
CLOSEDQUORUM Malware Deploys Autonomous AI Voting System to Bypass Human-in-the-Loop Security
Cisco Talos researchers have identified CLOSEDQUORUM, a sophisticated Windows malware that utilizes a consensus-based AI voting mechanism to execute malicious commands autonomously without human intervention.
Encrygma is selling the entire Full Cyber Weapon Research of CLOSEDQUORUM Malware Deploys Autonomous AI Voting System to Bypass Human-in-the-Loop Security for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Cisco Talos
- Read Time:
- 4 min
Executive Summary
Security researchers at Cisco Talos have uncovered a groundbreaking evolution in malware development: CLOSEDQUORUM. Unlike traditional malware that relies on a Command and Control (C2) server operated by a human, CLOSEDQUORUM leverages a decentralized voting mechanism powered by four distinct Large Language Models (LLMs) to make tactical decisions on infected systems. This shift marks a transition from AI as a mere productivity tool for attackers to AI as a core, autonomous component of the attack infrastructure.
Threat Analysis
CLOSEDQUORUM represents a significant leap in the operationalization of artificial intelligence in cyber warfare. By removing the human operator from the decision-making loop, the malware achieves a level of resilience and adaptability previously unseen in the wild. The malware is primarily designed for credential theft and cryptocurrency exfiltration, but its modular architecture suggests it could be repurposed for more complex espionage or destructive operations.
Technical Details
The malware integrates with four major AI services: DeepSeek, Qwen, Mistral, and Google Gemini. When the malware encounters a decision point—such as determining the best method for lateral movement or identifying high-value data—it queries these models simultaneously. It then evaluates the responses, executing only those commands that reach a consensus or meet a specific confidence threshold. If one AI service is unavailable or returns an error, the malware seamlessly fails over to the remaining models. This process is facilitated by the CAIRN (Cognitive Artifact Intelligence Research Network) framework, which allows the malware to maintain operational continuity even under network instability.
Attribution Assessment
While the specific threat actor behind CLOSEDQUORUM remains under investigation, the sophistication of the code and the integration of multiple frontier models suggest a well-resourced group, likely an Advanced Persistent Threat (APT) actor. The use of the CAIRN framework indicates a high level of technical maturity, potentially linked to state-sponsored research initiatives aimed at automating cyber-offensive capabilities.
Implications
This development fundamentally alters the threat landscape. Traditional signature-based detection and behavioral analysis are increasingly ineffective against malware that can rewrite its own logic or consult AI models to evade detection. The ability of CLOSEDQUORUM to operate autonomously means that the 'dwell time' between initial infection and data exfiltration is reduced to minutes, leaving security operations centers (SOCs) with almost no window for manual intervention.
Recommendations
Organizations must shift toward AI-driven defensive postures. This includes deploying behavioral analytics that can detect anomalous AI-model querying patterns, implementing strict egress filtering to prevent unauthorized API calls to public LLM services, and adopting zero-trust architectures that limit the potential impact of autonomous lateral movement. Security teams should also prioritize the monitoring of 'digital fingerprints' associated with AI-integrated malware as identified by the CAIRN framework.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



