
New 'ClosedQuorum' Malware Uses Autonomous AI Voting to Execute Cyber Attacks
A novel Windows malware strain, ClosedQuorum, has emerged, utilizing a multi-model AI voting system to autonomously determine post-compromise attack vectors without human intervention.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Cisco Talos
- Read Time:
- 4 min
Executive Summary
Security researchers at Cisco Talos have identified a sophisticated new strain of Windows malware dubbed 'ClosedQuorum'. Unlike traditional malware that relies on hardcoded scripts or human-operated command-and-control (C2) infrastructure, ClosedQuorum leverages a decentralized ensemble of Large Language Models (LLMs) to make real-time, autonomous decisions during the post-compromise phase of an attack. This development marks a significant shift toward fully agentic, AI-driven cyber operations.
Threat Analysis
ClosedQuorum represents a departure from standard automated threats. Once the malware gains initial access to a host, it initiates a local reconnaissance phase. Instead of following a pre-programmed playbook, the malware queries a suite of integrated AI models—specifically Google Gemini, DeepSeek, Qwen, and Mistral—to analyze the environment and suggest the most effective next steps, such as lateral movement, privilege escalation, or data exfiltration. The malware operates with zero human oversight, effectively functioning as an autonomous offensive agent.
Technical Details
Written in Go, the malware is designed for modularity and resilience. It employs a unique 'voting system' to reach consensus on its tactical decisions. When the malware identifies a potential target or system vulnerability, it prompts each of the four integrated LLMs to propose an action. These proposals are then weighted and compared. In the event of a tie, the DeepSeek model is hardcoded to hold the tie-breaking authority, followed by Qwen, Mistral, and Gemini. This consensus mechanism allows the malware to adapt its behavior dynamically based on the specific security posture of the infected host, making signature-based detection significantly more difficult.
Attribution Assessment
As of September 24, 2026, no specific threat actor group has been definitively linked to the development of ClosedQuorum. However, the sophistication of the integration suggests the work of a highly capable cybercriminal entity or a state-sponsored research unit experimenting with the weaponization of frontier AI models. The use of multiple commercial and open-source models indicates a deliberate effort to avoid reliance on a single API provider.
Implications
The emergence of ClosedQuorum highlights the growing risk of 'agentic' malware. As AI models become more capable of reasoning and executing complex tasks, the barrier to entry for sophisticated cyber attacks is lowered. Organizations must now contend with threats that can 'think' and adapt in real-time, rendering traditional static defense mechanisms increasingly obsolete.
Recommendations
- Implement strict egress filtering to prevent malware from communicating with unauthorized AI model APIs.
- Deploy behavioral-based endpoint detection and response (EDR) solutions capable of identifying anomalous process chains, even if the individual actions appear legitimate.
- Enhance monitoring of API usage patterns within the corporate network to detect unauthorized queries to LLM services.
- Adopt a zero-trust architecture to limit the potential impact of autonomous lateral movement.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Autonomous AI Agent Attacks Surge: Spain Reports First Incident of LLM-Driven Vulnerability Exploitation

Spain Reports First Autonomous AI Agent-Powered Cyber Attack on Enterprise Infrastructure

