News Room
16
Share
Autonomous 'CLOSEDQUORUM' Malware Uses Multi-Model AI Voting to Orchestrate Cyber Attacks
criticalAI Cyber Attacks

Autonomous 'CLOSEDQUORUM' Malware Uses Multi-Model AI Voting to Orchestrate Cyber Attacks

Security researchers have identified CLOSEDQUORUM, a novel strain of malware that autonomously determines its next malicious action by polling four distinct commercial AI models for consensus.

03 October 2026Last updated 03 October 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
Critical
Actor Type:
Unknown
Geography:
Global
Confidence:
High Confidence
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

Cisco Talos researchers have uncovered a sophisticated new class of malware dubbed CLOSEDQUORUM. Unlike traditional automated scripts, this malware operates without a human operator, instead utilizing a decentralized decision-making process where four commercial AI models vote on the most effective next step for the infection chain. This development marks a significant evolution in autonomous cyber threats, moving beyond simple script-based execution to cognitive, model-driven decision-making.

Threat Analysis

CLOSEDQUORUM represents a paradigm shift in how malware interacts with its environment. By offloading tactical decisions to external LLMs, the malware can adapt its behavior in real-time based on the specific security posture of the target network. The threat actor behind this campaign appears to be leveraging the malware to conduct reconnaissance, identify high-value data, and determine the most stealthy exfiltration path, all while minimizing the footprint of traditional command-and-control (C2) traffic.

Technical Details

The malware functions by embedding a lightweight agent that queries four different commercial AI APIs. It provides the models with a snapshot of the compromised system's environment, including running processes, network configuration, and detected security software. The malware then aggregates the responses from these models. If a consensus is reached on a specific action—such as privilege escalation or lateral movement—the malware executes the corresponding payload. This 'voting' mechanism allows the malware to bypass static heuristic detection, as the decision-making logic is not contained within the binary itself but is instead generated dynamically by the AI models.

Attribution Assessment

While the specific threat actor remains unconfirmed, the sophistication of the integration suggests a highly capable group with significant resources to maintain persistent API access to multiple AI providers. The use of commercial models indicates a shift toward 'living-off-the-land' techniques, where attackers utilize legitimate AI infrastructure to facilitate malicious operations, making attribution significantly more difficult for defenders.

Implications

The emergence of CLOSEDQUORUM highlights the growing risk of adversarial AI. As malware becomes capable of 'reasoning' through its own infection lifecycle, traditional signature-based defenses become increasingly obsolete. Organizations must now contend with threats that can adapt their tactics faster than human analysts can respond, necessitating a move toward agentic, AI-driven defensive systems.

Recommendations

  1. Implement strict egress filtering to block unauthorized API calls to known AI model endpoints from sensitive internal servers. 2. Deploy behavioral analytics that can detect anomalous patterns of 'reasoning' or decision-making logic within system processes. 3. Monitor for unusual outbound traffic patterns that correlate with high-latency API requests. 4. Adopt a zero-trust architecture to limit the potential impact of autonomous lateral movement.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo