News Room
16
Share
ClosedQuorum Malware Deploys Multi-LLM Voting System for Autonomous Cyber Attacks
criticalAI Cyber Attacks

ClosedQuorum Malware Deploys Multi-LLM Voting System for Autonomous Cyber Attacks

A new Go-based malware, ClosedQuorum, has emerged, utilizing a sophisticated voting mechanism across four major LLMs to autonomously execute post-compromise attack stages without human intervention.

25 September 2026Last updated 25 September 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
Critical
Actor Type:
Unknown
Geography:
Global
Confidence:
Confirmed
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

Security researchers at Cisco Talos have identified a novel Windows-based malware strain dubbed 'ClosedQuorum.' Unlike traditional malware that relies on hardcoded command-and-control (C2) instructions, ClosedQuorum leverages a decentralized decision-making architecture powered by multiple Large Language Models (LLMs) to determine its post-compromise behavior. This development marks a significant shift toward fully autonomous, AI-driven cyber operations.

Threat Analysis

ClosedQuorum represents a departure from standard automated scripts. By integrating with APIs for Google Gemini, DeepSeek, Qwen, and Mistral, the malware performs real-time reconnaissance on infected hosts and queries these models to decide the most effective next step. This approach allows the malware to adapt its tactics dynamically based on the specific environment it encounters, effectively bypassing static signature-based detection systems.

Technical Details

Written in Go, the malware operates as a modular agent. Upon gaining initial access, it collects system metadata, network configurations, and active process lists. This data is fed into a local voting engine that prompts the four LLMs for tactical recommendations. The malware employs a weighted consensus algorithm: if the models disagree, the DeepSeek model is granted tie-breaking authority, followed by Qwen, Mistral, and Gemini. This hierarchy ensures that the malware maintains a consistent, albeit malicious, strategic direction during its execution phase.

Attribution Assessment

While the specific threat actor behind ClosedQuorum remains unidentified, the sophistication of the multi-model integration suggests a well-resourced group with advanced knowledge of LLM API exploitation. The use of DeepSeek as the primary decision-maker may indicate a preference for models with specific reasoning capabilities, though researchers are currently investigating whether this is a tactical choice or a reflection of the malware author's access to specific model endpoints.

Implications

The emergence of ClosedQuorum highlights the growing trend of 'Adversarial AI,' where attackers weaponize generative models to scale operations and reduce the need for human operators. This autonomous capability significantly shortens the time between initial compromise and data exfiltration, leaving security operations centers (SOCs) with a shrinking window for detection and response.

Recommendations

Organizations should implement strict egress filtering to block unauthorized API calls to known LLM providers from non-authorized endpoints. Furthermore, security teams should monitor for anomalous Go-based binaries that exhibit high-frequency outbound traffic to AI model endpoints. Implementing behavioral analytics that detect unusual process-to-network patterns is critical to identifying autonomous agents like ClosedQuorum before they can complete their objective.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo