal-forum postings about carding dating to 2025, but said it could not confirm who built the malware or whether it has been used in real-world attacks. The public distribution build Talos examined carried placeholder API keys and a dummy webhook, so researchers did not observe a complete live end-to-end run from that sample.

Ryan Fetterman, who led CAIRN at Talos, told WIRED the point is to give defenders a shared way to track AI-integration fingerprints as the category grows beyond a handful of named families. Matt Olney, Talos’s senior director of threat intelligence, framed the shift as attackers moving from AI as a productivity aid to AI as operational scaffolding.

This brief covers the Tuesday CAIRN release and CLOSEDQUORUM disclosure. It is distinct from AI Tech Daily’s earlier coverage of open-weight models used in bug hunting and from product security wires on consumer AI agents.

Sources

0 0 votes
Article Rating
Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x