News Room
16
Share
CLOSEDQUORUM Malware: The Rise of Autonomous AI-Orchestrated Cyber Attacks
criticalAI Cyber Attacks

CLOSEDQUORUM Malware: The Rise of Autonomous AI-Orchestrated Cyber Attacks

Security researchers have identified CLOSEDQUORUM, a novel Windows malware that utilizes a consensus of four distinct AI models to autonomously execute malicious actions, marking a shift in threat architecture.

₿

Encrygma is selling the entire Full Cyber Weapon Research of CLOSEDQUORUM Malware: The Rise of Autonomous AI-Orchestrated Cyber Attacks for ₿ 0.10 BTC. Contact us.

04 October 2026Last updated 04 October 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
Critical
Actor Type:
Unknown
Geography:
Global
Confidence:
Confirmed
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

Cisco Talos researchers have uncovered a sophisticated new strain of Windows malware dubbed CLOSEDQUORUM. Unlike traditional malware that relies on a Command-and-Control (C2) server operated by a human, CLOSEDQUORUM leverages a decentralized decision-making process powered by multiple Large Language Models (LLMs). This development represents a significant evolution in the threat landscape, where AI is no longer just a tool for code generation but a core component of the malware's operational infrastructure.

Threat Analysis

CLOSEDQUORUM is designed to operate with a high degree of autonomy. By querying four different AI services—DeepSeek, Qwen, Mistral, and Google Gemini—the malware can determine its next move based on a consensus mechanism. This approach allows the malware to adapt to environmental variables on an infected host without needing constant instructions from a human operator, effectively reducing the footprint of traditional C2 traffic that security teams typically monitor.

Technical Details

The malware was identified using the newly released CAIRN (Cognitive Artifact Intelligence Research Network) framework, which is specifically designed to detect digital fingerprints left by AI-integrated malicious code. CLOSEDQUORUM functions by evaluating responses from the four integrated AI models. If one service is unavailable or provides an unreliable response, the malware dynamically switches to the remaining models to continue its execution. Its primary objectives include the exfiltration of Windows credentials, saved browser passwords, and cryptocurrency wallet data.

Attribution Assessment

While the specific threat actor behind CLOSEDQUORUM remains under investigation, the sophistication of the integration suggests a high-tier actor capable of operationalizing complex AI workflows. The malware appears to have been in development for at least three months, with initial code analysis dating back to June 2026. The use of multiple public AI models indicates a strategy aimed at resilience and evasion, ensuring the malware remains functional even if individual AI service providers implement stricter guardrails.

Implications

The emergence of CLOSEDQUORUM signals a transition toward 'autonomous' cybercrime. By removing the human-in-the-loop requirement for tactical decision-making, attackers can scale their operations significantly. This shift challenges existing EDR and network monitoring solutions that are primarily tuned to detect human-driven command patterns rather than autonomous, AI-generated logic.

Recommendations

Organizations should prioritize the implementation of AI-aware security frameworks like CAIRN to identify anomalous AI-service interactions within their networks. Security teams must also enhance their monitoring of outbound API calls to public LLM services from endpoints. Furthermore, adopting a zero-trust architecture is essential to limit the potential impact of autonomous malware that successfully gains initial access to sensitive credential stores.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo