
Autonomous 'CLOSEDQUORUM' Malware Uses Multi-Model AI Voting to Execute Cyber Attacks
Cisco Talos has identified a novel malware strain, CLOSEDQUORUM, that autonomously decides its next attack phase by polling four commercial AI models, eliminating the need for human operators.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Cisco Talos
- Read Time:
- 4 min
Executive Summary
Security researchers at Cisco Talos have uncovered a groundbreaking development in autonomous malware: a strain dubbed CLOSEDQUORUM. Unlike traditional malware that relies on hardcoded logic or human-operated command-and-control (C2) servers, CLOSEDQUORUM utilizes a decentralized decision-making process. It queries four distinct commercial Large Language Models (LLMs) to determine its next move, effectively crowdsourcing its malicious strategy to optimize success rates in real-time.
Threat Analysis
CLOSEDQUORUM represents a significant shift in the threat landscape. By leveraging multiple AI models, the malware can bypass static security heuristics that look for predictable patterns. The malware operates by analyzing the target environment, feeding the telemetry to the AI models, and executing the action that receives the highest consensus among the models. This 'voting' mechanism allows the malware to adapt its behavior based on the specific defenses it encounters, making it highly resilient to traditional signature-based detection.
Technical Details
The malware is designed to operate on Windows systems. Upon infection, it performs a reconnaissance phase, gathering system metadata, active processes, and network configuration. This data is then encrypted and sent to an API gateway that interfaces with four different LLM providers. The prompt sent to these models is designed to frame the malicious activity as a 'security research' or 'system optimization' task to bypass safety filters. Once the models return their suggestions, the malware executes the most frequently recommended action, which may include lateral movement, credential harvesting, or data exfiltration.
Attribution Assessment
While the specific origin of the code remains under investigation, the sophistication of the API orchestration suggests a highly capable threat actor. The use of commercial LLM APIs indicates that the attackers are likely leveraging compromised or illicitly obtained API keys, potentially linked to the CARBONATO botnet, which has been observed stealing such credentials to fund its own AI operations.
Implications
This development signals the arrival of 'agentic' malware. As AI models become more integrated into security stacks, the ability of malware to 'reason' and 'collaborate' with these same models creates a dangerous feedback loop. Organizations can no longer rely on simple behavioral analysis, as the malware is now capable of mimicking legitimate administrative tasks to achieve its goals.
Recommendations
- Implement strict egress filtering to prevent unauthorized API calls to known LLM providers from internal servers.
- Monitor for anomalous API key usage patterns within cloud environments.
- Deploy AI-native security agents that can detect 'adversarial prompt injection' and 'cognitive manipulation' attempts.
- Enhance endpoint detection and response (EDR) to identify the specific process chains associated with CLOSEDQUORUM's multi-model polling behavior.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Autonomous Malware 'CLOSEDQUORUM' Uses Multi-LLM Voting to Execute Cyber Attacks

Autonomous 'CLOSEDQUORUM' Malware Uses Multi-LLM Voting to Orchestrate Cyber Attacks

