News Room
16
Share
CLOSEDQUORUM Malware: New Windows Threat Uses AI Consensus to Execute Attacks
highAI Cyber Attacks

CLOSEDQUORUM Malware: New Windows Threat Uses AI Consensus to Execute Attacks

Security researchers have identified a sophisticated Windows malware strain, CLOSEDQUORUM, that utilizes a voting mechanism between four distinct AI models to determine its next malicious action.

₿

Encrygma is selling the entire Full Cyber Weapon Research of CLOSEDQUORUM Malware: New Windows Threat Uses AI Consensus to Execute Attacks for ₿ 0.10 BTC. Contact us.

09 October 2026Last updated 09 October 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
High
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
Confirmed
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

Recent intelligence from Cisco Talos has uncovered a novel class of Windows malware dubbed CLOSEDQUORUM. Unlike traditional command-and-control (C2) architectures that rely on direct human input or static scripts, this malware employs a decentralized decision-making process powered by a consensus of up to four separate AI models. This development marks a significant shift in how autonomous agents are being integrated into the cybercriminal toolkit.

Threat Analysis

CLOSEDQUORUM represents a departure from standard automated malware. By offloading tactical decision-making to AI models, the malware can adapt its behavior based on the specific environment it infects. The primary objective of these models is to identify and exfiltrate high-value targets, including Windows credentials, saved browser passwords, and cryptocurrency wallet data. The use of a voting system suggests an attempt to minimize errors and optimize the success rate of data theft by leveraging the collective 'reasoning' of multiple AI agents.

Technical Details

Discovered via the newly released CAIRN hunting tool, the malware's architecture is designed to query multiple AI services to decide its next move. While the public version of the code is currently non-functional, analysis of the codebase—which dates back to at least June 2026—reveals a complex integration layer. The malware does not rely on a single server for instructions; instead, it acts as a client that orchestrates a 'quorum' of AI models. If a majority of the models agree on a specific exploit path, the malware executes the corresponding payload. This modular approach makes signature-based detection significantly more difficult.

Attribution Assessment

While specific threat actor attribution remains ongoing, the sophistication of the code suggests a well-resourced group capable of integrating complex API calls into malicious binaries. The methodology aligns with recent trends observed in 2026, where attackers are increasingly moving away from custom toolmaking toward AI-accelerated frameworks to lower the barrier to entry and increase operational speed.

Implications

The emergence of CLOSEDQUORUM highlights the growing 'agentic' threat landscape. As attackers leverage AI to automate post-compromise activities, the time between initial access and data exfiltration is shrinking to mere minutes. Organizations must prepare for a future where malware is not just a static script, but an evolving, decision-making entity that can bypass traditional security controls through adaptive logic.

Recommendations

  1. Implement robust egress filtering to detect and block unauthorized API calls to known AI service providers from suspicious processes. 2. Utilize advanced behavioral analytics to monitor for anomalous process chains that indicate AI-assisted decision-making. 3. Deploy tools like CAIRN to proactively hunt for AI-integrated malware within the network. 4. Enforce strict credential management and multi-factor authentication to mitigate the impact of successful credential theft.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo