
ClosedQuorum Malware Leverages Multi-LLM Voting System for Autonomous Cyber Attacks
A new Go-based malware strain, ClosedQuorum, has emerged, utilizing a sophisticated voting mechanism across four major AI models to autonomously execute post-compromise attack decisions.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Cisco Talos
- Read Time:
- 3 min
Executive Summary
Security researchers at Cisco Talos have identified a novel Windows-based malware strain dubbed 'ClosedQuorum.' Unlike traditional automated malware that relies on hardcoded scripts or C2 instructions, ClosedQuorum integrates multiple Large Language Models (LLMs)—specifically Google Gemini, DeepSeek, Qwen, and Mistral—to make real-time, autonomous decisions during the post-compromise phase of an attack. This development marks a significant shift toward fully autonomous, AI-driven threat actors.
Threat Analysis
ClosedQuorum represents a departure from standard automated malware. By embedding LLM API calls directly into its execution flow, the malware can analyze the environment of an infected host and determine the most effective next step without human intervention. The malware operates by gathering reconnaissance data and feeding it into a multi-model voting system. This architecture allows the malware to adapt its behavior based on the specific security posture of the target, effectively bypassing static detection methods.
Technical Details
Written in Go, the malware functions as a modular agent. Upon infection, it performs local reconnaissance to identify sensitive files, network configurations, and active security software. This data is then sent to the four integrated LLMs. Each model provides a suggested action, and a weighted voting system determines the final command. Notably, the developers have implemented a tie-breaking protocol where the DeepSeek model is granted priority, followed by Qwen, Mistral, and Gemini. This hierarchy suggests a deliberate effort by the threat actors to optimize for specific reasoning capabilities found in these models.
Attribution Assessment
While the specific threat actor behind ClosedQuorum remains under investigation, the sophistication of the integration suggests a highly capable group with significant resources. The use of multiple LLMs indicates an attempt to mitigate the 'hallucination' risks associated with single-model reliance, pointing toward a developer with advanced knowledge of AI orchestration and adversarial machine learning.
Implications
The emergence of ClosedQuorum highlights the rapid weaponization of generative AI. As attackers move from using AI for simple phishing or code generation to using it for real-time decision-making, the window for incident response is shrinking. Traditional signature-based defenses are increasingly ineffective against malware that can dynamically alter its tactics based on the environment it encounters.
Recommendations
Organizations should prioritize the implementation of behavioral-based endpoint detection and response (EDR) solutions that can identify anomalous API calls to external AI services. Furthermore, network egress filtering should be tightened to restrict unauthorized communication with known LLM endpoints. Security teams should also conduct threat hunting exercises specifically focused on identifying Go-based binaries that exhibit unusual outbound traffic patterns to AI model providers.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

New 'ClosedQuorum' Malware Uses Four-LLM Hive Mind for Autonomous Cyber Attacks

New 'ClosedQuorum' Malware Uses Autonomous AI Voting to Execute Cyber Attacks

